Person verifying a suspicious phone request using a trusted callback number
| |

The Callback Rule: A Five-Minute Defense Against AI Impersonation Scams

A familiar voice is no longer proof of identity.

Someone can call sounding like an executive, family member, vendor, or business partner and ask for a wire transfer, an authentication code, or a confidential document.[1][2] The request may arrive with details that make it feel legitimate: a real project name, a colleague’s title, a recent trip, or a plausible emergency.[2]

Artificial intelligence did not invent impersonation fraud. It made an old tactic easier to scale and harder to judge by appearance alone. The FBI has warned that criminals use AI to produce targeted phishing messages and clone the voices or video likenesses of trusted people.[1] In a later alert, the FBI described campaigns using text messages and AI-generated voice messages to impersonate senior officials, build rapport, and move victims to encrypted messaging services.[2]

The practical response is not to become an expert at spotting synthetic media. It is to change how important requests are approved.

Use a trusted channel, not the channel that brought the request

The callback rule is simple:

When a message asks for money, credentials, sensitive information, or an unusual action, stop and verify the request through contact information you already trust.

Do not reply to the same text. Do not call the number shown in the message. Do not use a replacement phone number or link supplied by the requester.[2][3]

Instead, use a number saved before the request arrived, a company directory, a known internal chat account, or another established contact.[2][3] The FTC gives the same advice for suspected voice-cloning scams: call the person using a number you already know belongs to them and verify the story.[3]

This works because the callback breaks the attacker’s control of the conversation. A convincing voice can keep you inside a false story. A trusted second channel forces the request to survive an independent check.

Decide which requests always trigger verification

A callback rule fails when people must debate whether a request is suspicious enough. Define the triggers in advance.

For a business, require independent verification when someone asks to:[1][2]

  • change a vendor’s bank or payment details;
  • send a wire, cryptocurrency payment, gift card, or expedited refund;
  • disclose a password, one-time code, customer record, tax document, or employee information;
  • bypass the normal approval process because an executive is traveling or unavailable;
  • install software, open a document, or move a conversation to a new messaging application;
  • provide contact information for colleagues, partners, or executives.

For a family, use the rule for emergency money requests, account-recovery codes, requests for identity documents, and calls claiming that a relative has been arrested, injured, or stranded.[2][3]

The FBI specifically advises people to verify new contact information through a previously confirmed platform, never disclose two-factor authentication codes, and independently confirm requests involving money or cryptocurrency.[2]

Make the verification specific

A weak callback sounds like this: “Did you send me something?”

That question can produce an ambiguous answer, especially if the real person recently sent several messages. A better verification states the action:

“I received a request to change Acme’s bank details and release a $14,800 payment today. Did you authorize that exact change?”

For higher-risk actions, require a second approver. Payment-detail changes should be verified with a known contact at the vendor and reviewed internally by someone who did not initiate the change.[1][2] The person performing the callback should record when the verification occurred and which trusted number or channel was used.

The goal is not paperwork for its own sake. It is to prevent urgency from becoming authorization.

Give people permission to slow down

Most impersonation scams put social pressure on the target.[2][3] The caller is important. The deadline is immediate. The situation is confidential. The normal process is supposedly unavailable.

A useful policy makes the pause non-negotiable:

  • Employees will not be penalized for delaying a sensitive request while they verify it.
  • Executives will support callbacks, even when the original request was genuine.
  • No one may ask another person to disclose an authentication code.
  • A request to bypass verification is itself a reason to escalate.

CISA’s small-business guidance treats security as a leadership and culture issue, not something that can be delegated entirely to IT. It recommends formal staff training, clear escalation duties, incident-response planning, and regular exercises.[4] The callback rule works best when leaders practice it themselves.

Practice before the real call

A short practice exercise can expose gaps before a real incident. CISA recommends regular tabletop exercises so leaders and staff can build and test their response reflexes.[4]

Send a fictional urgent request to the people who handle payments, payroll, customer data, or executive communications. Ask them to explain what they would do, which number they would call, who could approve the request, and where they would report the attempt.

Then test the awkward cases:

  • What if the executive says they lost their phone?
  • What if the vendor claims its usual contact has left?
  • What if the request arrives late on a Friday?
  • What if the voice sounds exactly right?

If the procedure depends on one unavailable person, fix that now. Keep an offline or otherwise resilient contact list for essential staff and vendors. Make sure backups are current, and ensure employees know how to report a near miss.

If someone already acted on the request

Move quickly without blaming the person who was deceived.

Contact the bank or payment provider immediately and ask whether the transaction can be stopped or recalled. Notify the organization’s security or incident-response contact. Preserve the message, call details, email headers, payment instructions, and a short timeline of events. Change exposed credentials and review affected accounts if anyone shared a password or authentication code.[1][2]

The FBI directs cybercrime victims to report incidents through the Internet Crime Complaint Center at IC3.gov.[1][2] Suspected scams can also be reported to the FTC at ReportFraud.ftc.gov.[3]

A voice can be copied. Your process should be harder to imitate.

Trying to judge every call, video, or message by how real it looks will become less reliable over time. A callback rule does not require special detection software. It relies on a known channel, a precise verification question, and permission to stop an urgent request.

Write the rule down. Tell employees and family members when to use it. Practice it once. Five minutes of verification can interrupt a fraud attempt before trust turns into a transaction.

Practical next step

Choose three actions that will always require a callback in your organization or household. Write down the trusted contact method for each person involved, then run one short practice scenario this week.

For more practical guidance on cybersecurity and safer AI use, subscribe to Cyber & AI Insights.

Sources

[1] https://www.fbi.gov/contact-us/field-offices/sanfrancisco/news/fbi-warns-of-increasing-threat-of-cyber-criminals-utilizing-artificial-intelligence — FBI Warns of Increasing Threat of Cyber Criminals Utilizing Artificial Intelligence [2] https://www.fbi.gov/investigate/cyber/alerts/2025/senior-us-officials-continue-to-be-impersonated-in-malicious-messaging-campaign — Senior U.S. Officials Continue To Be Impersonated in Malicious Messaging Campaign [3] https://consumer.ftc.gov/consumer-alerts/2024/04/fighting-back-against-harmful-voice-cloning — Fighting back against harmful voice cloning [4] https://www.cisa.gov/cyber-guidance-small-businesses — Cyber Guidance for Small Businesses

Similar Posts