How to use this page. These five scenarios are illustrative composites reflecting tactics widely reported by the FBI and industry researchers, not transcripts of one real call, business, or person. Read two or three aloud at your next team meeting, pause after the caller's lines and ask “what would you do here?”, then reveal the red flags below each one. It takes about fifteen minutes and works better as a quarterly refresher than a once-a-year slideshow.

Published · HI Tech Hui · ~7 min read

Why phone scams are working better than ever

Voice-based social engineering has become one of the most common ways attackers get an initial foothold. In its M-Trends 2026 report, Mandiant ranked vishing the second most common initial infection vector observed across investigations in 2025 — and the leading vector into cloud environments specifically (Voxbooster, citing Mandiant M-Trends 2026). On the loss side, the FBI's 2025 Internet Crime Report recorded $2.13 billion in tech-support-scam losses (up 46% year over year) and $798 million in government-impersonation losses (up 97%) — both categories that typically begin with a phone call.

The reason phone scams work isn't clever technology. It's pressure. Every scenario below uses the same core move: create urgency, then ask the target to skip a verification step they'd normally take.

Five scenarios to read aloud

1. The fake IT help desk

Setup: Caller ID shows an internal-looking extension or a name close to your actual IT provider. Target: any employee.

Caller: “Hi, this is Dave from IT support — we're seeing some unusual login activity on your account this morning and need to lock it down before it gets worse. Can you confirm the code that just texted to your phone so I can verify it's really you?”

Employee (scripted response to model): “I can't share a code over the phone. What's your name and extension? I'll call our IT provider back on the number we already have on file.”

Red flags: A real IT provider will never ask you to read back a one-time code or password — that code exists specifically to stop someone other than you from logging in. Urgency (“before it gets worse”) is doing the persuading, not the caller's credentials.

2. The fake executive requesting an urgent transfer

Setup: Caller ID is spoofed to resemble an owner or executive's number, or an AI-generated voice clone is used. Target: accounting or accounts payable staff.

Caller: “Hey, it's [Owner's name] — I'm in a meeting and can't talk long. I need you to process a payment to a new vendor today, before end of day. I'll send the account details by text right after this call. Don't loop anyone else in yet, I want to handle the announcement myself.”

Employee (scripted response to model): “I'll get that ready as soon as I confirm with you directly — I'm going to call you back on your usual cell number.”

Red flags: Urgency plus secrecy plus a new payment destination is the classic combination. A request to keep a financial decision away from the normal approval chain is reason enough to pause, no matter who appears to be asking.

3. The fake bank fraud department

Setup: Caller claims to be from your bank's fraud department, often after a real or fabricated "suspicious charge" text. Target: an owner, bookkeeper, or anyone with account access.

Caller: “We flagged a $4,200 charge on your business card this morning that looks fraudulent. To reverse it and freeze the card, I just need to verify your online banking PIN and the last four of your routing number.”

Employee (scripted response to model): “I'm going to hang up and call the number on the back of our card directly.”

Red flags: A real bank never needs your PIN or full account credentials to "reverse a charge" or "freeze a card" — they already have your account information. Any request for a PIN, password, or one-time code over an inbound call is disqualifying on its own.

4. The fake vendor changing payment details

Setup: Caller claims to be from a vendor you actually work with, often after researching your public vendor relationships. Target: accounts payable.

Caller: “This is Lisa from [real vendor name] billing — we switched banks recently and wanted to give you our updated account and routing number before your next payment goes out, so it doesn't bounce.”

Employee (scripted response to model): “I appreciate the heads up — I'll confirm this by calling our regular contact at [vendor] on the number in our files before we update anything.”

Red flags: Any request to change where money goes should always be verified through an independent channel — a phone number you already had, not one provided in the call or a follow-up email. This is the single most common way real businesses lose money to phone-based fraud.

5. The fake tech support cold call

Setup: Unsolicited call, sometimes preceded by a pop-up or alarming email about a "virus" or "license expiring." Target: any employee, especially at a small front desk or retail location.

Caller: “We're calling because our monitoring flagged a virus on one of your computers. If you can just open your browser and go to this address, I'll walk you through removing it before it spreads to your other systems.”

Employee (scripted response to model): “We don't take unsolicited tech support calls. I'll check with our actual IT provider directly.”

Red flags: Legitimate IT providers and software companies don't cold-call about a virus they "detected" on your machine, and they never ask you to install remote-access software from an unsolicited call. This is one of the oldest scams in the book precisely because it still works (FBI tech support scam guidance).


The one rule that covers all five

Hang up. Call back on a number you already have on file — never one the caller gives you. Do this before resetting a password, sharing a code, changing payment or banking details, or providing any account information, no matter how urgent or convincing the caller sounds. This single habit defeats nearly every scenario above.

Other red flags worth training on

  • Pressure to act “right now” or “before end of day,” especially paired with a reason you can't easily verify (a meeting, travel, a system outage)
  • A request to keep the conversation or transaction private from a manager or coworker
  • Any request for a one-time passcode, PIN, or password to be read aloud or texted back
  • A sudden change to payment, banking, or account details delivered only by phone or a single email
  • Caller ID that looks right but the request feels slightly off — caller ID can be spoofed and, increasingly, voices can be cloned
  • A caller who gets impatient or pushes back hard when you say you need to verify independently

Running this as a 15-minute team session

  1. Pick two or three scenarios above — rotate through all five over a few sessions rather than covering all at once.
  2. Read the caller's lines aloud (a manager or a volunteer works well) and pause before revealing the “employee” response.
  3. Ask the team: “What would you actually do if this call came in right now?”
  4. Reveal the red flags and the verification rule, and connect it to your team's actual known contact numbers — bank, IT provider, key vendors.
  5. Repeat quarterly with a fresh pair of scenarios so the pattern-recognition stays current, not just memorized once and forgotten.

Related reading


Want help building a full security awareness program around scenarios like these — phishing simulations, vishing drills, and real reporting on who's clicking or falling for what? HI Tech Hui runs ongoing security awareness training for Hawaii businesses. Call (808) 206-8549, email info@hitechhui.com, or schedule a discovery call. We are at 401 Kamakee St Suite 206, Honolulu, HI 96814.

Scenarios on this page are illustrative composites for training purposes and are not transcripts of any actual call, business, or individual. Statistics cited reflect the sources linked above at time of publication.

Ready when you are

Let’s scope your IT & security plan.

Talk with a Honolulu-based engineer about managed IT, cybersecurity, or a 24/7 SOC handoff. We’ll review your current environment, identify the highest-impact gaps, and outline a clear next step — with no obligation.

HI Tech Hui team