About Partners Contact Client Portal
LinkedIn Twitter
Services Industries Insights & Events Careers & Culture
Insights & Events

Services

RubinBrown specializes in providing a comprehensive range of services to meet business and personal needs. Whether you require expert tax, strategic business consulting, audit services or more, RubinBrown's team of experienced professionals are here to support you.

View All Our Services
Assurance Services
Benefit Plan Audit Services Public Company Services SOC Examinations, IT Audit, & Third-Party Risk
Consulting Services
AI & Data Consulting Services Business Process Improvement Services Business Restructuring & Bankruptcy Services Cyber Security Services Independent ERP Selection Consultants Fraud & Forensics Healthcare Consulting Services SOC Examinations, IT Audit, & Third-Party Risk Information Technology Services Litigation Services Mergers & Acquisitions Services Risk & Internal Audit Services Valuation Services
Entrepreneurial Services
Outsourced Accounting & Advisory Services
Tax Services
Federal Tax Services Private Client Services Credits & Incentives Services State & Local Tax Services
Wealth Management Services by RubinBrown Advisors RubinBrown Corporate Finance

Industries

At RubinBrown, we bring experience across a range of industries. Our experience enables our professionals to offer tailored solutions catering to the intricacies of each sector. Our professionals have years of focused engagement and skills, allowing them to navigate industry-specific challenges to benefit our clients.

View All Our Industries
Colleges & Universities Construction Financial Institutions Gaming Healthcare Law Firms Life Sciences & Technology Manufacturing & Distribution Not-For-Profit Private Equity Public Sector Real Estate Transportation & Dealerships

Careers & Culture

At RubinBrown, we are inspired team members, working as one firm, living our core values, and Being Our Best for Others while delivering totally satisfied clients. We invite you to learn more about the Firm's culture, the Be Your Best for Others mentality, and explore the available opportunities at RubinBrown.

Discover Our Culture
Baker Tilly International Campus Recruiting Diversity & Inclusion Experienced Recruiting RubinBrown Charitable Foundation Join The Team
Back to Insights

Phishing Moved to Teams, Text and the Help Desk: The New Shape of Social Engineering

Contact Us

Phishing Moved to Teams, Text and the Help Desk: The New Shape of Social Engineering

Contact Us

October is Cyber Security Awareness Month. This is the first article in a series throughout October that will call attention to the importance of cyber security awareness.  

Employees have spent a decade learning to distrust suspicious email. Attackers adapted. Social engineering now increasingly arrives through phone calls, text messages, collaboration platforms and the help desk - channels that often carry more trust and fewer technical controls.

Why it matters

Social engineering is the use of deception to persuade people to disclose information, approve a transaction, reset credentials or grant access. The technique is not new. What changed is where attackers are applying it and how convincingly they can do it.

By the numbers:

  • 41% of social engineering breaches involved a vector other than email, according to the 2026 Verizon Data Breach Investigations Report.

  • The human element was present in 62% of all breaches, up from 60% the year before.

  • Voice phishing ranked as the second most common initial infection vector in 2025, at 11% of investigations where a vector could be identified, according to M-Trends 2026.

  • Verizon puts the median click rate for email phishing simulations at about 1.4%. For phone-centric methods, it is closer to 2% - roughly 40% higher.

The implication is straightforward: email defenses became harder to bypass and employees became more cautious, so attackers shifted toward channels with a better return.

Why attackers moved beyond the inbox

Corporate email has accumulated a decade of defenses: filtering, authentication standards, link rewriting, external-sender banners and attachment sandboxing. It is also the channel where employees receive the most security-awareness training. An unexpected email with a link now triggers suspicion in a way it often did not ten years ago.

That same defensive context usually does not exist elsewhere. A text message has no external-sender banner. A Microsoft Teams or Slack message arrives inside a platform employees associate with colleagues. A phone call has no filter beyond caller ID.

There is a behavioral side effect as well. By repeatedly teaching employees that email is where deception lives, organizations may have reinforced an unintended assumption that other channels are safer. Attackers are exploiting that trust gap.

Pretexting changes the problem

Verizon now tracks pretexting separately from phishing. That distinction matters because the defensive behavior is different.

A phishing email is fixed. Employees can be taught to recognize suspicious links, unusual requests or other warning signs because the message does not change. A live pretext is adaptive. A threat actor can answer objections, supply supporting detail, increase urgency when a target hesitates and back off when pressing too hard would raise suspicion.

Consider a caller to accounts payable who knows the CFO is traveling, references a transaction already in progress and names the bank the company uses. None of that necessarily requires a prior breach. Public websites, LinkedIn profiles and press releases can provide enough detail to make the story sound legitimate. The challenge is no longer simply spotting a bad message; it is validating a plausible request.

The help desk is now part of the security perimeter

Verizon documents attacks that use Microsoft Teams and Quick Assist to manufacture an IT emergency and persuade an employee to open a remote support session with legitimate tools already built into the operating system. There may be no malware for security software to detect because no malware was required.

The same technique works in reverse. An attacker can call the help desk, impersonate a legitimate employee and request a password reset or MFA re-enrollment. Help desks are designed to solve problems quickly for people who sound stressed or blocked. That service orientation is exactly what the attacker is trying to exploit.

For leadership, the practical conclusion is simple: help desk identity verification is now a security control, not merely a customer-service step. The process must be written down, consistently applied and able to withstand a caller who claims an urgent meeting or business deadline.

AI changes the economics, not the attack

AI did not invent social engineering. It lowered the cost of executing it well.

Voice cloning can use public audio from earnings calls, conference panels, podcasts or voicemail greetings. Generative tools can produce fluent, context-specific pretexts in multiple languages. That makes old awareness advice - such as relying on poor grammar as a warning sign - less dependable.

Verizon data indicates 44% of AI-assisted initial access activity falls into the phishing category. More important for business leaders, research and personalization that once required significant operator time can now be produced much faster.

That change matters for mid-sized organizations. Highly tailored attacks were once concentrated on larger targets because tailoring was expensive. Lowering the cost makes more convincing pretexts economical against organizations that may not have built controls for that level of attention.

What organizations should do now

  • Make out-of-band verification a rule, not a judgment call. Requests to move money, change banking details, reset credentials or grant remote access should be verified through a channel the requester did not choose, using contact information the organization already holds. Apply the rule even when the request sounds legitimate; that is precisely when a good pretext is most effective.
  • Write down help desk identity-proofing requirements. Define what proof is required before a password or MFA reset, who can approve an exception and whether urgency can ever override the process.
  • Use phishing-resistant MFA where compromise would have the greatest impact. Prioritize administrative accounts, remote access and email, where a stolen or socially approved code can create significant downstream exposure.
  • Make reporting easy and non-punitive. An employee who realizes twenty minutes later that something felt wrong may be the best available detection signal. If reporting feels like admitting failure, that signal arrives late or not at all.
  • Simulate more than email. Verizon found large organizations facing a median of 48 SMS-based phishing campaigns a year. A testing program focused only on email does not prepare employees for unsolicited texts, collaboration-platform messages or voice calls.

Four questions for your leadership team

  1. Do we have a written out-of-band verification requirement for payment changes, credential resets and access requests, and does it apply regardless of who is asking or how urgent the request sounds?
  2. What does our help desk require before resetting a password or MFA enrollment, and who is permitted to waive it?
  3. Does our awareness testing include voice, text and collaboration platforms, or only email?
  4. If an employee realized an hour from now that they had been deceived, would they know who to call - and would they make the call?
The full 16-question set for all four topics in this series will be available at the end of October.

Bottom line

Email remains the largest single social engineering channel, and the defenses built around it still matter. But a comprehensive security-awareness program can no longer treat the inbox as the entire attack surface.

The more important question is whether the organization has verification controls that still work when a request sounds completely legitimate. As attackers move into trusted channels and use AI to improve the quality and scale of their pretexts, recognition alone is not enough. Verification has to carry the control.
 

Next in this series: People are one way into an organization. Unpatched technology is the other, and it recently overtook stolen credentials as the most common way in. Next: "The Shrinking Patch Window."

RubinBrown Cyber Security Services helps organizations assess social engineering exposure, test help desk and verification controls, and build awareness programs that cover the channels attackers actually use. Learn more about RubinBrown Cyber Security Services.


 

Published: 09/24/2026

Readers should not act upon information presented without individual professional consultation.

Any federal tax advice contained in this communication (including any attachments): (i) is intended for your use only; (ii) is based on the accuracy and completeness of the facts you have provided us; and (iii) may not be relied upon to avoid penalties.

 

Contact Us:

Talk to Our Experts

Audrey Katcher, CPA, CISA, CITP, CGMA Partner audrey.katcher@rubinbrown.com 314-290-3420
Robert Rudloff, CISSP, CISA, QSA, CMMC RPA Partner rob.rudloff@rubinbrown.com 303-952-1220

Be Your Best for Others at RubinBrown

At RubinBrown, our firm fosters a culture built upon five vision points, and are guided by our philosophy of Being Our Best for Others. Discover how you can be your best at RubinBrown today by visiting our Careers & Culture Overview for available opportunities and more.

Discover Our Culture

Join Our Mailing List

RubinBrown periodically sends breaking regulatory updates, technical summaries, industry-specific information and event (in-person and virtual) invitations through electronic newsletters.

Sign Up for Our Communications

Certified Public Accountants & Business Consultants

Ranked a Top 50 Accounting Firm by Inside Public Accounting

1-800-678-3134
  • Services
  • Industries
  • Insights & Events
  • Careers & Culture
  • Contact
  • RubinBrown Advisors
  • RubinBrown Corporate Finance
  • RubinBrown Executive Recruiting
  • Firm News
  • Disclaimers
  • Privacy Policy
  • Client Payment
© 2026 RubinBrown LLP