{"id":4303,"date":"2026-07-20T15:34:35","date_gmt":"2026-07-20T15:34:35","guid":{"rendered":"https:\/\/blogs.chapman.edu\/information-systems\/?p=4303"},"modified":"2026-07-20T15:34:35","modified_gmt":"2026-07-20T15:34:35","slug":"when-the-scam-sounds-like-your-boss","status":"publish","type":"post","link":"https:\/\/blogs.chapman.edu\/information-systems\/2026\/07\/20\/when-the-scam-sounds-like-your-boss\/","title":{"rendered":"When the Scam Sounds Like Your Boss"},"content":{"rendered":"<p><span data-contrast=\"auto\">A quick note from your CISO: the next phishing attempt may not look fake.\u00a0It may sound familiar!<\/span><\/p>\n<p><span data-contrast=\"auto\">A few years ago, spotting a scam was usually a matter of catching the obvious signs: bad grammar, strange formatting, or the classic \u201cDear User\u201d greeting \u2014 the cybersecurity equivalent of a fake mustache. Today\u2019s version may reference a real project, use the right tone for your department, or include a voicemail that sounds exactly like someone you know. That last part is where things get<\/span><b><span data-contrast=\"auto\">\u00a0<\/span><\/b><span data-contrast=\"auto\">uncomfortably interesting.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Wait;\u00a0They Can Clone Voices Now?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Yes!\u00a0AI voice-cloning tools can now create a convincing version of\u00a0someone\u2019s\u00a0voice from a surprisingly small audio sample:\u00a0a public video, a podcast, a\u00a0conference recording, or a\u00a0short clip posted online. A call or voicemail may sound familiar without being legitimate, especially\u00a0when it\u00a0asks you to move\u00a0quickly,\u00a0share information, or do \u201cone small favor,\u201d which in\u00a0scam\u00a0language\u00a0is rarely small.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Put another way:\u00a0\u201cIt sounded like them\u201d\u00a0is\u00a0useful\u00a0context.\u00a0Attackers\u00a0do not\u00a0need access to Chapman systems\u00a0to be convincing. A\u00a0little public information, a familiar name, and\u00a0a well-timed sense of\u00a0urgency\u00a0can do a lot of damage.\u00a0Cybercriminals\u00a0are persistent \u2014\u00a0basically the\u00a0raccoons of the internet.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">What Does This Look Like in the Real World?<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The most common version is vishing\u00a0or\u00a0voice phishing. In practice, that could be\u00a0a voicemail from\u00a0\u201cyour supervisor\u201d\u00a0asking for a quick favor, a call about payroll or vendor payments, or a follow-up to an email that already seemed believable. Add voice cloning, and the request\u00a0does not\u00a0just\u00a0feel\u00a0convincing;\u00a0it sounds familiar. That combination of urgency and familiarity is what makes these attacks\u00a0effective, especially on\u00a0a busy day\u00a0when everyone is trying to keep things moving. Attackers\u00a0are counting on our desire not to be difficult. Rude, but effective.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">Why This Works (Even If You Know About It)<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">These\u00a0scams\u00a0work because the message lines up just enough: it sounds like someone you\u00a0trust,\u00a0it arrives at a busy moment, and the context feels close enough to be real. AI helps attackers research, personalize, and scale those interactions,\u00a0which means\u00a0more attempts\u00a0can\u00a0sound\u00a0believable and\u00a0land with\u00a0the right\u00a0person at the wrong time.\u00a0It is not\u00a0magic. It is automation with bad manners.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/security-insider\/threat-landscape\/microsoft-digital-defense-report-2024\"><span data-contrast=\"none\">The Microsoft Digital Defense Report 2024<\/span><\/a><span data-contrast=\"auto\">\u00a0notes\u00a0that deepfakes and AI-enabled impersonation are being used to create convincing interactions, including real-time voice and video impersonation designed to build trust. The goal\u00a0is not\u00a0to fool everyone. It is\u00a0to catch one person at the wrong moment. If something sounds exactly like a colleague, your brain may not stop to run a\u00a0full\u00a0security review; it moves straight to\u00a0\u201chow do I help?\u201d\u00a0That instinct is good.\u00a0It is also what attackers are counting on.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><b><span data-contrast=\"auto\">What You Should Do Differently (Practical Version)<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Slow down urgent requests, especially ones involving money, credentials, access, or sensitive data. \u201cUrgent\u201d is often the first red flag, not the last.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Verify through a second channel. Call the person back on a saved number, send a quick Teams message, or check with your department. Not because you distrust people, but\u00a0because you do not want to trust the wrong version of them.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Do not assume familiar means safe. If something\u00a0feels slightly\u00a0off,\u00a0that feeling is worth a second look.\u00a0Your \u201cthat\u2019s weird\u201d instinct\u00a0is often\u00a0doing useful work.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Report it, even if you are unsure. Early reporting helps us spot patterns, block similar attempts, and protect others across campus.\u00a0We would much rather review a false alarm than clean up a\u00a0real one.<\/span><\/li>\n<\/ul>\n<p><b><span data-contrast=\"auto\">Final Thought<\/span><\/b><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Cybersecurity used to be about spotting the obvious fakes. Now the fakes may sound familiar, reference real work, and arrive at exactly the wrong time. If something feels off,\u00a0especially around money, access, sensitive information, or urgency,\u00a0pause, verify it\u00a0through\u00a0another\u00a0channel, and report\u00a0it\u00a0to\u00a0<\/span><a href=\"mailto:abuse@chapman.edu\"><span data-contrast=\"none\">abuse@chapman.edu<\/span><\/a><span data-contrast=\"auto\">.\u00a0Trust is good. Verified trust is better.<\/span><\/p>\n<p><span data-contrast=\"auto\"><br \/>\nStay safe, stay vigilant!<\/span><br \/>\n<span data-contrast=\"auto\">Keith Barros<\/span><br \/>\n<span data-contrast=\"auto\">Chief Information Security Officer (CISO)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A quick note from your CISO: the next phishing attempt may not look fake.\u00a0It may sound familiar! A few years [&hellip;]<\/p>\n","protected":false},"author":3283,"featured_media":4304,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"custom_author_name":"Keith Barros","chapman_pin_hero_slider":"","footnotes":""},"categories":[35,23,246],"tags":[34,36,45],"class_list":["post-4303","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information-security","category-ist","category-online-safety","tag-cybersecurity","tag-infosec","tag-phishing"],"_links":{"self":[{"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/posts\/4303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/users\/3283"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/comments?post=4303"}],"version-history":[{"count":1,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/posts\/4303\/revisions"}],"predecessor-version":[{"id":4305,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/posts\/4303\/revisions\/4305"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/media\/4304"}],"wp:attachment":[{"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/media?parent=4303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/categories?post=4303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.chapman.edu\/information-systems\/wp-json\/wp\/v2\/tags?post=4303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}