Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Need more storage? Get a lifetime of 10TB cloud space for just $270.

    Ask HN: Would you use a job board where every listing is verified?

    OpenAI is reportedly pushing back the launch of its ‘adult mode’ even further

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      What the polls say about how Americans are using AI

      February 27, 2026

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026
    • Business

      Need more storage? Get a lifetime of 10TB cloud space for just $270.

      March 8, 2026

      Google PM open-sources Always On Memory Agent, ditching vector databases for LLM-driven persistent memory

      March 8, 2026

      Regulate AWS and Microsoft, says UK cloud provider survey

      March 8, 2026

      Google releases Gemini 3.1 Flash Lite at 1/8th the cost of Pro

      March 4, 2026

      Huawei Watch GT Series

      March 4, 2026
    • Crypto

      Banks Respond to Kraken’s Federal Reserve Access as Trump Sides with Crypto

      March 4, 2026

      Hyperliquid and DEXs Break the Top 10 — Is the CEX Era Ending?

      March 4, 2026

      Consensus Hong Kong 2026: The Institutional Turn 

      March 4, 2026

      New Crypto Mutuum Finance (MUTM) Reports V1 Protocol Progress as Roadmap Enters Phase 3

      March 4, 2026

      Bitcoin Short Sellers Caught Off Guard in New White House Move

      March 4, 2026
    • Technology

      Ask HN: Would you use a job board where every listing is verified?

      March 8, 2026

      OpenAI is reportedly pushing back the launch of its ‘adult mode’ even further

      March 8, 2026

      NASA’s DART spacecraft changed a binary asteroid’s orbit around the sun, in a first for a human-made object

      March 8, 2026

      Forget the Specs. Which MacBook Neo Color Is Best? CNET Weighs In

      March 8, 2026

      OpenAI’s head of robotics resigns following deal with the Department of Defense

      March 8, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»‘Dual-channel’ attacks are the new face of BEC in 2026
    Technology

    ‘Dual-channel’ attacks are the new face of BEC in 2026

    TechAiVerseBy TechAiVerseJanuary 14, 2026No Comments4 Mins Read4 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    ‘Dual-channel’ attacks are the new face of BEC in 2026
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    ‘Dual-channel’ attacks are the new face of BEC in 2026

    peterschreiber.media – stock.ado

    Business email compromise remains a significant threat as cyber fraudsters deploy a more diverse range of tactics against their potential victims, according to a report.

    By

    • Alex Scroxton,
      Security Editor

    Published: 13 Jan 2026 17:19

    So-called ‘dual-channel’ attacks using multiple methods of communication either simultaneously or in sequence are becoming more prevalent as digital fraudsters seek out new ways to defeat cyber protections against business email compromise (BEC) scams, according to new data from security services supplier LevelBlue.

    BEC attacks – which spoof trusted entities, often c-suite executives, then use their identities to convince victims to transfer money into the attackers’ pockets – have long been a bugbear for enterprise defenders.

    “[BEC] continues to be one of the costliest cyber attacks as reported by the FBI’s IC3, with over $2.7bn (£2bn) in adjusted losses in 2024 alone,” wrote LevelBlue researcher Katrina Udquin.

    “BEC attacks are not slowing down, and fraudsters continue to evolve their scamming techniques and arsenal,” she said.

    According to LevelBlue, last year its systems observed a significant increase in BEC attacks in which the initial lure was a request for contact, seeking to establish the potential victim’s mobile number or personal email address. A total of 43% of lures that it saw took this form, compared to 31% which took the form of a more traditional request for a payroll transfer, and 10% which asked for invoice payments or wire transfers.

    Such request for contact lures are very often a precursor to a dual-channel attack seeking to move the conversation to an alternative platform.

    LevelBlue’s systems tallied over 5,000 unique dual-channel attacks in 2025, and found that in 66% of them, the cyber fraudsters tried to move the conversation to traditional SMS messaging, in 32% of cases to messaging applications such as WhatsApp, and in 2% of cases to personal email addresses.

    The rationale behind this tactic is a relatively simple one – external mobile networks, messaging applications and personal email addresses will in almost all circumstances fall well beyond the purview of any enterprise IT security department.

    Done successfully, a dual-channel attack renders expensive email protection services basically useless, meaning all security teams can do is hope that the social engineering modules of their cyber training courses have been effective.

    Related to this, LevelBlue said it also observed an increase in callback phishing, in which the criminals encourage their mark to reach out first by contacting a specified malicious phone number. This tactic more than doubled in popularity during 2025. Callback phishing is effective because it relies heavily on authority bias and a sense of urgency, exploiting people’s tendency to take messages or instructions from people in positions of authority seriously.

    Emerging trends

    According to LevelBlue’s data – gleaned largely from its proprietary MailMarshal defence service – 2025 saw a number of other notable trends developing in the BEC sphere.

    Among these were the emergence of longer-form BEC emails. While BEC spam has traditionally been rather concise, more longer, well-crafted messages are now increasingly being seen, likely a result of cyber fraudsters trying to make their emails more elaborate and more authentic. Often, said LevelBlue’s researchers, longer emails appear to be being generated with the ‘help’ of generative artificial intelligence (GenAI) large language models (LLMs).

    The past 12 months also saw a spike in attacks using multiple-personas and crafted email threads, where the victim appears to be copied in on an ongoing email chain. This tactic has been well-used for the past four or five years by nation-state threat actors targeting individuals of interest, such as academics, activists, diplomats, journalists or politicians, but is now spreading among financially-motivated groups, too.

    In a criminal context multiple-persona impersonation and email threads seem to be being used predominantly in invoice payment fraud, with the spoofed identities often including the victim’s third-party suppliers.

    Preventing BEC: Back to basics

    Although cyber criminal tactics around BEC are clearly evolving, defenders can take solace from the fact that the best ways to protect against it are tried and tested.

    Naturally, it remains an absolute imperative that staff across the organisation are educated on how to identify potential BEC spam email indicators.

    Beyond this, security teams should ensure that they work with compliance and financial colleagues to ensure the organisation performs rigorous identification and verification checks when making external payments.

    Finally, limiting access controls to organisational systems, records and documentations, and protecting these with multifactor authentication (MFA) as standard, can inhibit the risk of data theft.

    Read more on Hackers and cybercrime prevention


    • Channel catch-up: News in brief

      By: Simon Quicke


    • How to prevent vendor email compromise attacks

      By: Amanda Scheldt


    • Advanced Email Attacks Skyrocket in Healthcare

      By: Jill Hughes


    • Meet the professional BEC op that targeted Microsoft 365 users for years

      By: Alex Scroxton

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticlePolice Digital Service ex-staffers launch employment tribunal action over mistreatment claims
    Next Article Microsoft patches 112 CVEs on first Patch Tuesday of 2026
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Ask HN: Would you use a job board where every listing is verified?

    March 8, 2026

    OpenAI is reportedly pushing back the launch of its ‘adult mode’ even further

    March 8, 2026

    NASA’s DART spacecraft changed a binary asteroid’s orbit around the sun, in a first for a human-made object

    March 8, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025705 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025292 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025166 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025125 Views
    Don't Miss
    Business Technology March 8, 2026

    Need more storage? Get a lifetime of 10TB cloud space for just $270.

    Need more storage? Get a lifetime of 10TB cloud space for just $270. Image: StackCommerce…

    Ask HN: Would you use a job board where every listing is verified?

    OpenAI is reportedly pushing back the launch of its ‘adult mode’ even further

    NASA’s DART spacecraft changed a binary asteroid’s orbit around the sun, in a first for a human-made object

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Need more storage? Get a lifetime of 10TB cloud space for just $270.

    March 8, 20262 Views

    Ask HN: Would you use a job board where every listing is verified?

    March 8, 20260 Views

    OpenAI is reportedly pushing back the launch of its ‘adult mode’ even further

    March 8, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    Best TV Antenna of 2025

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.