How hackers have turned our safety net against us
I’d been wanting it for months. When I saw it was 40% off, I bought it right away. A moment later, I started to worry. Was the deal too good to be true? Soon after, I got a bank notification, then a confirmation email, and finally a message from the courier… I felt relieved.
For years, these follow-up messages have made us feel safe. Each one confirmed the last, and the more I received, the more relaxed I became.
But now, hackers use that sense of security as a secret weapon.
Hackers have reverse-engineered the same mechanic. Multi-channel attacks are now some of the fastest-growing threats at work. The messages that made me feel safe at home are now giving employees a false sense of security and letting attackers slip past important security checks.
How our trust gets hijacked
These attacks work for a reason. Security tools usually only watch one channel at a time, so it’s hard to spot when different messages are part of the same attack. Each attack might look different, but the steps to gain our trust are often the same.
Step 1: Make sure the first message gets through
You get an email asking for an urgent change to payment details. By itself, it doesn’t stand out. It doesn’t have to be convincing yet, because the next messages will build on it.
All our training is meant for this moment: check who sent it, hover over the link, and spot the urgency. That usually works. But what if a second message shows up?
Step 2: Use the next messages to persuade
Twenty minutes later, you get a text about the same request, then a message in the team chat: “Tried calling about something urgent, will try again shortly.”
Just like after my purchase, the more I saw the same message, the more I believed it. Nothing about this feels suspicious. Now it just feels like confirmation.
Step 3: Watch as repeated messages become proof
This is the real trick. Attackers know that when messages are consistent, it feels like proof. So they call the employee and mention the whole conversation from email, text, and chat.
Each step is meant to build the employee’s trust. The attacker keeps confirming the story until they’re sure, and only then do they make their move.
If the attacker just called with the same request, our training would kick in. But when it’s part of a bigger plan, that training can be bypassed.

Introducing step 4: Taking back control
That night on my sofa, three confirmations were enough to make me relax. At work, those same three steps can convince someone to give away real money or important data. The feeling is the same.
AI now makes it easier than ever to create convincing attacks quickly, so our training needs to change too. The question we’ve learned to ask, “Is this convincing?”, doesn’t protect us anymore. Proof can look just as real as a lie.
The only real test is to find out who actually sent the message. Contact the sender using a number or address you already trust, or go old-school and walk over to ask them in person.
Until you confirm otherwise, the message stays suspicious. In the workplace, the safest mentality is one of ‘guilty until proven innocent’.
This approach won’t work if employees are left to handle it alone, hoping they’ll spot attacks under pressure while leaders stay silent. Leaders, managers, and executives need to understand these attacks just as well as frontline staff. People who ask, “can I call you back on a number I already have” need to know their questions are welcome, not resented. If someone gets a strange look for double-checking, they’ll stop doing it. This habit only lasts if it’s clearly supported from the top.
So the solution isn’t just being more careful. It’s creating a workplace where asking for proof is encouraged and rewarded.
This article was written by Cywareness, a company specializing in cybersecurity awareness.
As part of its mission, Cywareness continues to monitor emerging trends, analyze real-world attacks, and share practical insights to help organizations stay ahead in today’s evolving threat landscape.