top of page

The Newest Way In Is a Phone Call. Baxter Is Just the Latest Name.

Writer: cAIberOps (SY-ber-ops) | MSSP
cAIberOps (SY-ber-ops) | MSSP
Aug 21
6 min read

The most effective way into a company in 2026 is not a clever piece of malware. It is a phone call. Someone researches your staff, picks one, calls them, and talks them through the act of handing over access. The tools you spent your budget on never get a vote, because nothing was hacked. A person was persuaded.

This is the attack pattern behind a run of the year's biggest breaches, and it is worth understanding stage by stage, because every stage is a place a trained person can stop it and an untrained one cannot.

Why the phone, and why now

For a decade the advice was about email. Do not click the link, check the sender, look for typos. Firms got better at it, filters got better at it, and attackers went looking for the softer target. They found the phone.

A voice call carries urgency and authority that an email cannot fake as easily. There is a real person on the line, they sound calm and official, and they are asking for something that sounds reasonable. Security teams have spent years hardening the inbox. Far fewer have spent any time preparing the person who answers the phone.

The groups running these campaigns know that. In July, Health-ISAC, the information-sharing body for the healthcare sector, warned members of a rising wave of exactly this: attackers using voice phishing to manipulate employees and help desks into resetting passwords, changing multifactor settings, and enrolling new devices. It named the extortion crew ShinyHunters and pointed at custom phishing kits built specifically for voice calls, kits designed for live interaction that can change what they show and pop authentication dialogs in real time as the call progresses.

Read that last part twice. The fake page is not a static decoy. It is driven live, by the person on the phone, while they keep the victim talking.

The attack, one stage at a time

Strip a modern vishing breach down and the same five steps appear.

Research. Before any call, the attacker learns the target. Who works there, who reports to whom, which vendors and platforms the firm uses, who sits at the help desk. Most of this is public: a company site, LinkedIn, a job posting that names the exact software the firm runs. The call that follows does not sound like a stranger, because in a sense it is not one.

Pretext. The caller becomes whoever the moment needs. IT support returning your ticket. An urgent approval the boss is waiting on. A document that has to be reviewed before end of day. The specific story varies, but the engine underneath is always the same: a plausible identity plus manufactured urgency, so the target acts before they think.

The page. At some point the target is guided to a sign-in page, and it looks right. Security researchers at ReliaQuest have catalogued the domains these crews register for this: company-okta-style addresses, dashboard-salesforce-style addresses, portals themed as ticket systems. The employee signs in. Because the attacker is on the line, they capture the password and the multifactor code in real time and use them immediately, before the code expires.

Access. Now the attacker is inside as the employee, and often the tools see a normal, authenticated login, because it is one. In a variant Microsoft has documented, no password is even stolen: the caller simply talks the employee through approving a connected application on a real consent screen, and the malicious app quietly carries the access out the door.

Extortion. Data gets pulled, and days or weeks later the company appears on a leak site with a demand. By then the phone call is a distant memory that nobody flagged.

Where Baxter fits, carefully

You have probably seen Baxter International in the news this month. On August 13 the company confirmed a cybersecurity incident involving, in its own words, certain third-party applications, with no impact to manufacturing, patient services, or business continuity. A day later ShinyHunters, the same crew Health-ISAC warned about, listed Baxter and claimed more than seven million records. That number is an unverified attacker claim, and we are not going to treat it as fact.

We want to be careful about one thing, because plenty of coverage will not be. Baxter has not publicly stated how the intruders first got in, and neither will we. What is documented is the campaign around it: this group's calling card, in this sector, this summer, is the researched phone call and the live fake page. Baxter is not a lesson in what Baxter did. It is a marker of how close this pattern now is to organizations you recognize.

The uncomfortable part for anyone who bought good tools

Here is the sentence that matters for a business owner. Every control in that attack chain can be working perfectly and the breach still happens.

The email filter is not tested, because the lure came by phone. The endpoint tool sees a valid login, because the credentials are real. Multifactor is enabled, and it is defeated live, because the victim reads the code aloud to a helpful voice. The connected-app approval is a legitimate feature used exactly as designed. Nothing malfunctioned. A person was talked past all of it.

That is not an argument against tools. Tools stop the enormous volume of attacks that never reach a human, and you should run them. It is an argument about what the last line of defense actually is. In an attack that is aimed at a person and not a system, the person is the final control, and preparing them is not a compliance chore or a box an insurer wants ticked. It is how you guard the castle after every wall has been walked around.

What actually prepares that person

Not a poster. Not a once-a-year video watched at 1.5 speed. Preparation that changes behavior looks like three things.

A rule that removes the judgment call. The most protective policies take pressure off the individual. No one resets a password, approves an app, or reads back a code because of an inbound call, ever, no matter who the caller claims to be. Verification always goes outbound, to a number the employee already had. A staff member who knows that rule does not have to out-argue a professional manipulator in real time. They just have to follow the rule.

Practice against the real thing. Awareness training that works uses simulations of current attacks, including voice and text, measured against a baseline, so people meet the tactic in a drill before they meet it for real. Published industry benchmarking across millions of users shows the share of employees who will fail a phishing test dropping from roughly one in three without training to around one in twenty after a year of continuous testing and training. The number that matters is not that people fail. It is how far and how fast failure drops when you actually train.

A help desk that treats identity as the crown jewel. These campaigns love the help desk, because its whole job is to be helpful to people who are locked out. A help desk that verifies identity through a channel the caller cannot control, and that is allowed to slow down without getting in trouble, closes the exact door this attack walks through.

Where we fit, and where we do not

We are a managed security provider for small and medium businesses, and this is the exact gap we build around. Managed email security is the platform: it catches the phishing that does come by inbox, endpoint detection watches for a stolen credential in use, and dark web monitoring surfaces the leaked logins these crews trade on. On top of that platform sits the part this whole article is about, and the part we treat as the point rather than the add-on: security awareness training that is built to change behavior, not to generate a monthly number for a file.

Most programs run one session at onboarding and one test email a month, and when someone fails it is logged as a statistic and nothing happens. We do not run it that way. A miss is a trigger, not a tally, and the training is designed so people actually take it seriously, because a program nobody respects protects nobody. That is the difference between training that satisfies an auditor and training that changes what your staff do at 3pm on a Friday when the phone rings. If you want a concrete first step, our free two-week email assessment shows you what is already reaching your team through the inbox, at no cost and with nothing to change. For healthcare organizations, where this campaign is aiming right now, here is how we work with practices.

The question worth asking this week

Not "do we have MFA." You probably do, and it can be talked around.

Ask instead: if someone called our office this afternoon, sounded official, created a deadline, and asked a staff member to sign in somewhere or approve something, is that person carrying a rule that stops them, or are they carrying their own good judgment against a professional?

Good judgment is not a plan. A rule, practiced, is.

If you run a small or medium business in Washington DC, Northern Virginia, or Maryland and want a plain-English read on where your people and your controls stand, book a free 15-minute call.

Comments


bottom of page