Three A4 pages to take to the people who own a payment, supplier-change or account-recovery process:
We send you nothing else unless you tick the box asking us to.
In January 2024 a finance employee in Arup’s Hong Kong office joined a video meeting with the UK chief financial officer and several colleagues, then made 15 payments, about £20m. Every other face in the meeting was a deepfake. The employee had even suspected phishing, and the meeting was what settled the doubt.
When a colleague asks you to pay something, you check several things at once without noticing. Each one used to be hard to fake. One attacker can now supply most of them in a single conversation, from public videos, a minute of recorded speech and a new phone number.
Who chose the route: you, or the person asking?
Ferrari showed the check working in July 2024. An executive got WhatsApp messages and then a call in CEO Benedetto Vigna’s voice about a confidential deal. The executive asked which book Vigna had recommended a few days earlier, and the caller hung up. The planned version of that check is a code word you agree in person and never send in a message.
The further someone is from your organisation, the fewer records you have to check them against.
Work accounts, the company phonebook, your bank’s approval settings
Ring back on the phonebook number. A second person approves in the bank portal with their own login.
The contacts and bank details you recorded when you started working together
Ring the onboarding contact on the number you recorded then. Confirmation of Payee, and a colleague approves the new payee.
Only what you built yourself: sign-up, login and account recovery
A passkey or saved recovery code. Reset links go only to the email or phone already on the account.
Meta’s 2026 incident shows what happens without that check. Attackers asked Instagram’s AI-assisted support tool to send a reset link to a new email address, and it never checked that the address belonged to the account. Meta notified 20,225 Instagram users. Accounts with two-factor authentication stayed safe.
Run it unannounced, the way you already run phishing simulations:
Pressure to skip the check is itself a reason to escalate, however familiar the voice.
Sources: Arup, Hong Kong Government and Hong Kong Free Press · Ferrari, Bloomberg · Meta, BleepingComputer and Krebs on Security · Code words, FBI, December 2024
Cyber Security Technician, Level 3, co-created with NordVPN, and Applied AI & Automation, Level 4. Both are apprenticeships for people already in the job, funded through the Growth and Skills Levy. To talk it through, find Ben after the talk or contact us.