Decision-first exercise

Callback support scam: refuse remote access

Practice ending a synthetic support call, using the official IT route, and responding if remote-management software was installed.

Synthetic scenario · Content reviewed
Synthetic callback and voice call

What you receive

Synthetic example
Channel
Email followed by phone call
Sender
Renewals <billing@endpoint-renewal.example>
Subject
Receipt: annual endpoint protection renewal — $489.00

The email says to call within 30 minutes to reverse an unexpected charge.

On the call, the agent says they must inspect the device before issuing a refund.

They direct you to install AssistNow Remote Client and read back a session code.

Decision 1 of 3
Before calling, how should you verify the claimed renewal?

Choose before revealing the explanation.

The reasoning appears after you lock this decision. Your choices remain only in this page and are not sent anywhere.

Text version for assistive technology and automated testing (includes the answers)
Exercise: Callback support scam: refuse remote access
Scenario: Synthetic callback and voice call
Channel: Email followed by phone call
Sender: Renewals <billing@endpoint-renewal.example>
Subject: Receipt: annual endpoint protection renewal — $489.00
Message: The email says to call within 30 minutes to reverse an unexpected charge.
Message: On the call, the agent says they must inspect the device before issuing a refund.
Message: They direct you to install AssistNow Remote Client and read back a session code.
Question: What should you do when the caller asks for the remote-session code?
Decision 1: Before calling, how should you verify the claimed renewal?
Option: Call the cancellation number in the email
Option: Check purchasing/card records and use the known vendor or internal IT contact
Option: Reply asking whether the charge is genuine
Preferred option: Check purchasing/card records and use the known vendor or internal IT contact
Rationale: The charge claim should be checked in authoritative account and purchasing records, then handled through a known support route.
Decision 2: What is the safest immediate response?
Context: The caller asks you to install a remote client and provide its session code.
Option: Share the code but watch the screen
Option: End the call and contact official IT/support
Option: Permit view-only access
Preferred option: End the call and contact official IT/support
Rationale: FTC guidance says unexpected tech-support callers may seek remote access; use a person and number you already trust.
Decision 3: What is the best next step?
Context: Assume the remote client was installed and the caller connected briefly.
Option: Uninstall it and continue working
Option: Disconnect from networks if policy permits, end the session, and call official IT/security for containment
Option: Call back and ask the agent to remove the tool
Preferred option: Disconnect from networks if policy permits, end the session, and call official IT/security for containment
Rationale: A connected RMM session is a potential system-access event. Follow the organization's known containment and recovery process.
Answer: End the call; the message supplied the number and still controls the conversation.
Calling a number from an unsolicited notice is not independent verification. A remote-management session can hand an unknown caller meaningful access even when described as view-only or refund support.
Signals:
- Strong evidence: The message supplies the callback number and cancellation story. Calling it keeps verification inside the requester's controlled channel.
- Strong evidence: The caller requests remote-management installation and a session code. Those actions can grant system access and are not required to verify whether a transaction exists.
- Contextual signal: A precise renewal price and short deadline. Specificity and urgency make the pretext persuasive but do not authenticate the charge.
Safe actions:
- End the call without installing software or sharing a session code.
- Check the charge in authoritative records and use the official IT or vendor channel.
- If access occurred, end the session and follow official containment, credential, and payment-response procedures.
ATT&CK mapping: T1566.004 Spearphishing Voice version 1.2
Mapping evidence: The synthetic voice interaction directs the learner to install an attacker-accessible remote-management client and provide a session code.
Mapping rationale: This mapping applies because the voice interaction is used to gain system access. A generic unwanted support call without that access objective would not be mapped by default.
Reviewed: 2026-08-02
Evidence

Authoritative references

Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.