Tactic or Technique: Out of band pivot

Attackers use out-of-band pivoting to move conversations off email and onto channels with less security oversight. They start with a simple message and then try to shift the conversation to phone, text, WhatsApp, or personal email, where monitoring and protections are weaker or nonexistent.
A message may reference an urgent issue and include a phone number, QR code, or request to continue the conversation elsewhere. Once the communication moves off email, attackers can push the scam further without being seen by security tools.
This tactic works because it breaks the visibility chain. Email security may catch a bad link or attachment, but it can’t detect what happens in a phone call or private chat. That gap gives attackers more freedom to ask for credentials, convince you to take risky actions, or escalate the attack without triggering alerts.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Callback Phishing via Zoom comment
1d ago
Feb 11th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-zoom-comment-8ec30881
Service abuse: WeTransfer callback scam
13d ago
Jan 30th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-wetransfer-callback-scam-c60c8650
Service abuse: Monday.com callback scam
17d ago
Jan 26th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-mondaycom-callback-scam-82cf4502
Service abuse: Microsoft Power BI callback scam
21d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-microsoft-power-bi-callback-scam-7a55388e
Callback phishing in body or attachment (untrusted sender)
21d ago
Jan 22nd, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Service abuse: GetAccept callback scam content
27d ago
Jan 16th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-getaccept-callback-scam-content-7ec2f70b
Benefits enrollment impersonation
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/benefits-enrollment-impersonation-5a6eb5a8
Link: ScreenConnect installer with suspicious relay domain
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-screenconnect-installer-with-suspicious-relay-domain-37d21eef
Callback phishing via DocuSign comment
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-docusign-comment-48aec918
Callback Phishing via Signable E-Signature Request
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-signable-e-signature-request-4599575d
Callback phishing via SignFree e-signature request
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-signfree-e-signature-request-21381c37
Callback phishing: Social Security Administration fraud
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-social-security-administration-fraud-a9049d52
Callback phishing via Yammer comment
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-yammer-comment-66650e2b
HR impersonation via e-sign agreement comment
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/hr-impersonation-via-e-sign-agreement-comment-796c6f0f
Attachment: Callback phishing solicitation via image file
1mo ago
Jan 12th, 2026
@vector_sec
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36
Callback phishing via Xodo Sign comment
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-xodo-sign-comment-6f722c5d
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/becfraud-job-scam-fake-thread-or-plaintext-pivot-to-freemail-ce21c151
Callback phishing via Google Meet
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-google-meet-70e01845
Service abuse: Google classroom solicitation
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/service-abuse-google-classroom-solicitation-e9c39e92
Callback phishing via Adobe Sign comment
1mo ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-adobe-sign-comment-7eb4516d