Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› How should security teams defend against multi-step phishing…
Threats, Abuse & Incident Response

How should security teams defend against multi-step phishing when secure email gateways miss the second-stage payload?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Threats, Abuse & Incident Response

Security teams should treat the first click as only one stage of the attack and inspect the full user journey, not just the email message. Detection must correlate link redirects, identity context, sender behavior, and destination reputation across steps. Behavioral baselining helps surface anomalies when a trusted platform is abused to lead users toward credential theft or OAuth abuse.

How to defend when the email gateway only catches the first step

Security teams need to move from message-level filtering to journey-level detection. Multi-step phishing often uses a benign first email, then shifts the victim through redirects, cloned login pages, or consent prompts after the gateway has already allowed the message. The defense challenge is not just blocking mail, but correlating what the user clicked, where they were sent, and what the destination tried to collect.

The first-stage email is often only the delivery mechanism. The real risk emerges later, when a trusted domain, URL shortener, cloud app, or compromised inbox thread is used to carry the victim into credential theft, session hijacking, or OAuth consent abuse. That means defenders need visibility across email, web, identity, and endpoint signals, not just attachment and URL verdicts at delivery time.

Teams should also treat reputation as dynamic rather than static. A destination that looks clean at click time may become malicious after the message is sent, and a previously trusted platform can be abused to host the second-stage payload or proxy the victim into a credential capture flow. Behavioral baselines help because the relevant anomaly is often not the message itself, but the unusual sequence of redirects, prompts, and account interactions that follows it.

What effective detection has to correlate

To catch these campaigns, the control point has to follow the path across stages. That usually means correlating URL expansion, redirect chains, browser activity, login events, and consent grants with sender behavior and destination reputation. A security team that only scans the original email body will miss campaigns that are intentionally staged so the payload appears after a delay or after a user is already outside the mail channel.

The most useful detections are sequence-based. For example, one weak signal might be a legitimate-looking message from an internal or partner account, another is an unusual redirect chain, and a third is an authentication or OAuth event that does not fit the user’s normal pattern. None of those signals alone may justify an alert, but together they show a phishing chain that has moved past the gateway and into account compromise territory.

This is where identity context matters. If the second stage asks for password entry, MFA approval, token consent, or reauthentication from a new device or location, the defender should interpret that as part of the phishing workflow, not as an isolated login event. The same applies when the payload is delivered through a cloud app or shared document platform, because the attacker is exploiting the trust relationship around the platform as much as the content itself.

Why second-stage payloads evade traditional email controls

Second-stage payloads evade secure email gateways because the dangerous content is often not present in the original message. The email may only contain a harmless lure, a link to an intermediate page, or a trusted service that later serves the malicious step. That breaks any control model that assumes the initial URL verdict or attachment scan is enough to judge the entire attack.

Another common failure mode is overreliance on sender reputation and brand recognition. Attackers can abuse compromised accounts, tenant-to-tenant trust, or familiar SaaS platforms to make the first interaction appear safe. Once the user is on the destination, the campaign can switch tactics, such as presenting a login page, prompting OAuth consent, or asking for reauthentication after an initial redirect. By then, the email gateway has already done its job from a narrow perspective, even though the phishing flow is still in progress.

Defenders should expect the payload to be distributed across time and services. The malicious step may arrive through a redirected page, a dynamically generated form, a cloud-hosted file, or a token request that only becomes visible after the user clicks. That is why the response needs to combine email security with web telemetry, identity logs, and endpoint visibility, rather than treating mail as the whole attack surface.

Risk and Threat Considerations

Multi-step phishing raises the chance of false confidence: the gateway blocks the obvious lure, but the user still reaches the credential theft or consent stage through a later redirect or trusted platform. The attack becomes harder to detect because each step can look plausible on its own, especially when the second stage is delivered outside the mail channel.

Failure mechanism: The attacker separates delivery from exploitation, then uses redirects, compromised accounts, or cloud-hosted pages to move the victim from an allowed email into a malicious authentication or consent flow.

Impact: Teams lose the ability to rely on single-message inspection, which increases the odds of credential compromise, token theft, and account takeover even when the original email was quarantined or scored low risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1566 — PhishingPhishing is the delivery pattern behind multi-step email-to-web compromise chains.
T1078 — Valid AccountsSecond-stage payloads often pivot into account abuse after the initial click.
Recommendation — Map multi-stage lure activity to T1566 and correlate the click path across mail, web, and identity telemetry. Detect use of valid accounts after suspicious redirects or reauthentication prompts.
NIST CSF 2.0DE.CM-01 — Networks and network services are monitored to detect potential cybersecurity eventsJourney-level detection needs monitoring across redirects, destinations, and follow-on activity.
PR.AA-05 — Managed identities and access are authorized before resources are accessedOAuth abuse and credential theft exploit weak authorization decisions after the lure.
Recommendation — Extend monitoring beyond the email message to correlate redirects, web activity, and identity events. Enforce strong authorization and consent controls for access requests triggered by phishing.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingCorrelating multi-step phishing depends on reviewing linked events across systems.
IA-2 — Identification and Authentication (Organizational Users)The second-stage payload often targets organizational user authentication to gain access.
Recommendation — Review and analyze linked email, web, and identity audit records for multi-step phishing. Strengthen user authentication flows that attackers try to hijack after the first click.
OWASP API Security Top 10API2 — Broken AuthenticationPhishing often lands in authentication abuse after the initial redirect chain.
API6 — Unrestricted Access to Sensitive Business FlowsOAuth consent abuse and similar flows can be weaponized as the second stage of phishing.
Recommendation — Treat suspicious post-click authentication attempts as broken-authentication signals. Restrict high-risk business flows that can be abused after a user is lured off-email.
NIST SP 800-63Phishing-Resistant AuthenticationPhishing-resistant authenticators reduce the chance that redirected login pages can steal reusable credentials.
Recommendation — Prefer phishing-resistant authenticators for accounts exposed to multi-step phishing.

Practitioner Guidance

What to verify: Confirm that your detections can stitch together the click path end to end, including URL expansion, intermediate redirects, login prompts, consent events, and the resulting identity activity. If those steps live in separate tools and never get correlated, the second-stage payload will stay invisible.

What to prioritize: Focus first on high-value accounts, external sharing workflows, and SaaS destinations that can launch authentication or consent flows. Those are the paths most likely to turn a single click into session theft or OAuth abuse, even when the email itself looks ordinary.

Practitioner takeaway: The control objective is not to make the email safer in isolation, but to detect when a benign first interaction is being used to drive the user into a later compromise stage that only becomes visible after the message has left the gateway.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org