Decision-first exercise
Callback support scam: refuse remote access
Practice ending a synthetic support call, using the official IT route, and responding if remote-management software was installed.
Synthetic scenario · Content reviewed
Synthetic callback and voice call
What you receive
Decision 1 of 3
The reasoning appears after you lock this decision. Your choices remain only in this page and are not sent anywhere.
Text version for assistive technology and automated testing (includes the answers)
Exercise: Callback support scam: refuse remote access Scenario: Synthetic callback and voice call Channel: Email followed by phone call Sender: Renewals <billing@endpoint-renewal.example> Subject: Receipt: annual endpoint protection renewal — $489.00 Message: The email says to call within 30 minutes to reverse an unexpected charge. Message: On the call, the agent says they must inspect the device before issuing a refund. Message: They direct you to install AssistNow Remote Client and read back a session code. Question: What should you do when the caller asks for the remote-session code? Decision 1: Before calling, how should you verify the claimed renewal? Option: Call the cancellation number in the email Option: Check purchasing/card records and use the known vendor or internal IT contact Option: Reply asking whether the charge is genuine Preferred option: Check purchasing/card records and use the known vendor or internal IT contact Rationale: The charge claim should be checked in authoritative account and purchasing records, then handled through a known support route. Decision 2: What is the safest immediate response? Context: The caller asks you to install a remote client and provide its session code. Option: Share the code but watch the screen Option: End the call and contact official IT/support Option: Permit view-only access Preferred option: End the call and contact official IT/support Rationale: FTC guidance says unexpected tech-support callers may seek remote access; use a person and number you already trust. Decision 3: What is the best next step? Context: Assume the remote client was installed and the caller connected briefly. Option: Uninstall it and continue working Option: Disconnect from networks if policy permits, end the session, and call official IT/security for containment Option: Call back and ask the agent to remove the tool Preferred option: Disconnect from networks if policy permits, end the session, and call official IT/security for containment Rationale: A connected RMM session is a potential system-access event. Follow the organization's known containment and recovery process. Answer: End the call; the message supplied the number and still controls the conversation. Calling a number from an unsolicited notice is not independent verification. A remote-management session can hand an unknown caller meaningful access even when described as view-only or refund support. Signals: - Strong evidence: The message supplies the callback number and cancellation story. Calling it keeps verification inside the requester's controlled channel. - Strong evidence: The caller requests remote-management installation and a session code. Those actions can grant system access and are not required to verify whether a transaction exists. - Contextual signal: A precise renewal price and short deadline. Specificity and urgency make the pretext persuasive but do not authenticate the charge. Safe actions: - End the call without installing software or sharing a session code. - Check the charge in authoritative records and use the official IT or vendor channel. - If access occurred, end the session and follow official containment, credential, and payment-response procedures. ATT&CK mapping: T1566.004 Spearphishing Voice version 1.2 Mapping evidence: The synthetic voice interaction directs the learner to install an attacker-accessible remote-management client and provide a session code. Mapping rationale: This mapping applies because the voice interaction is used to gain system access. A generic unwanted support call without that access objective would not be mapped by default. Reviewed: 2026-08-02
Evidence
Authoritative references
- U.S. Federal Trade CommissionHow to spot, avoid, and report tech support scams
- MITRE ATT&CKATT&CK T1566.004: Spearphishing Voice
- CISA, NSA, FBI, MS-ISACPhishing Guidance: Stopping the Attack Cycle at Phase One
Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.