Attacks that are not by message.
WHAT HAPPENS
A caller claims to be from a supplier, a bank, a service provider, or your own organisation.
They request information, access, or an action.
WHAT THEY MAY ALREADY KNOW
Details that make them credible: names, references, recent events.
Knowing things is not proof of identity.
WHAT TO DO
Do not act on an inbound call requesting anything sensitive.
End it, and call back on a number you already held.
WHAT LEGITIMATE ORGANISATIONS ACCEPT
Being called back.
Anyone objecting to verification is the warning.
WHAT TO NEVER PROVIDE ON AN INBOUND CALL
Passwords Verification codes Payment details Remote access to a device
THAT LAST ONE
A caller asking to connect to your computer is attempting to take it.
FOR PEOPLE ARRIVING IN PERSON
Verify who they are before granting access to equipment or areas.
WHAT TO TELL STAFF
The procedure, and that following it is never a problem.