Signals Weekly Briefing

SIGNAL: Week 40 - Hang Up, Call Back

28 September 2026 · 8 min read · Andy
← All Signals briefings

Monday 28 September 2026 · 8-minute read

Last week we looked at attackers who win by being charming. This week the pendulum swings the other way. Almost everything worth reading in the past few days is about impersonation of institutions: the FBI counting the cost of fake police officers, Gartner confirming that faked voices on work calls are now routine, and criminals dressing malware up as your payroll provider. The encouraging part is that the counter-move is the same everywhere, and it is behavioural rather than technical. Stop trying to spot the fake. Break contact, and re-establish it through a channel you already trust. Hang up, call back.

Fear works as well as charm, and it costs more

The FBI's Internet Crime Complaint Center (IC3) has issued a public service announcement on scams impersonating police officers and federal agents, and the numbers deserve attention. Between January 2025 and July 2026, reported losses to law enforcement impersonation reached 1.6 billion dollars. Jury duty scams alone generated 6,833 complaints and around 36 million dollars in losses.

The behavioural detail is what makes this worth your time. These scammers do not build rapport over weeks. They manufacture a crisis in minutes: you have missed jury duty, there is a warrant, your licence is at risk. Then they do two things that should be on every red-flag list you teach. They refuse to speak to anyone but the target, keep them on the line continuously, and demand secrecy from family, colleagues, and even real authorities. Isolation is the mechanism. The targeting is calculated too, with medical professionals threatened with licence revocation and international students threatened with deportation, each group hit precisely where authority has the most leverage over them.

This is government complaint data, so it undercounts (embarrassed victims don't report), and it skews toward the US. The psychology travels, though.

What does this mean for me? Most awareness content still teaches people to spot fakes. This data suggests teaching people to recognise the feeling of being isolated and rushed, no matter who the caller claims to be. Two behaviours cover it: real authorities never mind you hanging up and calling back through a published number, and any demand for secrecy is itself the signal. If your organisation employs internationals or licensed professionals, they are being specifically targeted and deserve a specifically worded heads-up.

Source: FBI IC3 public service announcement, reported by Help Net Security (21 September 2026).

Deepfake calls are now a routine finding, says Gartner

Gartner surveyed 297 senior cybersecurity leaders between March and May 2026, and 41 per cent reported at least one social engineering incident involving a deepfake on an audio call in the past year. For video calls the figure was 36 per cent. Sit with that for a moment: in a decent-sized sample of security leaders, faked voices on work calls are closer to the norm than the exception. Phishing and business email compromise still lead the table at 79 per cent, but the gap is closing fast.

Gartner's advice is notable because it has given up on detection as the primary control. The recommendation is to make verification the default for risky requests on every channel, use phishing-resistant authentication for critical workflows, and update incident response plans for what they call multimodal impersonation. In other words, the analyst consensus has arrived where behavioural practitioners have been for a while: you cannot train ears to beat synthesis, so you train habits that make synthesis irrelevant.

The usual caveat applies to self-reported survey data, and "involving a deepfake" leaves room for interpretation. The direction is unambiguous, though, and it matches what CISOs describe informally.

What does this mean for me? If your deepfake guidance still centres on artefacts (odd blinking, robotic cadence), retire it. The durable control is a callback norm: any request involving money, credentials or urgency gets verified through a second, known channel, no matter how convincing the voice. The cultural work is making that verification feel like professionalism rather than insubordination, and that means executives visibly welcoming being checked. A leader who says "well caught" in public does more than a module ever will. This survey is also useful ammunition for the budget conversation, because 41 per cent is a hard number from a source boards respect.

Source: Gartner survey, reported by Help Net Security (22 September 2026).

Apple builds the intervention into the moment of risk

Here is the constructive counterpoint. With iOS 27 and iPadOS 27, Apple has shipped Impersonation Risk Detection, an opt-in feature that analyses device activity patterns on the phone itself and estimates whether the user is currently in the middle of a social engineering scam. When someone attempts a sensitive action, such as a payment or a password change, a participating app can request a risk level (unknown, medium or high) and respond with friction: an identity check, a waiting period, a warning. Apple never sees the underlying data, only which app asked.

Why this matters to our field: it is choice architecture applied at exactly the point where awareness training runs out of road. A scam victim mid-call is aroused, rushed and coached by the attacker; no poster reaches them there. A system that quietly notices the pattern (unusual calls, new apps, atypical account activity) and slows the transaction down intervenes at the only moment that counts. Apple has even anticipated attacker adaptation, noting that anyone who instructs you to turn the feature off is probably scamming you.

Fair caveats: it is opt-in, it depends on apps choosing to participate, and an "unknown" rating is not a clean bill of health. It is a design direction, not a solved problem.

What does this mean for me? Two things. Short term, this is worth including in personal-safety comms, especially for employees supporting older relatives, once your users are on iOS 27. Longer term, it is a model to steal. Ask where your own workflows could request friction proportional to risk: a cooling-off period on new-payee changes, a callback step on out-of-band payment requests. Timely, targeted friction beats retrospective training, and you can now cite Apple as precedent when the business objects.

Source: Apple's own documentation, About Impersonation Risk Detection, with coverage from Help Net Security (24 September 2026).

What Switzerland and Cameroon reveal about "universal" security training

A newly published Springer proceedings chapter from researchers at the University of Applied Sciences Northwestern Switzerland (FHNW) and Biaka University of Buea offers something our field rarely gets: a genuinely cross-cultural study of security behaviour, comparing Switzerland and Cameroon through interviews and focus groups with professionals, educators and students in both countries.

The findings map security behaviour onto cultural dimensions such as power distance, individualism and uncertainty avoidance. In low power-distance Switzerland, employees question security policies, which sounds like friction but actually surfaces problems. In higher power-distance settings, employees accept the same policies without resistance, which can look like compliance but may mask quiet workarounds and unreported incidents. Collectivist cultures, meanwhile, showed a real strength the field underuses: security knowledge spreads socially, through the group, rather than through formal channels.

Honesty about limitations: this is a small qualitative study (fifteen interviews and three focus groups), so treat it as hypothesis-generating rather than definitive. But it is asking a question most of our industry ignores while shipping identical training worldwide.

What does this mean for me? If you run a programme across regions, your completion dashboard may be flattering you. Uniform content lands differently in different cultural contexts, and silence is not agreement. Practically: ask your regional teams how policy pushback actually happens locally, treat questioning as a health signal rather than resistance, and in collectivist contexts invest in champions and peer networks over individual e-learning, because that is the channel knowledge already flows through. The Hofstede-style framing has its academic critics, but as a prompt for examining your own assumptions it earns its keep.

Source: Peer-reviewed conference chapter, published by Springer and available open access via FHNW.

Briefly: the payroll app your vendor never made

Allure Security found fake desktop applications impersonating three major US payroll platforms, none of which actually offers a desktop app. The lure sites were built with an AI website builder, and the installer plays a genuine Microsoft component installer as theatre while silently deploying ScreenConnect, a legitimate remote access tool, configured for unattended access to the machine of whoever handles payroll. Reach was modest (a few hundred downloads at most), and it was caught early, but only 32 of 70 antivirus engines flagged the installer, and the researcher's one-liner is the whole lesson: a download the vendor does not offer is not an upgrade; it is the attack.

What does this mean for me? A narrow, high-value nudge for finance and HR: publish the list of software your payroll and HR vendors actually ship, and make "install only from the vendor's own site" the norm for that group. Five minutes of comms, aimed at the dozen people who can divert a payroll run.

Source: Allure Security research, reported by Help Net Security (25 September 2026).

 


Signing off

Cybersecurity Awareness Month starts on Thursday, and if this week's reading suggests a single message worth amplifying through October, it is the callback habit. It is teachable in a sentence; it works against fake police, fake executives and fake payroll portals alike, and unlike deepfake-spotting, it will still work next year. See you next Monday.

 

Get Signals in your inbox

Subscribe and choose the Signals weekly briefing to receive each edition the morning it publishes.