The Oldest Trick in the Book Just Got a New Number
According to a report covered by TechCrunch, Google’s security team has identified hackers who are using phone calls — not fancy malware — to break into large financial and investment firms. These attackers call employees on their personal mobiles, pretend to be a coworker or IT support, and trick them into handing over login details and multi-factor codes.
This matters because it shows that even in 2025, the simplest social engineering still works against well-resourced companies. If global private equity giants can be fooled by a phone call, every Australian business needs to pay attention.
Why Your Multi-Factor Authentication Isn’t a Silver Bullet
Most small and mid-sized businesses have been told to enable multi-factor authentication (MFA) as a top security step. That’s still good advice. But the TechCrunch report highlights a dangerous blind spot: MFA can be bypassed if the user voluntarily gives away the code over the phone.
These attackers don’t need to hack servers. They need to hack trust. They research employees online, find their personal phone numbers, and call them with a convincing story. Once the victim enters their credentials and the one-time code on a fake website, the attacker is inside. This technique, often called “vishing” (voice phishing), relies on human error, not software flaws.
For Australian SMBs, the lesson is clear. Technology alone won’t protect you if your team can be talked into handing over the keys. Digital transformation projects often focus on tools and platforms, but the human layer remains the weakest link.
What This Means for Australian SMBs
Australian small and mid-sized businesses might think they are too small to be targeted. That is a risky assumption. The hacking groups described by Google have previously gone after manufacturing, healthcare, and real estate companies — the same mix of industries you find in any Australian suburb. These attackers follow the money, not the brand name.
If a $10 million extortion demand makes sense for a private equity firm, a $50,000 demand could be devastating for a local accounting practice or logistics company. The same phone call technique works at any scale. Australian businesses must treat every unsolicited call asking for login details as a potential attack, no matter how friendly the caller sounds.
What You Can Do Now
- Train every employee to never share a password or multi-factor code over the phone, even if the caller claims to be from IT or a known colleague.
- Create a clear process for verifying identity: if someone calls asking for access, hang up and call them back on an official company number you already have saved.
- Use hardware security keys (like YubiKeys) instead of SMS or app-based MFA for any system that holds sensitive data — these cannot be tricked out over a phone call.
- Run regular, simple phishing simulations that include phone-based scenarios, not just emails, to help your team spot the red flags.
- Limit what personal employee information is publicly available online, especially on social media profiles and company websites, so attackers have less to work with.
At MS&VG, we help Australian SMBs build practical security habits that match the real threats they face — including the ones that start with a simple ring on a mobile phone. Our digital transformation services always put people first, because technology only works when your team knows how to use it safely.