Originally a 2022 article adapted from The Technology Press. Rewritten as practical guidance on 15 September 2026; original URL retained.
The scam follows the conversation
A message can borrow the name of a supplier, colleague or support team. It may ask you to sign in, scan a code, change payment details or approve an unexpected request.
This article began as a 2022 trends piece. Old attack percentages have been removed; the useful lesson is to verify the action, even when the sender or branding feels familiar.

A known account can be compromised.
Familiarity is not proofLook at what you are being asked to do.
Sign in, pay, disclose or approveVerify through an established route.
Not the contact supplied by the requesterPractical checkpoints, not a guarantee of security or compliance.
What to check
Protect payment changes
Treat a new bank account as a separate verification task.
What to check
Use a known contact number and normal approval process. Do not let urgency replace the check.
Question unexpected sign-ins
A real login page can still be part of an unwanted authentication flow.
What to check
Do not enter a device code or approve setup at an unsolicited caller’s direction. Ask IT through the established route.
Report without blame
Tell staff how to report uncertainty and mistakes.
What to check
Preserve the message and time. IT can investigate account activity and take appropriate containment steps.
Sources & further reading
Make the next step practical
Talk to ITFR about your business, priorities and the controls that fit.









