Tactic or Technique: Out of band pivot

Attackers use out-of-band pivoting to move conversations off email and onto channels with less security oversight. They start with a simple message and then try to shift the conversation to phone, text, WhatsApp, or personal email, where monitoring and protections are weaker or nonexistent.
A message may reference an urgent issue and include a phone number, QR code, or request to continue the conversation elsewhere. Once the communication moves off email, attackers can push the scam further without being seen by security tools.
This tactic works because it breaks the visibility chain. Email security may catch a bad link or attachment, but it can’t detect what happens in a phone call or private chat. That gap gives attackers more freedom to ask for credentials, convince you to take risky actions, or escalate the attack without triggering alerts.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Microsoft Power Apps callback scam
4d ago
Oct 2nd, 2026
Sublime Security
Service abuse: Self-service platform redirecting to newly registered suspicious domain
5d ago
Oct 1st, 2026
Sublime Security
Service abuse: Apple callback scam
7d ago
Sep 29th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
8d ago
Sep 28th, 2026
Sublime Security
Callback phishing via Xodo Sign comment
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Callback phishing solicitation via image file
8d ago
Sep 28th, 2026
@vector_sec
Callback phishing via SignFree e-signature request
8d ago
Sep 28th, 2026
Sublime Security
Callback Phishing via Signable E-Signature Request
8d ago
Sep 28th, 2026
Sublime Security
Callback phishing via Adobe Sign comment
8d ago
Sep 28th, 2026
Sublime Security
Callback phishing solicitation in message body
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Callback phishing solicitation via text-based file
8d ago
Sep 28th, 2026
Sublime Security
Benefits enrollment impersonation
13d ago
Sep 23rd, 2026
Sublime Security
Link: ScreenConnect remote access tool delivery with unattended guest access
25d ago
Sep 11th, 2026
Sublime Security
Attachment: Fake research internship offer
1mo ago
Sep 1st, 2026
Sublime Security
Service abuse: EventCreate links to newly registered domains
1mo ago
Aug 31st, 2026
Sublime Security
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
1mo ago
Aug 26th, 2026
Sublime Security
Service abuse: AWS SNS callback scam impersonation
1mo ago
Aug 20th, 2026
Sublime Security
Service abuse: Arketa notification callback scam
1mo ago
Aug 19th, 2026
Sublime Security
Link: Direct link to Dropbox Paper file
1mo ago
Aug 17th, 2026
Sublime Security
VIP Impersonation: VIP handoff with fake forwarded invoice thread
1mo ago
Aug 17th, 2026
Sublime Security