Home › Knowledgebase › KB-269

How to recognise and avoid vishing (voice phishing) phone call scams targeting Australian businesses

Summary

This guide helps you troubleshoot and resolve: How to recognise and avoid vishing (voice phishing) phone call scams targeting Australian businesses. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Vishing, or voice phishing, is a type of scam where criminals ring your business pretending to be from a trusted organisation such as your bank, the ATO, NBN Co, Microsoft, or even your own IT provider. Their goal is to pressure you or a staff member into revealing login credentials, transferring funds, or granting remote access to a computer. These calls can sound highly professional and may even display a legitimate-looking number on your phone (a technique called caller ID spoofing). Recognising the warning signs and knowing how to respond is essential for protecting your business, staff, and data.

Common Vishing Tactics to Watch For

Scammers constantly refine their approach, but most vishing calls share a few recognisable patterns. Being familiar with these tactics is the first step in defending your team.

Impersonation of Trusted Brands

Urgency and Fear

Requests for Sensitive Information

Unusual Payment Methods

Remember: The ATO, your bank, NBN Co, and Microsoft will never call you unexpectedly to ask for passwords, remote access, or payment in gift cards. If in doubt, hang up and call the organisation back using a number from their official website.

What to Do If You Receive a Suspicious Call

  1. Stay calm and do not share any information. Politely tell the caller you cannot discuss account details and that you will call them back through the organisation's official number.
  2. Hang up. Do not press any keys or follow any prompts, even if the caller asks you to.
  3. Verify the call independently. Look up the organisation's contact details from their official website (do not use any number the caller provides). Ring them to confirm whether the call was genuine.
  4. Check your systems. If you or a staff member did share information or grant remote access, treat the device as compromised. Move to the steps below immediately.
  5. Report the call. Notify your team and report the scam to Scamwatch. If you believe your business has been targeted, contact your IT provider or open a support ticket so they can assist with securing your environment.

If You Have Already Shared Information or Granted Access

Acting quickly can limit the damage. Work through these steps in order.

  1. Disconnect the affected device from the network. Unplug the Ethernet cable or turn off Wi-Fi to stop any active remote session.
  2. Do not shut the computer down. Leaving it running helps technicians investigate. If you must shut it down, do not turn it back on until it has been reviewed.
  3. Change passwords from a different, trusted device. Update the password for any account that may have been exposed, starting with email, banking, and any portals you use. Use a unique, strong password for each.
  4. Enable or rotate multi-factor authentication (MFA). If MFA was active, remove and re-add the authenticator method. If it was not enabled, turn it on for all critical accounts.
  5. Contact your bank. If financial details were shared, ring your bank straight away to monitor or freeze affected accounts.
  6. Notify key contacts. Inform your leadership team and any staff who may also be targeted. Scammers often reuse details across an organisation.
  7. Open a support ticket. Submit a ticket through your IT provider's support portal with as much detail as possible: the caller's claimed name, the number they rang from, what was discussed, and any actions taken.

How to Protect Your Business Going Forward

Build Awareness Across Your Team

Strengthen Your Technical Defences

Document a Clear Response Process

Tip: If you are ever unsure whether a call claiming to be from a trusted organisation is genuine, hang up and contact them directly using details from their official website. A legitimate organisation will never be offended by a cautious caller.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket