top of page

Prove the Sender: Phishing and Vishing Awareness

11 minutes ago
2 min read

Week one asked you to prove things in general. This week gets specific: prove the sender. Whether it arrives as an email or a phone call, the identity attached to a message is the easiest part of it to fake, and the part most of us trust without checking. This is why phishing and vishing awareness is so important.


On email, the display name is decoration. Anyone can type anything there; the real address underneath is what matters, and it's the part almost everyone skips, especially on a phone screen where it may not even be visible. On the phone, a familiar-sounding caller proves even less: around a third of people internationally have now had a scam call using a cloned voice, and the social engineering of IT help desks and account-recovery processes is the standout access technique behind the UK's most costly recent breaches, including the attack on Jaguar Land Rover. NCSC and CISA have both urged organisations to review how their help desks verify a caller.


The guidance is the same for both channels: don't verify a sender using anything the sender gave you. Expand the email address before acting on anything financial or unusual, don't reply to check, since a reply goes wherever the attacker set it to go. On a call, say you'll call back, then use a number you already had, not one just given to you. If a caller pushes back on that, you have your answer. It applies at home too, an unexpected call about your bank account should always end with you ringing the number on your card.



Talk to us: if your service desk has never had its caller-verification process reviewed, that's exactly the gap NCSC and CISA are pointing at. Our Culture360° service includes phishing and vishing simulation built around this.


Get the guide: the full CAM26 “Prove It” pack is free to download. Get the CAM26 guide.


Dark purple promo banner for ICA Consultancy, featuring Cyber Awareness Month 2026 guide text and a Download the guide button.

 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page