6 min read By Excello Mail Team

43% of BEC Emails Now Just Ask for Your Phone Number. Once You Reply, DMARC Is Out of the Conversation.

LevelBlue's SpiderLabs team tracked business email compromise activity up 15% in 2025 and found that the most common lure is no longer a fake invoice. It is a short, harmless-looking request to move the conversation to a phone call, SMS, or WhatsApp, a dual-channel tactic that exits the email inbox before the actual fraud ever begins.

LevelBlue’s SpiderLabs threat research team, the group formerly under AT&T Cybersecurity, closed out its review of 2025 business email compromise activity with a number that should reframe how most security teams think about BEC defense. Attack volume was up 15 percent year over year. But the more consequential finding sat inside the lure data itself. Across the thousands of BEC submissions SpiderLabs analyzed, “Request For Contact” was the single most common opening move, showing up in 43 percent of cases, and callback phishing tactics more than doubled in popularity across the year. Neither of those numbers describes an email attack in the way most defenses are built to think about one. They describe an email that exists purely to get the victim to stop using email.

The Email’s Only Job Is to Get You Off Email

A dual-channel BEC attack starts the same way most impersonation attempts do, with a short message that looks like it came from an executive, a vendor, or a colleague. What it does not do is ask for money, a password, or a click. It asks for a phone number, a WhatsApp contact, or it invites the recipient to call a number back. “Are you at your desk? I need to confirm something with you, what’s the best number to reach you on?” is a plausible, unremarkable line, and that is precisely the design. There is no malicious link for a secure email gateway to sandbox, no attachment for antivirus to scan, no financial ask for a BEC-detection model trained on wire-transfer language to flag. The message is, by construction, empty of everything automated defenses are built to catch.

Once the recipient replies with a phone number, the attacker has already won the only battle that mattered inside the email channel. Everything that follows, the urgent story, the fabricated banking change, the pressure to act before a deadline, happens over a voice call, a text thread, or a WhatsApp conversation that no corporate email filter will ever see.

Callback Phishing Doubled, and It Comes With a Live Operator

SpiderLabs also tracked a sharp rise in callback phishing, sometimes called telephone-oriented attack delivery, where the lure email instructs the recipient to call a number rather than asking for one. When the victim dials in, a live operator answers, often working from a script tied to the impersonated brand or executive, and walks them through the actions that matter: approving a payment, installing a remote-access tool, or reading back a one-time code. The research also flagged multi-persona impersonation as a growing pattern, where the identity on the other end of the conversation shifts mid-attack, an “executive assistant” handing the call to a “finance director,” each swap adding a layer of manufactured legitimacy that a single spoofed sender name could never carry on its own.

Why None of This Touches What DMARC Checks

DMARC’s entire value proposition rests on one assumption: that the fraudulent instruction itself, the fake invoice, the altered banking details, the urgent wire request, arrives inside a message whose From header lies about where it came from. That assumption holds for a huge share of BEC volume, which is exactly why DMARC enforcement matters. It does not hold here. A “Request For Contact” email carries no fraudulent instruction at all. It is frequently sent from a domain that authenticates cleanly, either because the attacker registered their own domain and configured SPF, DKIM, and DMARC correctly for it, the way any legitimate sender would, or because the message came from a genuinely compromised mailbox that was never spoofed in the first place. DMARC checks whether a domain is authorized to send a message. It has no opinion on what the message says, and it has absolutely no visibility into a phone call, an SMS thread, or a WhatsApp conversation that happens after the email has already done its work and gone quiet.

This is not a gap in DMARC’s implementation. It is the edge of what an email authentication protocol was ever built to evaluate, and dual-channel BEC is a tactic engineered specifically to hand off the fraud to a channel sitting past that edge.

What This Means for Your Program

Train staff to treat “let’s move this off email” as the alert, not the click. A short, content-free message that pushes toward a phone number or a messaging app should carry more suspicion than a message with an obvious malicious link, precisely because it is designed to carry less.

Never call back a number supplied inside the email that asked for the call. Verify the request through a phone number or contact method your organization already had on file before the message arrived, not one introduced in the same conversation that is asking for something.

Route financial and banking-detail changes through a channel established before the request, with a second approver who was not party to the original conversation. A dual-channel attack is built to isolate one employee across two channels it controls. A verification step that reaches outside both channels breaks that isolation.

Flag first-contact, low-content messages that solicit a phone number or messaging handle from external senders claiming to be executives or vendors. These messages are unusual enough as a category, low information, high urgency to reach a person, that they are worth a standing filter rule even though no individual instance looks obviously malicious.

Keep DMARC enforced at reject regardless. It still closes the door on anyone trying to spoof your domain outright to open one of these conversations, and a meaningful share of BEC still starts exactly that way.

The Takeaway

BEC defense has spent years converging on email authentication and content inspection, and both remain necessary. But a lure that asks for a phone number instead of a password does not need to beat either one, because it never triggers them. LevelBlue’s data shows nearly half of the BEC activity it tracked is now built around exactly that handoff, out of the inbox and onto a channel no email control was ever positioned to watch. Closing that gap takes verification habits and out-of-band confirmation sitting next to DMARC, not a stronger version of DMARC itself.


Excello Mail gives you continuous visibility into your DMARC enforcement and every source authorized to send under your domain, so the email channel stays locked down while your team handles the harder problem of what happens after someone replies. Sign up for free to Excello Mail and see exactly who is sending as you, all the time.