DefenseTwo-Channel Verification
The playbook

Two-Channel Verification

Confirm a request through a second, independent channel before acting.

This move is free.No product needed — see Tools only if a paid option genuinely helps.

A request and its proof should never travel the same road. Two-Channel Verification is one rule for the moment money is about to move or change direction: confirm the request on a second, independent channel — one the sender didn't choose and an attacker can't control — before you act. It's the single habit that defeats the most expensive scams there are.

Why one channel is never enough

Every channel you trust can be the thing that's compromised. An email account gets taken over and a real thread is hijacked. A phone number is spoofed so the caller ID shows your bank. A text arrives from a "new number" claiming to be your daughter. A voice or video call is cloned to sound like your boss. In each case the request and the "proof it's real" arrive on the same road — so that road proves nothing.

Two-Channel Verification breaks that. You take the request on one channel, then confirm it on a different, independent one before acting. If the first channel was faked or hijacked, the second one catches it — because a scammer who controls your inbox almost never also controls the phone number you already had for the person.

What actually counts as a second channel

A real second channel has two properties: it's a different medium, and you initiate it. Got the request by email? Confirm by phone. Got a text? Call the number you already have stored, not the one that messaged you. The key is that you reach out through contact details you already trust — not anything supplied in the request itself.

This is where people slip: the number the caller reads out, the "confirm here" link, the reply button on the email, the extension in the text — none of those are a second channel. They're the same road wearing a disguise. If the verification route came from the message, it isn't verification.

Where it matters most: money changing direction

The highest-stakes use is any request to send money or change where money goes — a wire, an invoice, or new bank details for a supplier or employee. This is business email compromise, which the FBI tracks as a scam exceeding $55 billion in reported losses. The attacker's whole play is to get a payment redirected before anyone confirms it out of band.

The FBI's own guidance is explicit: "use secondary channels and/or two-factor authentication to verify requests for changes in account information." Make it a flat rule with no exceptions: any new or changed payment details get a call to a known number before a cent moves — even if the request looks completely routine, especially if it's marked urgent or confidential.

The family version

The same rule protects you at home. When a message claims a relative is on a new number and needs money fast — the "Hi Mum" scam — the request arrived on a channel you can't trust (an unknown number), so you confirm on one you can. The ACCC advises calling them "on the number already stored in your phone to confirm if it's no longer in use," and if you can't reach them, trying "a secondary contact method" or asking "a personal question a scammer couldn't know."

Their bottom line doubles as yours: "never send money without being absolutely sure who you are sending it to." Being sure means a second channel — not a more convincing message on the first one.

Set it up today
  1. Treat any request to send money or change payment/bank details as unverified until you confirm it on a second channel.
  2. Confirm on a different medium than the request arrived on — got an email, make a call; got a text, ring the number you already have.
  3. Always initiate the contact yourself using details you already trust. Never use a number, link, reply, or extension from the message.
  4. Make it a hard rule at work: new or changed payee details get a call-back to a known number before any payment — no urgency overrides this.
  5. For a "relative on a new number", call their saved number first; if you can’t reach them, use another contact or ask something only they’d know.

What it looks like with a supplier "bank details have changed" email:

Email Please note our bank account has changed — kindly send this month's payment to the new account below. Invoice attached.
You I'll confirm this change by phone before updating anything.
You (calls the supplier on the number from the signed contract — not the one in the email)
Supplier We never changed our details.

Frequently asked

The email came from my colleague’s (or supplier’s) real address. Isn’t that proof enough?

No. Email accounts get taken over, and attackers frequently hijack a genuine, ongoing thread — so a message from a real address is exactly what a sophisticated BEC scam looks like. The address can't verify itself; that's why the confirmation has to come on a different channel you control, like a call to a number you already had.

They gave me a phone number to call and confirm. Can I use that?

No — a number provided in the message is the same channel, not a second one. If the request is fake, the "confirmation" line will be the scammer too. A real second channel uses contact details you already trusted before this request existed: the number on a signed contract, in your saved contacts, or on the back of your card.

Isn’t calling to confirm every payment change overkill?

For routine, unchanged payments, you don't need it. The rule targets one specific trigger: money moving in a new direction — a new payee, changed bank details, or an unexpected wire. That's the narrow window BEC exploits, and a single call to a known number is trivially cheap insurance against the costliest scam category there is.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every move is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›