Double Phishing: When the Text Message Is Followed by a Call

In early May BACS described an attack pattern we keep running into during client engagements yet most people still underestimate: double phishing, meaning the combination of a digital message followed by a phone call.

First comes an SMS, the classic “your package could not be delivered” setup. Click the link, enter your details (name, address, credit card), and then sometimes just minutes later the phone rings. This is where it gets nasty: the caller already knows the data you just entered, claims to be from your bank or the police, sounds completely professional and then demands you approve a payment, confirm login credentials or install some software. Two channels, one attack, and it works terrifyingly well.

Why this is increasing

Traditional email phishing is hitting its limits because people have grown more sceptical (finally), spam filters are getting better and phishing pages sometimes survive only hours before they get taken down. So attackers do the obvious thing and step up their game.

The SMS provides the pretext and harvests data, the phone call provides credibility. When someone on the phone knows your name, your address and your last supposed delivery, who is going to think “scam”?

Proofpoint documented a 97 percent increase in multi-channel phishing attacks for 2025.

BACS example

An SMS reports an undeliverable package. Tap the link, the page looks exactly like the postal service (convincingly real), enter your name, address and credit card details for a small redelivery fee of CHF 2.90 or so.

Then maybe ten minutes later the phone rings. The caller knows the details you just entered, claims to be from the bank (“verifying a suspicious transaction”) or from the police (“documenting the fraud case”). In reality the goal is to push the victim into one more action, e.g. confirming a Twint payment or handing over a security code. The timing is everything: the victim is still in context, the package story is still fresh in their mind, and the connection between SMS and phone call feels logical rather than suspicious.

In a corporate context

Double phishing does not just hit private individuals. In a corporate context it looks like this: an employee receives a phishing email, supposedly from a supplier. Click, login credentials entered. Shortly after someone calls, “IT support” or “the supplier”, and uses those details to deepen the attack.

Or CEO fraud: an email from the “CEO” announces an urgent transfer and ten minutes later the “CEO” calls to confirm. The voice sounds familiar, or soon will thanks to AI voice cloning.

What makes the combination so dangerous is that it undermines the natural cross-check. Every security training recommends “if you receive a suspicious email, verify through a second channel”, and the attackers provide exactly that second channel (arguably the cleverest part of the whole attack).

Countermeasures

The most important rule: callbacks must go through a number you looked up yourself, not the number on the display, not the number in the email, not the number the caller helpfully dictates, but the number on the official website or in your own records.

For businesses you need a clear escalation rule, namely that any payment instruction by email or phone that does not follow the standard process gets paused and independently verified. That takes five minutes; a successful double phishing attack costs orders of magnitude more.

And something many overlook: awareness training needs to go beyond email phishing. If you are only testing employees with simulated phishing emails you are preparing them for yesterdays attack. The combination of digital and voice vectors has to be part of the trainig.

Bigger picture

Double phishing reflects a trend we are seeing in virtually every current attack: more effort per target, higher return per attack. Instead of blasting out ten thousand generic emails, groups focus on fewer targets with multi-stage approaches. For defenders this means that simple filters and an annual awareness PowerPoint are no longer enough, and you need processes that hold up even when the attack comes through multiple channels and is well researched…

In our social engineering assessments we simulate exactly these multi-stage attacks, including combined email and phone scenarios. Uncomfortable? Yes. But better with us than for real. Talk to us.

Sources: BACS Weekly Review CW 18, Proofpoint State of the Phish 2026