Out-of-band verification means confirming a sensitive request through a separate trusted channel, such as calling a known phone number, using a pre-registered mobile app, or checking in person. The goal is to avoid trusting the same email thread, chat account, or web session that delivered the request in the first place.
This control matters because attackers often impersonate executives, vendors, or banks and then try to rush staff into changing payment details, resetting passwords, or approving transfers. If the original channel is compromised, the request may look legitimate. Defenders use out-of-band verification to break that trust chain: finance teams confirm banking changes with a known contact, administrators validate reset requests with another approved path, and incident responders verify unusual instructions before acting. In ransomware and business email compromise cases, it is a simple but effective way to stop fraud and account takeover.


