Tactic or Technique: Out of band pivot

Attackers use out-of-band pivoting to move conversations off email and onto channels with less security oversight. They start with a simple message and then try to shift the conversation to phone, text, WhatsApp, or personal email, where monitoring and protections are weaker or nonexistent.
A message may reference an urgent issue and include a phone number, QR code, or request to continue the conversation elsewhere. Once the communication moves off email, attackers can push the scam further without being seen by security tools.
This tactic works because it breaks the visibility chain. Email security may catch a bad link or attachment, but it can’t detect what happens in a phone call or private chat. That gap gives attackers more freedom to ask for credentials, convince you to take risky actions, or escalate the attack without triggering alerts.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link: ScreenConnect remote access tool delivery with unattended guest access
5d ago
Sep 11th, 2026
Sublime Security
Service abuse: Self-service platform redirecting to newly registered suspicious domain
6d ago
Sep 10th, 2026
Sublime Security
Attachment: Fake research internship offer
15d ago
Sep 1st, 2026
Sublime Security
Service abuse: EventCreate links to newly registered domains
16d ago
Aug 31st, 2026
Sublime Security
BEC/Fraud: Self-addressed reply with unrelated link in ongoing thread
21d ago
Aug 26th, 2026
Sublime Security
Service abuse: AWS SNS callback scam impersonation
27d ago
Aug 20th, 2026
Sublime Security
Service abuse: Arketa notification callback scam
28d ago
Aug 19th, 2026
Sublime Security
Link: Direct link to Dropbox Paper file
1mo ago
Aug 17th, 2026
Sublime Security
VIP Impersonation: VIP handoff with fake forwarded invoice thread
1mo ago
Aug 17th, 2026
Sublime Security
Callback phishing in body or attachment (untrusted sender)
1mo ago
Aug 5th, 2026
Sublime Security
Attachment: Callback phishing solicitation via text-based file
1mo ago
Aug 5th, 2026
Sublime Security
Service abuse: Adobe share containing newly observed email address domain
1mo ago
Jul 31st, 2026
Sublime Security
Service abuse: Postman reply-to mismatch with credential theft intent
1mo ago
Jul 29th, 2026
Sublime Security
Attachment: Callback phishing solicitation via pdf file
1mo ago
Jul 27th, 2026
Sublime Security
Callback phishing via Microsoft comment
1mo ago
Jul 27th, 2026
Sublime Security
Service abuse: FileMail callback scam
1mo ago
Jul 24th, 2026
Sublime Security
Service abuse: Zohodesk reply-to mismatch with job scam indicators
1mo ago
Jul 22nd, 2026
Sublime Security
Callback phishing via Google Meet
2mo ago
Jul 8th, 2026
Sublime Security
Impersonation: IT Department mailbox storage alert
2mo ago
Jul 7th, 2026
Sublime Security
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
2mo ago
Jul 1st, 2026
Sublime Security