Business email compromise is primarily email-based fraud, often using impersonation or spoofing to persuade a victim to transfer money or disclose information. TOAD, or telephone-oriented attack delivery, starts in email but pushes the victim to call a number, where the attacker can coax credentials or malware installation. The key difference is the pivot from email deception to phone-based interaction.
Why BEC and TOAD diverge in live phishing operations
The distinction matters because the attacker’s objective changes the whole interaction model. BEC is usually designed to complete an email-led fraud path, such as redirecting payment or eliciting sensitive business information, while TOAD uses email only as the first lure and then moves the victim into a phone conversation where social engineering can become more adaptive and harder to review later. That difference affects detection, response, and user training, because the decisive step is no longer confined to the inbox. In real campaigns, defenders often underestimate how much attacker control increases once the conversation leaves written channels.
For teams studying identity-adjacent abuse patterns, the most useful reference point is the OWASP Non-Human Identity Top 10, because it reinforces how trust in credentials, contacts, and workflow context can be manipulated even when the initial lure is not technical.
In practice, many security teams only notice the difference after the fraud path has already moved from mailbox controls into human-led persuasion.
How the campaign mechanics differ once the victim leaves email
BEC typically depends on message credibility: a convincing sender identity, a plausible business pretext, and a request that fits an existing workflow. The attacker tries to make the victim act quickly without changing channels. That means the campaign can succeed with relatively little back-and-forth if the target accepts the email as authentic enough. TOAD is more interactive. The email acts as a trigger, but the phone call lets the attacker answer objections in real time, redirect the conversation, and create urgency with voice-based pressure. That extra interaction can make TOAD more resilient when inbox filtering blocks some obvious fraud patterns, because the payload of the attack is no longer contained in the message itself.
For defenders, that distinction changes what evidence matters. BEC investigations often focus on email headers, impersonation indicators, mailbox rules, and payment or invoice workflow abuse. TOAD investigations need to include call-back numbers, voicemail cues, callback timing, and whether the victim was directed to install software, share a code, or approve access under pressure. Where the email asks the recipient to move the conversation off-platform, the risk often rises because the attacker can steer the victim away from normal verification steps.
- BEC tends to optimise for one convincing message and a fast business action.
- TOAD tends to optimise for live coercion after the first lure.
- BEC is easier to anchor in email logs and workflow evidence.
- TOAD requires wider telemetry because the decisive abuse happens outside email.
That guidance breaks down when the phishing flow mixes both tactics, because some campaigns use email, phone, and chat in sequence rather than as separate patterns.
Where the edge cases blur the label
Tighter classification often improves investigation quality, but it also creates overhead, so organisations have to balance simple labels against mixed attack chains. A campaign can start as BEC and then add a call-back step, or begin as TOAD and end with invoice fraud, credential theft, or remote-access abuse. Industry usage is not fully standardised here, so analysts should describe the observable behaviour rather than force a perfect taxonomy when the campaign straddles categories.
The most important edge case is the callback number that simply confirms a payment request versus the callback number that becomes the primary social-engineering channel. The first is still closer to BEC with a verification twist. The second is materially TOAD because the phone interaction becomes the attacker’s main delivery mechanism. Another common ambiguity is when the email contains no malware itself, but the call leads to software installation or credential capture. In those cases, the delivery mode matters more than the final impact, because the path the victim follows tells you which controls failed first.
For practitioners, the label should follow the dominant control break: email deception, live voice manipulation, or a blended sequence. That distinction is more useful than debating whether a single campaign “counts” as one acronym or the other.
Risk and Threat Considerations
Both patterns create financial, credential, and workflow-abuse risk, but TOAD usually increases the attacker’s ability to adapt during the interaction. Once a victim is on a call, the attacker can respond to hesitation, exploit urgency, and steer around normal written verification controls. BEC is often more dependent on the credibility of the initial message, while TOAD is more dependent on the attacker’s ability to sustain pressure and keep the victim engaged.
Failure mechanism: the control failure is not just email compromise or spoofing, but the collapse of verification boundaries when a user treats a phone call as inherently more trustworthy than the original message. That can bypass inbox filtering, invoice review, and some approval workflows because the attack shifts into an unlogged or weakly logged conversation channel.
Impact: the likely result is unauthorised payment, credential disclosure, malicious software installation, or a broader fraud chain that is harder to reconstruct after the fact because part of the social engineering occurred off email.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Identity Inventory and Ownership | Phishing campaigns abuse trusted identities and contact paths. |
| Recommendation — Inventory and verify trusted identities that attackers can impersonate or redirect. | ||
| CIS Controls v8 | 14 — Security Awareness and Skills Training | BEC and TOAD both rely on user social-engineering failure. |
| Recommendation — Train users to verify payment and callback requests through independent channels. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Phishing seeks credential theft and improper access. |
| Recommendation — Enforce strong authentication and verify high-risk requests before granting access. | ||
| MITRE ATT&CK | T1566 — Phishing | Both BEC and TOAD are phishing variants with distinct delivery paths. |
| Recommendation — Map observed lures to T1566 and differentiate email-only from callback-driven activity. | ||
Practitioner Guidance
What to prioritise: Treat callback escalation as a higher-risk branch whenever an email asks the recipient to move off-platform. The key decision is whether the message is merely fraudulent email or the start of a live persuasion sequence, because that changes the evidence you need and the speed of escalation.
What to verify: Confirm whether the same number, mailbox, or identity is reused across multiple lures, and whether the call path was used to request payment changes, codes, or software installation. That evidence usually separates a simple impersonation attempt from an operational TOAD campaign.
Practitioner takeaway: The main mistake is treating TOAD as “just BEC with a phone call”; once the victim leaves email, the attacker gains a more flexible social-engineering channel and defenders lose some of the traceability they would normally rely on.
Related resources from NHI Mgmt Group
- What is the difference between batch campaigns and real-time personalization?
- What is the difference between traditional email security and behavioural AI for stopping modern phishing campaigns?
- What is the difference between changing port 22 and real SSH hardening?
- What is the difference between a policy violation and a real risk scenario?