Look beyond spelling and appearance
Social engineering means manipulating people into an action or disclosure. Phishing is one way this can happen, including through email and other messaging channels. A request may appear to come from a colleague, manager or familiar organisation and still deserve verification.
Unexpected requests for money, credentials or sensitive information are particularly worth examining. Urgency and pressure to bypass normal approvals are warning signs. Good grammar, a familiar display name or an apparently relevant conversation do not settle authenticity. A warning sign raises a question; it is not a diagnosis. Detecting socially engineered messages
Verify the instruction independently
For a sensitive request, use an established contact method and the normal approval process. If a message asks you to change payment details, a phone number included in that same message is not independent confirmation. ACSC personnel guidance addresses verification of sensitive requests as part of staff awareness. Guidelines for personnel security
A familiar voice or video appearance alone is not verification; follow the established approval and identity-check process. Guidelines for personnel security, Synthetic impersonation.
The organisation should decide what its verification process looks like before someone is facing a rushed transaction. Staff need an understandable way to handle an urgent request that might be legitimate, rather than being left to improvise.
Report what you know
A useful internal report describes when the message arrived, the channel used, what it requested and whether anyone has already acted. Follow the organisation’s approved method for supplying the message itself. Do not open an attachment or follow a link simply to gather more evidence.
Businesses should name a reporting contact and an alternative if normal communications are unavailable. These are process choices that should fit the actual tools and response arrangements, consistent with ACSC incident-planning guidance. Cyber security incident response planning: Practitioner guidance
If bank or card details are at risk, contact the financial institution promptly using a trusted route. ACSC also identifies ReportCyber as a reporting channel. Reporting does not guarantee that a transaction can be stopped or money recovered. Report and recover from business email compromise
An invented payment-request example
An accounts employee receives an email asking for a supplier’s new bank details to be used immediately. The employee pauses the change, contacts the supplier using previously established details and follows the business’s payment-approval process. They also report the unusual message internally.
If the employee had already acted, the priority would be prompt reporting of what happened. Blame or embarrassment should not be built into the reporting process.
A short personal checklist
- Pause before acting on an unexpected sensitive request.
- Use an independent, established route to verify it.
- Follow the relevant approval process.
- Report the concern and say whether you already acted.
- Leave technical investigation to authorised people.
This is a suggested everyday workflow, not a substitute for your organisation’s incident procedures.
Optional depth: make the process usable
Operations, finance and security staff should agree who handles reports, how urgent payment concerns are escalated and what staff should do if the usual contact is unavailable. Product reporting buttons vary, so instructions need to match the messaging platform. Legal or contractual notification decisions belong with the responsible specialists; an internal report does not determine those duties.
Related reading
- MFA and passkeys — Understand sign-in protection and its limits.
- Preparing a cyber incident-response plan — See how organisational response is planned.