Out-of-Band Verification
MinutesConfirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
How to do it
- 1Treat the channel the request came through as compromised for the purpose of checking it. Do not reply to the email, call the number in the text, or click the link in the chat to "confirm"; an attacker controls all of those.
- 2Pick a channel the sender did not choose: the phone number in your own contacts or on the back of your card, the address in the company directory, the account manager you have spoken to before, or a walk down the hall.
- 3Describe the request and ask whether it is real. For a payment or an account change, read back the exact amount, account number, and destination and get a yes from a person you can identify.
- 4In an organization, make this a written control: any change to payment details, any transfer above a threshold, and any request from an executive to move money or send data is confirmed by voice on a previously known number before it is acted on, with no exception for urgency or seniority.
- 5Record who confirmed, how, and when. A confirmation that cannot be shown later did not happen.
What to say
- “I am going to hang up and call you back on the number I have on file. If this is real, that will be fine.”
- “Our policy is that changed bank details are confirmed by phone with a person we already know. I will call the number from the original contract, not the one in this email.”
When to use it
- •An email or message asks you to pay an invoice, change where payments go, buy gift cards, or send a file containing personal data.
- •A caller or text claims to be your bank, a government agency, a delivery company, or tech support and asks you to act.
- •A voice, video, or message that sounds like a relative or an executive asks for money or for secrecy.
- •A login or "verify your account" link arrives that you did not request.
Counters
Evidence and how strong it is
Out-of-band verification is the standard control recommended by the FBI's Internet Crime Complaint Center for business email compromise, which its 2022 public service announcement described as having produced more than $43 billion in reported exposed losses worldwide between 2016 and 2021; the recommended defense is to verify payment and account changes by phone on previously known numbers rather than on contact details supplied in the request. The rationale comes from social-engineering practice: Mitnick & Simon (2002) and Hadnagy (2018) both describe attacks that succeed because the target checks the request through the channel the attacker controls, and both prescribe independent verification. Evidence strength: practitioner and regulator consensus with case-based support. There are no randomized trials of household verification rules, and the organizational evidence on phishing awareness training is mixed (Lain, Kostiainen & Capkun 2022 found that embedded training in a large company did not reduce click rates and in one condition increased them), which is an argument for process controls like this one over training alone.
- The verifying channel must predate the request. A number "helpfully" included in the message, an inbound call from a number that matches your bank, or a link in the same email are all inside the attacker's control.
- Caller ID and email display names can be spoofed; the fact that a call appears to come from your bank's number proves nothing. Only a call you place to a number you looked up counts.
- In organizations the rule fails when an executive is allowed to waive it. The point of a policy is that it binds the people most likely to be impersonated.
- Verification takes minutes and can feel rude. Legitimate counterparts are used to it; only fraudulent ones argue against it.
- Federal Bureau of Investigation, Internet Crime Complaint Center (IC3) (2022). Business Email Compromise: The $43 Billion Scam (Public Service Announcement I-050422-PSA). ic3.govReported BEC losses and the recommended defense of verifying payment changes by phone on previously known numbers.
- Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. WileyCase narratives in which targets verified requests through attacker-controlled channels, and the recommendation of independent verification.
- Hadnagy, C. (2018). Social Engineering: The Science of Human Hacking (2nd ed.). WileyPractitioner account of pretexting and phishing mechanics and of verification as the primary organizational defense.
- Lain, D., Kostiainen, K., & Capkun, S. (2022). Phishing in Organizations: Findings from a Large-Scale and Long-Term Study. IEEE Symposium on Security and Privacy (S&P) 2022Field evidence that embedded phishing training had no protective effect in a large company, supporting process controls over awareness alone.