Tactic or Technique: Out of band pivot

Attackers use out-of-band pivoting to move conversations off email and onto channels with less security oversight. They start with a simple message and then try to shift the conversation to phone, text, WhatsApp, or personal email, where monitoring and protections are weaker or nonexistent.
A message may reference an urgent issue and include a phone number, QR code, or request to continue the conversation elsewhere. Once the communication moves off email, attackers can push the scam further without being seen by security tools.
This tactic works because it breaks the visibility chain. Email security may catch a bad link or attachment, but it can’t detect what happens in a phone call or private chat. That gap gives attackers more freedom to ask for credentials, convince you to take risky actions, or escalate the attack without triggering alerts.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
3h ago
Nov 12th, 2025
Sublime Security
/feeds/core/detection-rules/becfraud-job-scam-fake-thread-or-plaintext-pivot-to-freemail-ce21c151
Callback phishing in body or attachment (untrusted sender)
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-in-body-or-attachment-untrusted-sender-b93c6f94
Callback Phishing via Signable E-Signature Request
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-signable-e-signature-request-4599575d
Callback phishing: Branded invoice from sender/reply-to domain less than 30 days old
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-branded-invoice-from-senderreply-to-domain-less-than-30-days-old-e6f4af53
Callback phishing solicitation in message body
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-solicitation-in-message-body-10a3a446
Callback phishing via Adobe Sign comment
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-adobe-sign-comment-7eb4516d
Callback phishing via SignFree e-signature request
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-signfree-e-signature-request-21381c37
Service abuse: Google classroom solicitation
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/service-abuse-google-classroom-solicitation-e9c39e92
Callback phishing via Xodo Sign comment
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-xodo-sign-comment-6f722c5d
Attachment: Callback phishing solicitation via image file
1mo ago
Sep 25th, 2025
@vector_sec
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-image-file-60acbb36
Callback phishing via DocuSign comment
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-docusign-comment-48aec918
Credential Phishing via Dropbox comment abuse
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/credential-phishing-via-dropbox-comment-abuse-744d494d
Attachment: Callback phishing solicitation via text-based file
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-callback-phishing-solicitation-via-text-based-file-ca39c83a
Callback Phishing via Zoom comment
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-zoom-comment-8ec30881
BEC/Fraud: Student loan callback phishing
2mo ago
Sep 5th, 2025
Sublime Security
/feeds/core/detection-rules/becfraud-student-loan-callback-phishing-a71f82c3
Callback phishing via Yammer comment
2mo ago
Sep 2nd, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-yammer-comment-66650e2b
Callback phishing via MicrosoftOnline comment
2mo ago
Aug 28th, 2025
Sublime Security
/feeds/core/detection-rules/callback-phishing-via-microsoftonline-comment-8346c7b9
Callback scam: Impersonation via TimeTrade infrastructure
2mo ago
Aug 20th, 2025
Sublime Security
/feeds/core/detection-rules/callback-scam-impersonation-via-timetrade-infrastructure-0c0b3664
HR impersonation via e-sign agreement comment
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/hr-impersonation-via-e-sign-agreement-comment-796c6f0f
BEC/Fraud: Scam lure with freemail pivot
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/becfraud-scam-lure-with-freemail-pivot-898c769f