Imagine one of your staff members gets a phone call on their personal mobile. The caller sounds professional, says they’re from “IT” or “head office support,” and explains there’s an urgent security migration happening that needs their login details or a quick code from their phone to complete. It sounds plausible. It sounds urgent. And it’s almost certainly a scam. This exact technique, known as vishing (voice phishing), has recently been used by a cybercrime group to break into cloud business systems at financial services and professional firms – and there’s no reason to think small regional businesses are off the radar.
Vishing is simply phishing over the phone instead of email. Attackers ring an employee, pretend to be IT support, a supplier, or even a manager, and talk them into handing over a password, approving a login prompt, or installing “remote support” software. Unlike an email, a phone call feels personal and immediate – there’s a real voice, sometimes with background office noise or a fake caller ID, and the pressure to help “IT” fix an urgent problem overrides normal caution.
What makes the recent wave of attacks particularly clever is that the scammers are calling personal mobile numbers rather than work phones or email. That sidesteps a lot of the spam filters, email security tools, and staff training that businesses have built up around phishing emails. It also catches people off guard – most of us don’t expect a work-related scam call to land on our personal phone during dinner or on a day off.
According to the security researchers who uncovered this campaign, attackers pose as help desk staff and tell the employee that a “mandatory security migration” needs to happen right away. They then talk the person through steps that actually hand over access – for example, approving a multi-factor authentication (MFA) prompt, reading out a one-time code, or installing a remote access tool. Once inside, the attackers go after data stored in cloud business systems such as Microsoft 365, Google Workspace, or other software-as-a-service (SaaS) platforms your business relies on every day.
The end goal is usually data theft for extortion – stealing sensitive files, client records, or financial information and then threatening to leak it unless a ransom is paid. Even if your business isn’t a big enterprise, the same cloud tools you use for email, invoicing, HR records, and client management are exactly what these attackers are after.
It’s tempting to think this kind of attack only targets big corporates with deep pockets. But attackers don’t necessarily know – or care – how big your business is before they call. Small and medium businesses are often easier targets because:
Training your team to recognise the red flags of a vishing call is one of the most cost-effective defences available. Some signs to watch for include:
You don’t need an enterprise security budget to significantly reduce your risk. A handful of practical habits go a long way.
If a staff member has already engaged with a suspicious caller – shared a code, approved a login, or installed something – treat it as a live incident, not a “wait and see” situation. Change the affected passwords immediately, revoke active sessions on the account, check recent login activity for anything unusual, and contact your IT support provider straight away so they can investigate further and lock down any other exposure.
This type of attack, detailed as reported by The Hacker News, is a timely reminder that cybersecurity isn’t just about firewalls and antivirus software anymore – it’s about training people to pause, question, and verify before acting on urgent requests, whether they arrive by email or by phone. For regional businesses juggling a hundred other priorities, a few simple habits and a clear plan for “what if this happens to us” can make all the difference between a near miss and a costly breach.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804