E-mail lets you pause; a live call pushes for instant action. Attackers may pose as “Microsoft,” the bank, police, or “IT,” mixing data from public leaks (name, company, role).
Rule: do not complete sensitive steps over an unexpected call. Real IT more often opens a ticket or uses known channels. Never install remote-control software on a stranger’s say-so.
Why voice beats a sloppy phish
A human voice adds “do it now” pressure. The caller may browse your site or old breach dumps to sound informed. Some campaigns pair mail with a follow-up call about an “urgent ticket” — both are fake.
After AnyDesk/TeamViewer-style installs, the attacker drives your desktop like you do. Many firms block those tools or require ticket approval first.
For smaller teams
A one-pager helps: “IT will never ask for your password or surprise AnyDesk installs.” Front desk can transfer internally — but “I’ll patch you through to tech” without verification is a red flag.
Phone + e-mail combos feel credible — stick to agreed channels. It is fine to say “I will call back using the number from our intranet” and hang up.
“Grandchild in trouble,” police, or “the CEO”
The same playbook hits consumers: a voice in distress (“I need bail”), a relative on a “new number,” or an “executive assistant” demanding an instant wire. Common tricks: forbid verification (“don’t tell Mom”) and extreme urgency.
Defense is simple: end the call and ring back on a saved or official number. Families use a safeword; businesses use dual payment approval. More in family and friend impersonation.
Synthetic voice and deepfakes
Short clips from social video or voicemail can now fuel convincing synthetic speech — especially effective late at night. Tech improves; verification rules stay the same: no instant money, call back on a known number, use a shared secret attackers cannot Google.
Pairing calls with SMS links
A classic combo: a text with a link, then a caller who “helps” you open it. Each channel looks weak alone; together they feel legitimate. Unified rule: no unknown links or installs from SMS or voice prompts — see smishing.