Category
Social EngineeringA large insurer lost Social Security numbers and medical records this month. The way in was not a hack. It was a friendly phone call to two employees. Here is why no gadget stops this, and what actually does.
See Where Your Business Stands →
A plain-English computer security scan. No card needed to see your results.
The problem: A social engineering phone scam does not break your locks. It talks your people into opening them. The criminal calls, sounds friendly and legitimate, and asks a helpful employee to let them in or reset something. And now AI lets a total stranger sound exactly like someone your team already trusts.
The straight answer: You can buy every security tool on the market and a smooth phone call still walks right past all of it, because the target is not your computer. It is your team’s good manners. Let me show you how it works, what one wrong call actually costs, and what real protection against it looks like.
Hey folks! This story is short, and that is exactly what makes it scary. There was no genius code and no midnight hacking scene.
Markel, a large insurance company, just disclosed that criminals got into part of its systems and made off with names, Social Security numbers, driver’s licenses, and medical information. The way in was not a fancy hack. It was a conversation. The criminals talked two employees into giving them access. That is the whole break-in.
This is the tactic sweeping through businesses right now. Instead of breaking a lock, the criminal calls your office. He sounds friendly and legitimate. Maybe he claims to be from IT, or from a vendor you use. Then he asks a helpful person to let him in or reset a password. It works because your people want to be helpful. That instinct, the one that makes them good at their jobs, is exactly the thing being used against them.
And here is what makes 2026 different from five years ago. AI now lets a total stranger sound exactly like someone your team would trust, right down to the voice. The old advice, “you will be able to tell it is a stranger,” does not hold anymore. The voice on the line can be a perfect copy of a boss, a vendor, a coworker.
Source: Data Breach Brief (Markel Insurance), week of July 20, 2026.
For years, security was about the walls. Firewalls, antivirus, passwords. The whole idea was to build a strong enough fence around the computers. A firewall, by the way, is just a digital gatekeeper that controls what traffic gets in and out. That fence still matters. But the criminals stopped climbing it.
They found an easier way over: your people. Every employee with a phone and a password is now part of the wall, whether they signed up for that or not. And a wall made of busy, well-meaning humans has a gate in it that no software controls, the simple human wish to be helpful and not make a fuss.
So here is the shift most owners have not caught up to. You can spend every dollar in your budget on tools that guard the computers, and a criminal will simply pick up the phone and ask a person to hand him the keys. The target moved from your machines to your team, and almost nobody moved their defense to match. This is not about whether your people are smart. Smart, careful people get caught by this every day, because it is built to use their best instincts against them.
I say this on the radio all the time: it is not right that the criminals get all the AI power. They are using it to sound like people you trust. The answer is not to make your staff paranoid. It is to make sure someone has actually taught them the one habit that beats this, and that someone is watching the systems those calls are trying to reach.
One friendly call, one helpful employee, and the whole business is exposed. Let me lay out what is actually at stake, because this is a business problem, not a tech one.
That is the whole ugly bargain. The most expensive break-in of the year can come through the cheapest tool a criminal owns, a telephone, aimed at the most decent instinct in your office. Which is exactly why protection here is not another gadget. It is training plus a real team watching what those calls are reaching for.
My own father fell for a phishing email. That is a fake message built to trick you into giving up a password or your money. More than three decades in this field, and it still reached the person I most wanted to protect. Scammers got into his computer from far away and started hunting for his financial papers. My step-mother noticed something was wrong and called me. I stopped them before they reached his bank logins. We were lucky. We caught it in time. A day slower and it would have been a very different phone call.
I tell you that because the trick that got my dad and the trick that got Markel are cousins. Both use trust, not technology. That is why I do this the way I do. More than 35 years at this, since 1991. FBI InfraGard trainer. Not one client I manage has ever been hit by ransomware, which is software that locks up your files and holds them for money. That is not luck. It is a real person watching the doors and teaching people how to spot the ones that talk back.
I believe your people are smart. So are the employees at Markel, and at every company that has been hit this way. That is the uncomfortable part: this scam is not built to fool dumb people. It is built to use a smart, helpful person’s best instincts against them, and it is now backed by AI that can copy a familiar voice. Being smart is not the defense. Having been taught the exact habit that stops it, and practicing it, is the defense.
So the honest question is not “are my people smart.” It is “if a friendly, familiar-sounding voice called tomorrow claiming to be from IT, would every one of them know to hang up and call back on a number they already have?” A once-a-year “stay alert” email does not build that habit. If you cannot say yes with confidence, that is the open door.
Let me ask you a few plain questions, and just answer them in your head. You trust your team, right? You hired good, capable people so you would not have to worry about the day-to-day. You are a careful owner, the kind who reads a warning like this all the way down. And you also just read that two capable employees at a large company handed criminals the keys over the phone, which means trusting good people and being exposed to this can both be true in the same business. Holding those two thoughts at once is uncomfortable.
That discomfort is not a sign your people are the problem. It is the gap between the good team you have and a habit nobody ever actually taught them, against a trick that got a lot sharper this year. That gap is not a knock on you or on them. It opened because the attack moved from the computers to the phone, and because “be careful out there” was never real training.
Here is the thing about that gap. You close it one of two ways. You can tell yourself your folks would surely catch it, and carry that quiet question into the next headline like this one. Or you can take a few minutes, find out where you actually stand and get your people the one habit that beats this, and put it to bed. One of those roads ends the worry. The other just reschedules it. Acting is not the risky move. Acting is what makes the worry stop.
No gadget stops a friendly phone call. What stops it is people who know the one habit that beats it, and a real team watching the systems those calls are trying to reach. You do not have to do it alone.
Book a call, on us. We scan your business and fix the three things most likely to hurt you right now. You will not pay a dime, and you decide what happens next.
Not one client we manage has ever been hit by ransomware. That is not luck. That is someone actually watching the doors.
You run your business. We keep it running.
Book My Call →
A few minutes with a real person, straight talk on where your business stands. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#SocialEngineering #SmallBusinessCybersecurity #Vishing #ForwardToSafety
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Join 10,000+ cybersecurity professionals