The Multichannel Scam Problem Isn’t the Channels: It’s the Case File
In February 2024, a finance employee at the engineering firm Arup joined a video call to authorize what he’d been told was a confidential transaction. He’d already received a message from someone claiming to be the UK-based CFO, followed by what looked like a routine internal meeting request. On the call, several colleagues appeared alongside the CFO, all recognizable, all speaking naturally. He had reservations, the CFO “looked a little off,” but every other participant on the call confirmed the request. He authorized the transfer. The company moved HK$200 million, about $25.6 million, before anyone realized every face on that call had been synthetically generated from footage scraped out of past company meetings.
Coverage of the Arup case focused on the deepfake, understandably. But the deepfake wasn’t the whole mechanism. The scam worked because it moved: a written message established the premise, a meeting invitation moved the target into a trusted format, and a video call supplied the final layer of social confirmation. No single channel carried the fraud. The sequence did.
A Coordinated Phishing Campaign Rarely Stays in One Inbox
Multichannel phishing follows the same logic at higher volume. A message arrives by email, then a near-identical version shows up as a direct message on LinkedIn, then a text, then an in-app notification, each one reinforcing the last and expanding the surface area a target has to evaluate before deciding what’s real.
What makes these campaigns durable is the use of compromised accounts on services people already trust. Platforms like LinkedIn, Microsoft 365, and Slack get borrowed for exactly this purpose, because a phishing message arriving through infrastructure the recipient already relies on clears a trust bar that a cold email never could. When a customer or partner is compromised this way, the reputational cost lands on the brand whose name appeared in the message, not on the platform that hosted it.
This isn’t a marginal problem. A 2023 Forrester study commissioned by Cloudflare found that four out of five security decision-makers had faced a multichannel phishing attack in the prior twelve months, and 90% believed the scope of the threat was still expanding. Most also said they weren’t prepared for it. The gap isn’t awareness. It’s that “prepared” still tends to mean prepared per channel.
Why Enforcement Structures Lag Behind the Attack Structure
Here is the part that doesn’t show up in most incident write-ups: the teams responsible for stopping this are typically organized the same way the old, single-channel threat was. Email security owns the inbox. A social media monitoring function owns impersonation on Instagram, TikTok, and LinkedIn. Domain and marketplace takedown work sits somewhere else. Executive protection, if it exists, is its own line.
Each of those functions can be genuinely good at its job and the seams between them can still be where the scam survives. A redirect domain flagged and taken down by one team can keep operating under a case opened by a different team that never learned the domain had already been reported once. A voice model used in one CFO-impersonation attempt can resurface in a second attempt against a different company with no mechanism connecting the two, because nothing in either case file was built to ask.
The MrBeast deepfake case illustrates the same structural gap from the demand side. In 2023, ads using a synthetic version of the creator’s likeness circulated on TikTok offering iPhones for two dollars, a scam built specifically to invert his actual reputation for giving products away. The ad lived on one platform; the checkout page lived on another. Reporting the ad didn’t touch the storefront collecting payment information, and reporting the storefront didn’t touch the next ad using the same footage on a different account.
Detection Is Not the Bottleneck Anymore
It’s worth being precise about what has actually changed. Detecting a phishing email, a cloned voice, or a synthetic video is a hard, ongoing technical problem, and AI-driven detection tools have made real progress on it. But detection answers “is this fake,” not “have we seen this actor before.” Those are different questions, and enforcement teams have gotten reasonably good at the first one while still treating the second as an afterthought, something an analyst might notice if they happen to remember a similar case from three months ago.
That’s not a criticism of any single team’s competence. It’s a description of how most brand protection and fraud operations are still structured: around channels and around cases, not around the infrastructure, the redirect domains, compromised accounts, voice models, payment handles, that actually persists across both.
What Tracking the Actor Instead of the Channel Would Require
A response built around the actor rather than the channel would need a few things most channel-specific tools don’t provide by default: a way to check a new report against every prior case that touched the same domain, image asset, or account, regardless of which team opened it; a shared record of infrastructure, not just closed tickets, so a takedown produces reusable intelligence; and enough visibility across functions that a pattern spotted in email phishing can inform what the social media and marketplace teams are already watching for.
None of this requires abandoning channel-specific expertise. Email security still needs people who understand email. The correlation layer sits on top of that expertise rather than replacing it, and it’s the layer most organizations haven’t built.
Questions Worth Asking About Your Own Setup
Before assuming the next multichannel case is a one-off, it’s worth checking a few things: Can a report filed against a phishing email be checked against every prior report touching the same sender infrastructure, regardless of which channel filed it? If a redirect domain gets taken down once, does anyone find out when it reappears in a listing three weeks later? When a deepfake or cloned voice surfaces in one incident, is there anywhere that asset gets logged so the next investigator doesn’t start from zero? And if the answer to any of that depends on one analyst remembering a similar case, what happens when that analyst is out, or the case load triples?
This is where an AI-native investigative environment earns its place in the conversation, not as a bigger case management tool, but as the layer that keeps a redirect domain, a compromised account, or a voice model visible across every channel it touches, so a takedown in one place actually informs the next report in another.
The Arup case cost $25.6 million and took three channels to pull off. The more useful question for any brand protection or fraud team isn’t whether they could detect that particular sequence. It’s whether their case files would have shown the message, the meeting, and the call as one actor, or three separate incidents waiting to be connected by whoever happened to notice.