Multichannel Fraud: When Attacks Move Beyond the Inbox

A phishing email used to be the whole attack. Increasingly, it's the opening move in a coordinated sequence that spans email, SMS, and voice, each channel reinforcing the others' credibility in a way that no single channel could achieve alone. An email establishes a pretext; a text message adds urgency and a sense of continuity; a phone call — sometimes using synthetic voice — provides apparent human confirmation. Evaluated separately, each piece might look unremarkable. Evaluated together, the pattern is unmistakable.
This piece looks at how multichannel fraud campaigns are typically structured, why single-channel security tools miss the pattern that spans them, and what a unified defense actually requires.
Quick Summary
- The shift: attackers increasingly coordinate campaigns across email, SMS, and voice rather than relying on a single channel.
- Why it's more effective: each channel reinforces the others' apparent legitimacy, and switching channels mid-attack helps evade tools built to monitor only one.
- The detection gap: most organizations deploy separate, disconnected tools for email security, mobile/SMS protection, and voice — none of which see the full picture a coordinated attack creates.
- What unified defense requires: a platform capable of correlating signals across channels, recognizing a pattern that no single channel's tool would flag in isolation.
Why Attackers Are Moving Beyond Email
As email security has matured — behavioral detection, real-time link analysis, and better authentication have all raised the cost of a successful email-only attack — attackers have adapted by diversifying their approach rather than abandoning email entirely. A coordinated, multichannel campaign doesn't need every individual message to be sophisticated; it needs the combination of channels to create a cumulative sense of legitimacy that any single message might not achieve on its own.
This mirrors a broader pattern across cybercrime: as one channel's defenses improve, attackers redistribute effort toward channels with comparatively weaker, less mature security coverage. SMS and voice have historically received far less dedicated security investment than email, making them an attractive complement even when email remains part of the overall attack sequence.
How a Typical Multichannel Campaign Unfolds
A coordinated campaign commonly follows a layered structure: an initial email establishes context — a notification, an alert, a request that sounds routine — without necessarily containing anything overtly malicious on its own. A follow-up SMS message, arriving shortly after, reinforces the same narrative with added urgency, exploiting the fact that people generally treat text messages as more immediate and personal than email, and therefore scrutinize them less carefully. In more elaborate campaigns, a phone call — sometimes from a human operator working from a script, sometimes using synthetic voice — provides an apparent human confirmation that overcomes any remaining hesitation the target might have.
Each individual touchpoint is often designed to look unremarkable in isolation specifically because attackers are aware that security tools, and human targets, evaluate messages one at a time. The email alone might not warrant a second look; the SMS alone might read as a routine notification; the phone call alone might sound like a normal customer service interaction. The manipulation lives in the sequence, not any single message.
Why Single-Channel Tools Miss the Pattern
Most organizations' security stacks are organized by channel: an email security platform, a separate mobile device management or SMS filtering tool, and no dedicated security tooling for voice at all in many cases. Each tool evaluates its own channel in isolation, with no visibility into what's happening on the others — meaning a coordinated campaign, by design, never presents a single tool with enough information to recognize the full pattern.
This is a structural gap, not a tuning problem: an email security platform doing an excellent job analyzing email simply has no data about a related SMS message sent minutes later, and no mechanism to connect the two even if it did. Closing this gap requires a platform architecture built around cross-channel correlation from the start, not a collection of best-in-class single-channel tools operating independently.
What Unified, Cross-Channel Detection Looks Like
A detection approach capable of catching multichannel fraud needs to treat email, SMS, and voice-adjacent signals as related data points about the same potential threat, rather than entirely separate streams. In practice, this means correlating signals like: an email and an SMS referencing the same account, transaction, or pretext within a short time window; a pattern of channel-switching that itself is unusual for how a given organization or individual typically communicates with the recipient; and shared infrastructure or content markers that link messages across channels even when they arrive through different technical delivery paths.
This kind of correlation is only possible with a platform that has genuine visibility into more than one channel simultaneously — which is the practical argument for consolidating multichannel protection under a single detection architecture rather than stitching together separate, channel-specific tools that were never designed to share signal with each other.
What Organizations Can Do Today
Beyond adopting genuinely cross-channel detection tooling, organizations can reduce exposure by applying the same "independent verification" principle used against BEC and executive impersonation to multichannel scenarios specifically: if a request arrives via email and gets "confirmed" via a follow-up SMS or call, that confirmation should be treated with the same skepticism as the original request, not as independent corroboration — since, in a coordinated campaign, both are from the same attacker. Genuine verification requires a channel and contact method established independently of the messages being verified, not a second message from the same unverified source.
FAQ
Why are attackers combining email with SMS and voice?
As email defenses have improved, attackers have diversified toward channels — particularly SMS and voice — that have historically received less dedicated security investment, using the combination to create cumulative legitimacy no single channel achieves alone.
Why don't email security tools catch multichannel fraud?
Because they only have visibility into email — a related SMS or phone call is invisible to a tool that was never built to correlate signals across channels in the first place.
Is a text message "confirming" an email request a reliable verification method?
No — in a coordinated attack, both the email and the follow-up SMS originate from the same attacker. Genuine verification requires a channel and contact method established independently of the messages being verified.
What does cross-channel correlation actually look for?
Signals like an email and SMS referencing the same account or transaction within a short window, unusual channel-switching patterns, and shared infrastructure or content markers linking messages that arrive through different technical paths.
Can organizations get cross-channel protection by combining separate best-in-class tools?
It's difficult — most channel-specific tools have no mechanism to share signal with tools covering other channels, which is a structural gap rather than something that can be solved by better tuning individual tools.
Is multichannel fraud only a concern for large enterprises?
No — any organization or individual reachable across multiple channels is a potential target. The technique is particularly effective against individuals and smaller organizations that may have even less channel-specific security coverage than a large enterprise.
Key Takeaways
- Attackers increasingly coordinate campaigns across email, SMS, and voice, with each channel reinforcing the others' apparent legitimacy.
- Individual touchpoints are often designed to look unremarkable in isolation — the manipulation lives in the sequence.
- Single-channel security tools structurally cannot see a pattern that spans multiple channels.
- Effective detection requires a platform architected for cross-channel correlation, not a collection of disconnected channel-specific tools.
- A follow-up message on a different channel should never be treated as independent verification of the original request.