Hello.
Another common social engineering technique is vishing.
In this case, the scam is carried out via a phone call in which the attacker impersonates a trusted person or organization.
Their goal is to obtain information or credentials, or to get us to take an action without verifying the request.
These calls may appear to come from:
- Banks,
- Suppliers,
- Technical services,
- Coworkers.
During the conversation, they usually convey:
- emergency,
- raise concerns
- to present a situation that requires immediate action.
All of this is meant to get us to make a quick decision before verifying whether the request is legitimate.
You know, be wary of:
- Unexpected calls.
- Requests for sensitive information.
- Unusual requests.
- People who pressure you to act quickly.
Before providing any information or taking any action, always verify the caller’s identity using an alternative channel.
Stop, think, and check.
If you have any doubts, end the call and confirm the request through official channels.
Because when it comes to vishing, a single conversation can be enough to set up a scam.
Think before you answer.
IMPORTANT NOTE:
If, despite complying with all these measures, you encounter situations that do not conform to the level of security required or established in internal policies, do not hesitate to inform your line manager, the Security Manager, security personnel and/or the IT department, depending on the type of suspicion.
If it happens to you on a personal level, report it directly to the police authorities, so that they can give you appropriate advice and conduct an investigation.
