It’s Not Just Email Anymore: How Voice and Text Scams Are Fooling Small Businesses

For years, most cybersecurity advice about scams has focused on email. Don’t click suspicious links. Check the sender’s address. Look for unusual wording or typos.

Those precautions still matter. But email isn’t the only place scammers are targeting employees anymore.

Text messages and phone calls are becoming increasingly useful to criminals, particularly because people tend to treat those channels as more personal and trustworthy. And with voice-cloning technology becoming easier to access, even hearing a familiar voice isn’t necessarily proof that you’re talking to the person you think you are.

Smishing: Phishing by Text

Think about the kinds of texts people receive every day:

A message from a bank about a suspicious transaction. A delivery notification with a tracking link. A message that appears to come from an IT provider asking an employee to verify an account.

These scams can be effective because people often respond to texts differently than they respond to email. A suspicious email may immediately raise questions. A text message can feel like a quick request that needs an equally quick response.

For businesses, one particularly concerning version involves impersonating company leadership.

An employee might receive a text that appears to come from the CEO or another manager asking for a wire transfer, gift cards, or sensitive information. The basic scam isn’t new. What’s different is the communication channel.

Vishing: When a Phone Call Sounds Legitimate

Voice phishing, or vishing, has been around for years. Many people are familiar with fake tech-support calls or callers pretending to be representatives from banks and other businesses.

The problem is that these calls can be much more convincing when the attacker has done some homework first.

Information from a company website, LinkedIn, social media, or other public sources can provide plenty of details about an organization. A scammer may know an employee’s job title, who they report to, which vendors the company uses, or what kind of work they handle.

That information can make a fraudulent call sound legitimate.

An employee might receive a call from someone claiming to be a vendor who needs to confirm payment information. Another caller might pose as an IT technician and ask the employee to install remote-access software to resolve an urgent problem.

The details make the difference.

Now There’s Another Problem: Voice Cloning

Voice-cloning technology adds another layer to these scams.

A scammer may be able to create a convincing imitation of someone’s voice using publicly available audio. A voicemail greeting, recorded presentation, podcast, or video can potentially provide enough material to make an impersonation sound believable.

That creates an obvious problem for businesses.

An employee could receive a call that sounds like the CEO or another executive and be told to transfer money, change payment information, or provide account credentials.

Hearing a familiar voice is no longer enough to establish someone’s identity.

Five Ways to Protect Your Business

You don’t need a complicated security system to make these scams harder to pull off. Start by making sure employees know what to do when a request involves money, credentials, or sensitive information.

  1. Verify financial requests through another channel.
    Any request to transfer money, change banking information, purchase gift cards, or provide sensitive information should be independently verified. If someone claiming to be the CEO calls with an urgent request, call the CEO back using a phone number you already have on file. Don’t use a number provided during the suspicious call or text.
  2. Consider using a verification phrase.
    Some businesses establish a simple code word or phrase for particularly sensitive requests. It’s an old-fashioned approach, but it can provide another way to confirm someone’s identity when a voice alone isn’t enough.
  3. Train employees on phone and text scams.
    Security awareness training shouldn’t stop at email. Employees need to recognize suspicious texts, unexpected phone calls, requests for remote access, and attempts to impersonate company leadership or vendors.
  4. Think about what’s publicly available.
    Businesses can’t realistically remove every photo, video, presentation, or recording of their leadership from the internet. But it’s worth being aware that publicly available information can be used by scammers to make an impersonation more convincing.
  5. Take away the pressure to act immediately.
    Urgency is one of the most effective tools scammers have. Establish a policy that employees can pause and verify an unusual request without worrying about upsetting a manager or missing a deadline. For financial transactions, requiring a second person’s approval can stop a scam before money leaves the business.

Don’t Let the Phone Become the Weak Spot

Scammers tend to focus on whatever gives them the best chance of getting someone to act.

As businesses get better at identifying suspicious email, criminals have more reason to look at text messages and phone calls. The technology available to them is changing, too.

The answer isn’t to distrust every phone call or text message. It’s to give employees a clear process for handling requests that involve money, passwords, account access, or sensitive information.

If a request is unexpected and urgent, stop. Verify it through a different channel. Then decide how to proceed.

If your team hasn’t discussed what smishing, vishing, and voice-cloning scams can look like, now is a good time to start that conversation.

CMIT Solutions Dayton South can help your business build practical security awareness training that covers the threats employees are actually encountering.

Get in touch to learn more.

Back to Blog

Share:

Related Posts

When One Tech Isn’t Enough: The Case for Managed IT Services

Over the course of my three-decade career I’ve worked in a wide…

Read More

Securing Trust

I was walking through the Dayton Home and Garden Show when I…

Read More

Is Your Business Prepared for Today’s Cybersecurity Expectations?

For many small and mid-sized businesses in **Dayton and Southwest Ohio**, cybersecurity…

Read More