Ramon got a call on a Tuesday afternoon. The caller ID showed an internal number. The voice was calm and professional. "Hi Ramon, this is Kevin from the IT help desk. We're seeing some unusual activity on your account and need to verify your identity before it gets locked out."
The caller knew his full name, his department, and even mentioned his manager's name. It felt official. It felt urgent. Ramon didn't want his account locked, so he confirmed his username and read back the six-digit code that just appeared on his phone.
The call ended. Two minutes later, his email account was compromised.
What Happened
The caller was not IT. He was a scammer using a technique called vishing, short for voice phishing. He had gathered basic information about Ramon from LinkedIn and the company website. The six-digit code Ramon read out loud was an MFA code. Giving it away handed the attacker full access to his account.
AI tools can now clone voices and mimic speech patterns convincingly. Scammers use them to sound like colleagues, managers, or IT staff. A caller knowing your name, your department or your manager is not proof they are who they claim to be. One phone call can hand over account access, personal data or company information. The damage happens before you realize something is wrong.
Remember the Framework

Simple Steps to Protect Yourself
-
Never read an MFA code aloud to anyone. IT will never ask for it by phone.
-
If a caller claims to be from IT, hang up and call the help desk directly using the number you already know.
-
Do not trust caller ID. It can be faked. A familiar number does not mean a trusted caller.
-
Be cautious if a caller creates urgency. "Your account will be locked" is a common pressure tactic.
-
Apply the same habit at home. Banks, delivery companies and government agencies will not call and ask for a code or password.
Do This Today
✔ Find your IT help desk number and save it in your phone contacts right now.
✔ Share one sentence with a coworker: "IT will never call and ask for your MFA code."
✔ If you received a suspicious call recently, report it to IT today, even if you did not share anything.
Quick Checklist
-
I know my IT help desk phone number.
-
I will never read an MFA code to a caller.
-
I hang up and call back on a trusted number if something feels off.
-
I do not trust a caller just because they know my name or department.
-
I report suspicious calls to IT even if I did not fall for them.
Zero Trust Human Habit of the Week
Hang up first. Call back on a number you already know. A real IT team will not mind.