Why would tech support call you? Don’t fall for phishing

Analysis
Aug 8, 20122 mins

Some phishing attacks have gotten sophisticated enough to call end users and pretend to be IT support, baiting them into giving up their personal information in the process. Don't fall for that.

Well, most of the time, we would not call you. But even though support teams rarely make calls to customers, there has been a rise in a social engineering attack where someone impersonating support staff calls and informs the IT department that there is a bug in such-and-such a system.

Even though customers know they don’t normally receive calls from support, they are willing to provide impersonators with valuable information such as account information, log-in credentials and more.

As someone who works in (IT) support, this can be perplexing to me, especially considering the lack of down time. You are (I am) answering calls and following up with customer and partner support tickets. When we aren’t on the phone, we are updating knowledgebase articles or even responding to questions in the user forum. We never have time to proactively call customers to help them with support issues. When there is a bug or a common issue with the software we support, we don’t generally call each customer individually to let them know.

Instead, my company, and most companies, has some sort of user forum or alert system to inform customers about known bugs and issues. We have very little time to proactively reach out to customers who aren’t yet experiencing a problem; and customers are aware of this.

My advice to customers receiving a call directly from one of their vendor’s support staffs is to do what we do when you call us; ask for authentication information. Or, better yet, tell the person on the other line you appreciate the call but you aren’t able to discuss the issue now and you will call your support contact in a few minutes.

There is a small chance you may end up giving a legitimate IT support person a hard time, but more than likely you are actually protecting yourself from a relatively clever social engineering attack. And as someone who works in a support capacity for a security company, we’ll understand if a customer is wary about giving important information out over the phone to someone offering unsolicited assistance.