Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

News

What is a "Multi-Channel Attack" leading from email to LINE? Latest tactics and countermeasures explained.

Learn how CEO fraud lures victims from email to LINE groups by impersonating executives. This post explains why QR codes and personal devices are targeted, simulates attacks combining SMS and phone calls, and outlines key prevention steps through employee training and verification protocols.

AI SOCとは? 仕組み・従来型SOCとの違い

Imagine arriving at work on a Monday morning to find an email with the subject line "Business Adjustment," sent under the name of your executive or direct supervisor.

At first glance, it looks like an invitation to a highly confidential project or an urgent consultation. However, the instructions are highly unusual. Rather than a phone call or face-to-face meeting, the sender asks you to create a new LINE group and send them the QR code.

Example of an actual observed email draft

フィッシングメール事例

You might think, "I would never fall for that." But what if the sender was the president or an executive, and the body of the email was marked "URGENT"?

This is not mere spam. It is the entry point of a highly targeted attack designed to make employees bypass the corporate security perimeter from the inside using their own hands.

This tactic combines two major trends in modern cyberattacks: multi-channel attacks and CEO fraud.

The Global Surge in "Multi-Channel Attacks"

Why do attackers choose not to complete the fraud within the email itself, opting instead to go through the trouble of moving the conversation to LINE? They do so with a clear objective: to neutralize the organization's defense networks.

Evading Log Monitoring and Audits

With corporate email, all correspondence is logged on servers and can be audited by the IT security department. However, the moment the interaction shifts to consumer tools like personal smartphones or LINE, the company loses all visibility into the conversation. The attacker deliberately engineers a "shadow IT" environment, pulling the victim into a monitoring blind spot.

Bypassing Security Filters

Modern email filters are highly effective. They quickly detect and quarantine suspicious attachments or fraud-specific keywords like "change bank account details." To bypass this, attackers use email only for innocuous business contact, moving to the unmonitored "closed room" of LINE before introducing their real agenda, such as money requests or malware transmission.

The "Image" Barrier of QR Codes

If a URL link is pasted into an email, anti-phishing systems analyze the destination and trigger alerts. Requesting or sharing a QR code "image" allows attackers to bypass these text-based analyses and URL filters. Attackers are highly adept at exploiting these technological gaps.

Generative AI is Accelerating Legacy "CEO Fraud (BEC)"

Beyond technical evasion, the core of this attack lies in psychological manipulation. The critical difference from legacy Business Email Compromise (BEC) is that generative AI has completely dismantled the "awkwardness" barrier. Detection signals we used to rely on—such as unnatural phrasing or subtle etiquette errors—no longer apply.

Abusing Authority: AI Style Mimicry and Forced Compliance

Subject lines like "Business Adjustment" or "Urgent" paired with an executive sender profile are classic social engineering tactics leveraging "authority." Generative AI has significantly amplified this capability. Attackers train AI on past interviews, social media posts, and public emails of a CEO to perfectly replicate their unique phrasing and communication style.

When presented with a scenario where "the president needs to contact you immediately but cannot take calls," it is psychologically difficult for a subordinate to flatly refuse. If the message reads exactly like something the president would write—urgent yet appreciative—any suspicion is quickly replaced by a sense of duty.

Isolation via Confidentiality: Plausible AI-Generated Scenarios

Instructions like "do not invite anyone else" are not for confidentiality; they are to prevent the victim from consulting colleagues or IT. Isolating victims to impair critical thinking is a standard BEC tactic, but generative AI makes it far more effective.

If a victim attempts to reply with "I need to verify this with my manager first," the AI instantly generates a highly plausible narrative (such as highly confidential M&A negotiations or a special internal audit mission) explaining exactly why no one else can know. This real-time, automated persuasion corners victims into a dead end where they feel unable to consult anyone.

The Most Deceptive Tactic: Leveraging the "IKEA Effect"

The most calculated element of this scheme is that the attacker does not send an invite link; instead, they instruct the victim to create the group and act as the owner.

Typically, users are wary when receiving a link from an unknown source (passive). However, in this attack, the victim actively takes steps to create the group (active).

This exploits the "IKEA effect" (the cognitive bias where consumers place a disproportionately high value on products they partially created) and the illusion of control. The fact that "I created this group and invited the members" reinforces the false assumption that "this is a safe space under my control." By making the victim perform this extra step, the attacker successfully lowers their guard.

What Happens After Joining the LINE Group?

The moment you reply with the QR code and the self-proclaimed CEO joins the LINE group, the conversation moves entirely beyond corporate visibility. Expected scenarios include:

  1. Financial Demands (Gift Card Fraud)

    • Demands like "I urgently need Apple Gift Cards for a client gift. Buy them now and send me the codes; I will reimburse you later." While legacy, sending images over LINE is highly intuitive, making it easy to force compliance.

  2. Credential Phishing

    • Attackers send a link to a fake site mimicking cloud storage (such as Box or Google Drive), claiming there are "documents that require urgent review." Entering your ID and password compromises your corporate account.

  3. Malware Infection

    • Under the guise of a "security patch" or "new business app," victims are tricked into installing malicious files (such as Android APKs), allowing attackers to exfiltrate all data from the mobile device.

Emerging Multi-Channel Attack Scenarios

Because many businesses do not use LINE for daily operations, redirecting targets to chat apps historically limited the pool of viable victims. Globally, attackers are increasingly shifting to phone calls and SMS to bypass this barrier.

Organizations must now prepare for hybrid attacks that combine SMS with voice elements.

Phase 1 (Initiation): The victim receives an SMS alert, such as "Urgent security notice" or "Issue with payroll account details."

Phase 2 (Trust Hijacking): Clicking the link opens a highly convincing spoofed site with a prompt stating: "Please contact the department in charge immediately at this number."

Phase 3 (Voice Compromise): Upon calling, the victim is greeted by fluent interactive voice response (IVR) or an attacker using a real-time AI voice changer, who then instructs them to enter credentials or initiate a wire transfer.

The attack vector is evolving from text to voice. Exploiting the human cognitive vulnerability to trust a voice over text, this method carries a much higher success rate and financial risk than LINE-redirection attacks. Moving beyond 2025, defenders must solve the new challenge of verifying voice traffic integrity.


Required Countermeasures Against Next-Gen Attacks

The most urgent priority is a fundamental overhaul of security awareness training. Legacy training focusing on "identifying suspicious URLs" or "spotting unnatural language" is obsolete in the age of generative AI. Current phishing emails and voice lures feature flawless business etiquette and local phrasing.

Next-gen security training must focus on recognizing psychological manipulation (social engineering) rather than trying to visually verify digital data integrity.

  1. Healthy skepticism of authority. Even if instructions appear to come from the CEO or an executive, employees must have the confidence to pause and verify if the request deviates from standard operating procedures (such as requesting gift cards or moving to personal chat apps).

  2. Resilience to artificial urgency. Organizations must train employees to recognize terms like "immediate" or "urgent" as psychological pressure tactics, encouraging them to slow down and verify requests through out-of-band channels.

  3. A culture that rewards verification. Organizational structures where "doubting the CEO is considered disrespectful" represent a critical vulnerability. Companies must foster a Zero Trust Culture where pausing to verify a request is recognized as a protective action, not insubordination.


Related Services: Click here to learn more about Yagura Awareness, which automates AI-driven security training and simulation across multiple channels including email, SMS, LINE, and voice.

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化や

サービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。