How to recognise and avoid vishing (voice phishing) phone call scams targeting Australian businesses
Summary
This guide helps you troubleshoot and resolve: How to recognise and avoid vishing (voice phishing) phone call scams targeting Australian businesses. Follow the steps below to fix the issue.
Common Causes
Vishing, or voice phishing, is a type of scam where criminals ring your business pretending to be from a trusted organisation such as your bank, the ATO, NBN Co, Microsoft, or even your own IT provider. Their goal is to pressure you or a staff member into revealing login credentials, transferring funds, or granting remote access to a computer. These calls can sound highly professional and may even display a legitimate-looking number on your phone (a technique called caller ID spoofing). Recognising the warning signs and knowing how to respond is essential for protecting your business, staff, and data.
Common Vishing Tactics to Watch For
Scammers constantly refine their approach, but most vishing calls share a few recognisable patterns. Being familiar with these tactics is the first step in defending your team.
Impersonation of Trusted Brands
- Caller claims to be from Microsoft, Telstra, the ATO, your bank, NBN Co, or even your own IT provider.
- They may reference real account details harvested from previous data breaches to sound credible.
- They often use official-sounding titles such as "Senior Technical Officer" or "Compliance Manager".
Urgency and Fear
- Statements like "your account has been compromised" or "legal action will be taken within 24 hours".
- Threats that your internet will be disconnected, your tax file number suspended, or your business fined.
- Pressure to act immediately, before you have time to think or verify.
Requests for Sensitive Information
- Asking for usernames, passwords, MFA codes, or credit card details.
- Requesting remote access to your computer via tools such as AnyDesk, TeamViewer, or Quick Assist.
- Asking you to install software, visit a website, or read out a code from your screen.
Unusual Payment Methods
- Demands for payment via gift cards, cryptocurrency, or wire transfer.
- Instructions to move money into a "safe account" to protect it from fraud.
What to Do If You Receive a Suspicious Call
- Stay calm and do not share any information. Politely tell the caller you cannot discuss account details and that you will call them back through the organisation's official number.
- Hang up. Do not press any keys or follow any prompts, even if the caller asks you to.
- Verify the call independently. Look up the organisation's contact details from their official website (do not use any number the caller provides). Ring them to confirm whether the call was genuine.
- Check your systems. If you or a staff member did share information or grant remote access, treat the device as compromised. Move to the steps below immediately.
- Report the call. Notify your team and report the scam to Scamwatch. If you believe your business has been targeted, contact your IT provider or open a support ticket so they can assist with securing your environment.
If You Have Already Shared Information or Granted Access
Acting quickly can limit the damage. Work through these steps in order.
- Disconnect the affected device from the network. Unplug the Ethernet cable or turn off Wi-Fi to stop any active remote session.
- Do not shut the computer down. Leaving it running helps technicians investigate. If you must shut it down, do not turn it back on until it has been reviewed.
- Change passwords from a different, trusted device. Update the password for any account that may have been exposed, starting with email, banking, and any portals you use. Use a unique, strong password for each.
- Enable or rotate multi-factor authentication (MFA). If MFA was active, remove and re-add the authenticator method. If it was not enabled, turn it on for all critical accounts.
- Contact your bank. If financial details were shared, ring your bank straight away to monitor or freeze affected accounts.
- Notify key contacts. Inform your leadership team and any staff who may also be targeted. Scammers often reuse details across an organisation.
- Open a support ticket. Submit a ticket through your IT provider's support portal with as much detail as possible: the caller's claimed name, the number they rang from, what was discussed, and any actions taken.
How to Protect Your Business Going Forward
Build Awareness Across Your Team
- Hold a short briefing with staff about vishing and share this article internally.
- Make it normal to question unexpected calls, even from familiar brands.
- Encourage a "verify before you trust" culture: no one should feel pressured to act on the spot.
Strengthen Your Technical Defences
- Enforce MFA on every account that supports it, especially email, banking, and remote access tools.
- Use a reputable password manager so staff are not tempted to share credentials over the phone.
- Restrict who can install remote access software such as AnyDesk, TeamViewer, or Quick Assist. Apply this through Group Policy on Windows or configuration profiles on macOS.
- Keep operating systems, browsers, and security software up to date so any unauthorised remote session is harder to maintain.
Document a Clear Response Process
- Create a one-page "Suspicious Call" runbook for your team, including who to contact internally and how to report the call to Scamwatch.
- Define a single escalation path so staff know exactly who to notify if something feels off.
- Review and rehearse the process every six months.
Still Having Issues?
💻 Open a Ticket