Out-of-Band Verification

Minutes

Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.

How to do it

  1. 1Treat the channel the request came through as compromised for the purpose of checking it. Do not reply to the email, call the number in the text, or click the link in the chat to "confirm"; an attacker controls all of those.
  2. 2Pick a channel the sender did not choose: the phone number in your own contacts or on the back of your card, the address in the company directory, the account manager you have spoken to before, or a walk down the hall.
  3. 3Describe the request and ask whether it is real. For a payment or an account change, read back the exact amount, account number, and destination and get a yes from a person you can identify.
  4. 4In an organization, make this a written control: any change to payment details, any transfer above a threshold, and any request from an executive to move money or send data is confirmed by voice on a previously known number before it is acted on, with no exception for urgency or seniority.
  5. 5Record who confirmed, how, and when. A confirmation that cannot be shown later did not happen.

What to say

  • I am going to hang up and call you back on the number I have on file. If this is real, that will be fine.
  • Our policy is that changed bank details are confirmed by phone with a person we already know. I will call the number from the original contract, not the one in this email.

When to use it

  • An email or message asks you to pay an invoice, change where payments go, buy gift cards, or send a file containing personal data.
  • A caller or text claims to be your bank, a government agency, a delivery company, or tech support and asks you to act.
  • A voice, video, or message that sounds like a relative or an executive asks for money or for secrecy.
  • A login or "verify your account" link arrives that you did not request.

Counters

Evidence and how strong it is

Out-of-band verification is the standard control recommended by the FBI's Internet Crime Complaint Center for business email compromise, which its 2022 public service announcement described as having produced more than $43 billion in reported exposed losses worldwide between 2016 and 2021; the recommended defense is to verify payment and account changes by phone on previously known numbers rather than on contact details supplied in the request. The rationale comes from social-engineering practice: Mitnick & Simon (2002) and Hadnagy (2018) both describe attacks that succeed because the target checks the request through the channel the attacker controls, and both prescribe independent verification. Evidence strength: practitioner and regulator consensus with case-based support. There are no randomized trials of household verification rules, and the organizational evidence on phishing awareness training is mixed (Lain, Kostiainen & Capkun 2022 found that embedded training in a large company did not reduce click rates and in one condition increased them), which is an argument for process controls like this one over training alone.

Cautions
  • The verifying channel must predate the request. A number "helpfully" included in the message, an inbound call from a number that matches your bank, or a link in the same email are all inside the attacker's control.
  • Caller ID and email display names can be spoofed; the fact that a call appears to come from your bank's number proves nothing. Only a call you place to a number you looked up counts.
  • In organizations the rule fails when an executive is allowed to waive it. The point of a policy is that it binds the people most likely to be impersonated.
  • Verification takes minutes and can feel rude. Legitimate counterparts are used to it; only fraudulent ones argue against it.
  1. Federal Bureau of Investigation, Internet Crime Complaint Center (IC3) (2022). Business Email Compromise: The $43 Billion Scam (Public Service Announcement I-050422-PSA). ic3.gov
    Reported BEC losses and the recommended defense of verifying payment changes by phone on previously known numbers.
  2. Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. Wiley
    Case narratives in which targets verified requests through attacker-controlled channels, and the recommendation of independent verification.
  3. Hadnagy, C. (2018). Social Engineering: The Science of Human Hacking (2nd ed.). Wiley
    Practitioner account of pretexting and phishing mechanics and of verification as the primary organizational defense.
  4. Lain, D., Kostiainen, K., & Capkun, S. (2022). Phishing in Organizations: Findings from a Large-Scale and Long-Term Study. IEEE Symposium on Security and Privacy (S&P) 2022
    Field evidence that embedded phishing training had no protective effect in a large company, supporting process controls over awareness alone.
Last reviewed

More in Scams and social engineering

The Callback Rule

When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.

Never Pay (or Move Money) to Protect Money

No bank, agency, or company will ever ask you to move, withdraw, convert, or hand over your money to keep it safe, so any such request identifies the person making it as the threat.

Gift Cards Mean Scam

Treat any demand to pay a debt, fine, fee, bail, or "security deposit" with gift cards, cryptocurrency, a wire to a stranger, a payment app, or cash handed to a courier as proof of fraud, because no legitimate institution collects money that way.

Tell Someone Before You Send Money

Before sending money or sharing account details in response to any unexpected request, describe the situation out loud to one person who is not involved, because scams depend on the target deciding alone.

Verify, Then Trust (for Authority Claims)

Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.

Multi-Factor Authentication and Passkeys

Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.