Attack technique

Barrel Phishing

Barrel phishing, also called double-barrel phishing, is a two-stage attack in which a harmless first email builds trust and rapport, so that the second email carrying the malicious link or request slips past the recipient's guard.

Definition

Barrel phishing, also known as double-barrel or double-barreled phishing, is a social engineering technique that splits an attack across two emails. The first message is deliberately benign, containing no malicious link, attachment, or request, and exists only to appear legitimate and establish a rapport with the target. Once that initial trust is set, the attacker sends a second email that carries the actual payload, such as a malicious link, a fraudulent invoice, or an urgent money transfer request. Because the follow-up appears to continue a conversation the recipient has already accepted, it faces far less scrutiny than a cold, standalone phishing email.

A barrel phishing attack unfolds in two deliberate stages. In the first, the attacker sends an innocuous message, perhaps a friendly introduction, a routine question, or a note referencing a shared context, that contains nothing harmful. This primer email is designed to lower the recipient's guard and create a sense of an ongoing, legitimate relationship. Antivirus and link scanners find nothing to flag because there is nothing malicious to detect yet. In the second stage, the attacker sends the real phishing message: a link to a spoofed login page, a poisoned attachment, or a request such as an urgent wire transfer or a shared file that is supposedly too large to attach.

A common example plays out as impersonation of a senior executive. The attacker first sends a short, harmless message like "Are you at your desk?" or "I need your help with something quick," which draws a reply and establishes a thread. The follow-up then asks the employee to pay an invoice, buy gift cards, or move funds urgently. Another pattern imitates a file-sharing service: the first email says a document is on its way, and the second directs the recipient to a counterfeit login page under the pretext that the file was too large to attach. Attackers often research their targets on social media first, so the messages reference real projects, colleagues, or events.

Barrel phishing matters because it defeats the instinct to distrust a single unexpected email. By the time the malicious message arrives, the recipient already perceives an established, credible exchange, and people rarely re-scrutinise the second or third message in a conversation the way they would the first. This makes the technique a natural vehicle for business email compromise and spear phishing, and effective against busy staff who are used to fast back-and-forth email. Defenses center on verifying any request that involves money, credentials, or sensitive data through a separate, trusted channel, regardless of how friendly or familiar the preceding email felt.

At a glance

Severity
High
Prevalence
Common in targeted BEC campaigns
Primary targets
Employees in finance, HR, and executive support roles who handle payments, credentials, or sensitive requests over email

How it works

  1. 1

    Reconnaissance: the attacker researches the target on social media and public sources to learn about colleagues, projects, and communication patterns.

  2. 2

    First barrel: a harmless email with no link, attachment, or request is sent purely to appear legitimate and open a conversation.

  3. 3

    Trust established: the recipient replies or mentally accepts the thread as genuine, lowering their guard for what follows.

  4. 4

    Second barrel: the real phishing message arrives, carrying a malicious link, a poisoned attachment, or an urgent request for money or data.

  5. 5

    Payload delivered: because it continues an accepted conversation, the follow-up faces little scrutiny and the recipient clicks, replies, or pays.

Warning signs

  • A first email that is oddly vague or contentless, seemingly just opening a conversation
  • A friendly or urgent follow-up that suddenly asks for money, gift cards, credentials, or a file
  • Requests that deviate from how a colleague or vendor normally communicates
  • A sender name that looks right but an email address that is subtly wrong
  • Follow-up messages that reference personal or company details gathered from social media

How to defend

  • Verify any request involving money, credentials, or sensitive data through a separate, trusted channel such as a phone call
  • Do not treat the second or third email in a thread as automatically safe just because the first seemed harmless
  • Check the sender's full email address, not just the display name, on every message in a conversation
  • Be wary of file-sharing pretexts claiming a document was too large to attach
  • Report suspicious two-part exchanges to your security team, even if the first email seemed innocent

Real-world example

A finance officer at a Jakarta manufacturing firm receives a short email from someone appearing to be the CFO: "Are you at your desk? I need help with something time-sensitive." She replies, and moments later a second email asks her to urgently transfer funds to a new supplier account before end of day. Because the exchange felt like a normal conversation with her boss, she nearly processes the payment before a colleague suggests she call the CFO to confirm, revealing the account was fraudulent.

How Claro helps

Claro helps organizations build resistance to barrel phishing by running multi-stage phishing simulations that mirror the real technique: a benign rapport-building email followed by a malicious ask, then measuring who engages, who reports, and who verifies through a second channel. When a user interacts with a simulated follow-up, Claro delivers just-in-time awareness and targeted micro-module training on treating every request for money, credentials, or data as something to confirm independently, no matter how established the conversation feels. Combined with risk scoring and an easy phish-reporting workflow, Claro turns barrel phishing from an invisible, trust-based threat into a measurable, trainable behavior, with bilingual content and OJK, BSSN, ISO 27001, and PDP-aligned reporting for Indonesian regulated industries.

Frequently asked questions

How is barrel phishing different from regular phishing?

Regular phishing usually relies on a single email carrying the malicious link or request. Barrel phishing splits the attack in two: a harmless first email builds trust, and only the second email delivers the payload, so the malicious message arrives inside an already-accepted conversation.

Why is the first email harmless?

The benign first email exists to lower the recipient's guard and establish rapport. It contains nothing malicious, so security filters find nothing to flag, and by the time the real request arrives the recipient already perceives a legitimate, ongoing exchange.

How is barrel phishing related to business email compromise?

Barrel phishing is a common technique used to carry out business email compromise. The trust built by the first email makes the fraudulent payment or data request in the second email far more likely to succeed.

What should I do if I get a friendly email followed by an urgent request?

Do not act on the request based on the conversation alone. Verify it through a separate, trusted channel such as a direct phone call to the person, and report the exchange to your security team, even if the first email seemed completely innocent.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo