Identity Theft Prevention
The caller was real. The call was not.
What Is Identity Theft Prevention?
Payroll and HR hold personal data, and a paycheck problem makes people move fast. This exercise uses that lever. A voicemail reports a direct deposit issue and names a real HR employee who checks out in the company directory. You call back, land on a verification portal carrying the company logo, and enter your banking details. The doubt arrives later, and so does the bank notification. You then file the incident report and read how the attacker built the pretext.
What You'll Learn in Identity Theft Prevention
- Recognize that a real employee's name and a correct directory entry are not evidence that a call is genuine
- Refuse to provide banking or personal data on a number or portal supplied by an inbound caller, and verify through a channel you already trust
- Identify the red flags in a payroll pretext, including personal-phone contact, manufactured deadline pressure, and a portal reached only through the caller
- Report the theft of your own personal data promptly, capturing the callback number and the fake portal so the attack can be traced
- Understand why freezing an account after disclosure limits but does not eliminate the damage already in motion
Identity Theft Prevention — Training Steps
-
A Routine Wednesday
It's Wednesday afternoon and you've just finished a productive client call. As you update your notes, your phone buzzes with a voicemail notification.
-
A Moment of Panic
Alice's stomach drops. A delayed paycheck would be a serious problem - rent is due next week, and she has client dinner expenses pending on her personal card. The urgency in Jennifer's voice sounded genuine. She grabs her phone to call the number from the voicemail: 1-888-927-3847 .
-
The Verification Portal
'Jennifer' sounds professional and helpful. She explains that Alice needs to verify her banking information through their secure HR portal to prevent payment delays.
-
Providing Banking Details
The portal looks professional - it has the Horizon Financial Services logo and mentions the quarterly payroll audit. Jennifer guides Alice through the form, asking her to enter her routing number and account number.
-
All Taken Care Of
Jennifer thanks Alice for her cooperation and confirms the information will be processed within 24 to 48 hours.
-
Reflection
Alice hangs up feeling relieved. But before we move on, consider what just happened.
-
A Creeping Doubt
As the afternoon wears on, Alice can't shake a nagging feeling. Why did HR call her personal phone instead of sending an email? Why was the callback number different from the company directory? And when has HR ever asked employees to verify banking details through a website during a phone call? A cold feeling settles in. Alice decides to call the real HR department to check whether Jennifer Walsh actually left that voicemail.
-
The Fallout
Marcus confirmed Alice's worst fear: Jennifer Walsh is a real HR employee, but she never left that voicemail. Someone impersonated her. The company never requests banking information through phone calls or external portals. Alice's banking details are now in the hands of an attacker. Marcus sends an email with immediate next steps and a link to the Security Portal for filing an incident report.
-
Accessing the Security Portal
Alice clicks the link to access the Security Portal and file her incident report.
-
Filing the Incident Report
Alice documents every detail of the attack - the voicemail, the callback number, the fake portal, and the information she provided. The more detail in the report, the better the security team can respond.
Security Framework Coverage
MITRE ATT&CK
- T1566.004 Phishing: Spearphishing Voice
- T1656 Impersonation
CIS Controls
- CIS 14.2 Train Workforce Members to Recognize Social Engineering Attacks
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind