
Monday 28 September 2026 · 4-minute read
Hello Champions! This week's stories all circle one big idea. Scammers are getting very good at pretending to be someone official: the police, your boss's voice, even your payroll company. The good news is that one simple habit beats nearly all of it. If a call or message pressures you, end the conversation and get back in touch through a number or website you already know is real. Hang up, call back. And with Cybersecurity Awareness Month starting Thursday, this is the perfect week to spread it.
The FBI, America's national police agency, has warned about scammers who phone people pretending to be police or government agents. Victims have lost more than 1.6 billion dollars this way in the last year and a half. The script is always fear: you have missed jury duty, there is a warrant, pay now or be arrested. And the scammers do two telling things. They insist on speaking only to you, keeping you on the line so you cannot think, and they tell you to keep it all secret. That secrecy demand is the giveaway. Real police never mind you hanging up and calling the station back on its published number. Scammers mind very much, because the spell breaks the moment you talk to someone else.
Talking point: share this line over coffee or in your team chat: "Anyone who says don't tell anyone about this call has just told you everything you need to know." Then ask people who they would sanity-check a scary call with. Naming a person makes it happen.
Learn more: Help Net Security
Gartner, a large research firm that advises companies, asked nearly 300 senior security leaders about the past year. About 4 in 10 said someone had used a computer-faked voice (a convincing imitation of a real person, often called a deepfake) on a phone call to try to trick their staff. For video calls it was just over a third. The advice is refreshingly simple: do not try to out-listen the computer. However real the voice sounds, any request involving money, passwords, or urgency should be checked through a route you already trust, like calling the person back on their usual number.
Evidence you can use: when someone says "surely no one would fall for a fake voice here", you can reply that about 4 in 10 big-company security bosses saw exactly that happen last year. A useful number for nudging your team, or your programme lead's budget conversation.
Learn more: Help Net Security
Some cheering news. Apple's new iPhone software (iOS 27) includes a feature called Impersonation Risk Detection. When it's on, your phone quietly watches for telltale signs of an active scam, such as odd calls and unusual account activity, and if you then try to do something sensitive like send money, apps can slow things down with an extra check or a warning. It all happens privately on your own phone. One lovely detail from Apple: if anyone tells you to switch this feature off, that is itself a sign you are being scammed.
Try this activity: if you have an iPhone, update it and look under Settings, then Privacy & Security, for Impersonation Risk Detection. Then send this story to a parent or grandparent and offer to help them set it up. Champions ripple beyond the office too.
Learn more: Apple's guide
Researchers from universities in Switzerland and Cameroon interviewed people in both countries about how they handle security at work. A neat finding: Swiss employees tend to openly question security rules they find odd, while in workplaces with more deference to hierarchy, people follow rules quietly, or quietly work around them without telling anyone. In more community-minded cultures, security know-how spreads through friends and colleagues rather than official training. Which is exactly what Champions are for. A small study, but a thought-provoking one.
Talking point: ask your team: "If a security rule got in your way, would you say so? And to whom?" If the answer is silence, that is worth passing gently to your programme lead. People asking questions is a sign of health, not trouble.
Learn more: The study (free to read)
Security researchers found fake websites offering desktop computer programs claiming to be from well-known payroll companies. The trick: those companies do not make desktop programs at all. Anyone who installed one actually got software that lets criminals control their computer from afar, aimed squarely at the people who run company payroll. The lesson is wonderfully simple. If a download isn't offered on the maker's official website, it is not an upgrade; it is the trap.
Try this activity: encourage your team to download work software only from the maker's own site, never from ads or search results. And if you know the people who handle payroll or HR systems, forward them this story; it was made for them.
Learn more: Help Net Security
One habit, five stories: hang up, call back. Teach it to one colleague and one relative this week, and you have done more than most posters manage in a month. Drop by drop, the pond fills.
Subscribe and choose Ripples to receive each edition the morning it publishes.