Module 9 of StartCloud's Cyber Hygiene for Staff learning pathway, in five short units with a knowledge check: attacks that skip technology entirely, the fake IT support call and the remote access tool behind it, the confident stranger in a hi-vis vest, tailgating through a secure door, the urgent favour supposedly from the boss, and why verifying a request is never rudeness.
The Phone Call, the Visitor, and the Favour
Attacks that skip the technology entirely
Everything so far in this pathway has involved a screen. This module does not. Some of the most effective attacks on a business use no technology at all: a phone call, a visitor, a favour asked nicely. There is nothing for a spam filter to catch, because the only thing being exploited is a person having a normal day.
The professionals call it social engineering. It is a grand name for something very old, which is convincing someone to open a door for you rather than picking the lock yourself. Three levers do nearly all the work, and you will notice none of them are weaknesses.
Somebody is stuck, running late, locked out, carrying too much. The instinct to help is a good one and most workplaces run on it. An attacker's whole job is to arrive looking like a person who needs a small, reasonable hand.
The IT department, head office, a director, a contractor sent by the building manager. Titles do a lot of quiet work. Most of us will not challenge a confident person who says they belong here, because being wrong about it feels worse than being right.
A meeting starting in two minutes, a system about to go down, a truck waiting outside. Urgency is not a side effect here, it is the whole design. Checking takes a minute, so they make sure you feel you do not have one.
Read that list again. Helpful, respectful, willing to get things done quickly. Those are the traits that make someone good to work with, and they are exactly what is being borrowed. Nobody gets caught out here because they are foolish. They get caught out because they are decent, and because a stranger counted on it.
The phone is where most of this lands, because a voice feels more real than an email and because you have to answer on the spot. The ACSC's advice for a suspicious call is refreshingly simple: take their details, hang up, and contact the organisation using a number you found yourself, not one the caller gave you.
The fake IT support call
"Hi, it's Dave from IT, we're seeing errors on your machine and I just need to get you to install a quick tool so I can take a look." The tool is real remote access software, and once it is running they are sitting at your desk from anywhere in the world. Sometimes the call starts with a text or a pop-up warning first, so it feels like they are ringing about a problem you already knew about.
- Nobody legitimate needs your password or a one-time code, ever
- Never install anything or grant remote access because of an incoming call
- Take their name, hang up, and ring IT or your MSP on the number you already have
- If your business has no IT team at all, that alone tells you the call was fake
The call that comes from your own IT team, allegedly
The other direction is just as common: someone rings the help desk pretending to be a staff member locked out of their account, and talks a helpful person into a password reset. Voices can be cloned now, and caller ID can be faked, so neither a familiar number nor a familiar voice proves anything on its own.
- Identity checks exist to protect the person being impersonated, including you
- Following the process is not being difficult, it is doing the job properly
- An impatient caller who resents being verified is a warning sign, not a VIP
- Verify through a channel the caller did not choose: ring back, or message them in Teams
This is the part people worry about, so let us settle it. If Dave really is from IT, hanging up and ringing back costs him ninety seconds and he will think nothing of it. Support teams are used to it, and plenty of them will tell you to do exactly that. The version where you are wrong is a mildly awkward phone call. The version where you are right is a very expensive week.
Now the physical version. Everything the business spends on security assumes attackers stay outside the building. Walking in is the shortcut around all of it, and it works far more often than anyone would like to admit.
A vest, a lanyard and a confident walk get people further into Australian workplaces than any password ever will. Nobody wants to be the person who challenged the air conditioning technician. The costume is doing all the work, and it costs about forty dollars at any hardware store.
You badge in, and someone walks through behind you with a coffee in one hand and a box in the other. Holding the door is polite. It is also how a swipe card system gets bypassed completely, without anyone needing to break anything. Once someone is inside, everybody assumes they were let in for a reason.
They mention your office manager by name, refer to a job that is genuinely happening, and know the company you use for cleaning. None of that is secret. Half of it is on your website and the rest came from LinkedIn. Knowing details is not the same as belonging, though it feels like it in the moment.
What they actually want is usually small: a few minutes near an unlocked computer, a photo of a whiteboard, a plug into a spare network port, a wander past the printer tray. It is over quickly and looks like nothing at all if anyone glances over.
You do not have to be a bouncer about it. "Morning, who are you here to see? I'll walk you over." That is warm, it is normal, and it completely defeats the confident-stranger routine, because a real contractor has an answer and an impostor does not. Everyone gets signed in, everyone gets walked, no exceptions for people who look like they belong.
The same goes for the door. Letting it close behind you is not rudeness, and if you feel awkward, say the friendly thing out loud: "Sorry, everyone has to badge in, it's a whole thing." A colleague will laugh and tap their card. Anyone who gets annoyed about it has just told you something useful.
The last one is the softest and the most expensive. A message arrives from the boss, or someone senior enough that you would not normally push back. "Are you at your desk? I need a quick favour and I'm heading into a meeting." Then it is gift cards, or a payment that has to go out today, or a staff member's bank details that need updating before payroll runs.
It works because refusing feels rude, checking feels like doubting them, and there is never quite enough time. That is not an accident. Every one of those feelings was placed there on purpose.
- Verify through a different channel than the one the request arrived on
- Use contact details you already had, from your own records or the internal directory
- Say it plainly: "I'll just confirm this with Sarah and come straight back to you"
- Tell someone about the odd request afterwards, even if nothing came of it
- Do not use the phone number, link or email address the request itself provided
- Do not skip the check because the person is senior or sounds rushed
- Do not buy gift cards, move money or reset an account on the strength of a message
- Do not keep a strange request to yourself because it felt embarrassing to question
This is the sentence worth carrying out of the module. Your actual manager, your actual finance officer, your actual IT person will be pleased you checked. Nobody has ever been reprimanded for ringing the boss to confirm a payment. Plenty of people have spent a very long month explaining one they did not. If someone in your workplace genuinely gets shirty about being verified, that is a problem with the culture, and it is worth naming.
A small favour for the whole team: talk about it afterwards. Mention the odd call, the visitor who did not add up, the message from the boss that was not from the boss. These attacks rely on happening to one person quietly. Said out loud in a team meeting, they stop working almost immediately, and the next person recognises it in three seconds instead of thirty minutes.
- cyber.gov.au: Social engineering, including voice phishing and impersonation
- cyber.gov.au: Protect yourself from remote access scams
- cyber.gov.au: Phone scams impersonating Australian businesses and government agencies
- scamwatch.gov.au: Report a scam to the National Anti-Scam Centre
- idcare.org: IDCARE, free support if personal information has been exposed
Impersonation tactics shift as the tools change, particularly with voice cloning, so the ACSC pages above are worth checking now and then. Details were current at the time of writing (August 2026).
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. Someone rings saying they are from IT and asks you to install a tool so they can look at your machine. What do you do?
2. Which trait do social engineering attacks actually exploit?
3. You badge through a secure door and someone in a hi-vis vest walks up behind you carrying a box. What is the right move?
4. A message that looks like it is from your managing director asks you to urgently buy gift cards and send the codes. What do you do?
5. Why does verifying a request never count as rudeness?