skip to content

Why do pretext callers impersonate an outsourced desk engineer rather than a colleague on your floor?

level: juniorimportance: must knowfreq 58%

answer

  1. who could contradict this claim?
  2. unfamiliarity is expected here
  3. no internal directory holds them
  4. every check runs back through the caller

basics

~20 s

Impersonation works where the target has no sideways check. A colleague can be confirmed by walking over or asking someone who knows them; an outsourced overnight engineer is a name nobody has met, on a rota nobody here can read.

solid answer

~40 s

A borrowed identity is chosen for its unverifiability, not its authority. Impersonating someone on your floor fails on the first sideways check: you look up, you ask the next desk, you notice the voice is wrong. The named engineer on a supplier's overnight desk removes all of that. The receiver has never met them, cannot find them in an internal directory, has no colleague who would recognise the name, and knows that unfamiliar names on that rota are normal. The same property explains the travelling executive and the supplier's accounts contact: each is an identity whose absence and unfamiliarity are expected rather than odd. The pretext is then built so that every way of checking runs back through the caller.

go deeper

for a junior

Be ready to say in one sentence what makes an impersonated identity hard to challenge: nobody on the receiving side has a way to confirm it that does not run back through the caller.

for a middle

Explain why unfamiliarity is normal for the identities chosen - rotating supplier rotas, contractors, travelling staff - so the receiver's usual sense that something is off never fires.

for a senior

Show which classes of request in your estate can currently be actioned on a caller's word alone, and where an organisational boundary removes every independent way to place the person.

for a principal

Own the decision of which cross-organisation identities are agreed in advance with the supplier, versus improvised at 03:00 by whoever answers, and who bears the cost of that friction.

## The property that is actually being selected for A pretext has three moving parts: what is asked for, how much research went into it, and **whose identity the caller wears**. This is the third. The instinct is that an operator borrows the identity with the most *authority* — a director, a partner, a regulator. In practice the dominant selection criterion is different and much duller: the operator borrows the identity the receiver **cannot check sideways**. A sideways check is any confirmation that does not run through the caller. You turn your head and ask the person next to you. You look the name up in an internal directory. You recognise the voice because you have heard it in twenty stand-ups. You walk two floors up. None of these are formal controls, nobody wrote them down, and they are the reason internal impersonation is hard: the claim has to survive checks the caller neither controls nor even knows about. ## Three identities with no sideways check **The outsourced desk.** A supplier runs overnight support for a Linux server fleet. The rota rotates, staff turn over, and the receiver has never met anyone on it. There is no internal directory entry, no colleague who would recognise the name, and no in-person option at 03:00. Critically, *unfamiliarity is the baseline* — the receiver's usual instinct, "I don't know this person", carries zero information here because they do not know any of them. **The unreachable executive.** Travelling, in back-to-back meetings, on another continent. The sideways path exists on paper — an assistant, a colleague — but the pretext supplies a reason not to use it, usually confidentiality or time, and the receiver is often junior enough that walking into that office was never a real option anyway. **The supplier's accounts contact.** The relationship is real and the company is real; only the person is borrowed. The receiver deals with an organisation, not a face, and has no way to enumerate who works in its finance team. In each case the identity's *non-availability is normal*. That is the whole trick. An impersonation that requires a strange story to explain why you cannot verify it is fragile; an impersonation where verification was never available in the first place needs no story at all. ## The closing move: every path leads back to the caller Once the identity is chosen, the pretext is arranged so that any attempt to confirm it is satisfied *by the caller*. The number to call back on is read out on the call. The supplier contact to check with is named by the caller. The email thread that establishes context was started by the caller. This is what makes the whole class of "just verify them" advice hollow unless the verification path is one the receiver already held. ## Why this is worth knowing at all It predicts where the exposure is. Draw the boundary of your organisation and look at every party across it who can telephone or email someone here and be believed: suppliers, contractors, outsourced desks, managed providers, auditors, recruiters, couriers. Everyone across that line is an identity nobody inside can place, and the ones who contact you routinely are the ones whose contact will not surprise anybody. It also reframes what you should be suspicious of. The receiver cannot usefully be suspicious of the *person*, because the identity was chosen so that suspicion has nothing to attach to. What can still be unusual is the **request**: an ask that desk has never made before, an action outside what the contract covers, a first-ever change to where something is sent. Structure sits in the request, not in the caller. ## The counter-property If the attack depends on the absence of a path that does not run through the caller, the control class that removes it is a path that does not run through the caller — an address of record you already hold, a person on the supplier side you had a relationship with before this call, an attribute in a system the caller cannot influence. The rest of this area is about what such a path must satisfy to survive a caller who has done their homework, and about the two signals people wrongly treat as such a path: the number that appeared on the call, and the voice on the other end.

  • The receiver has never met anyone on that desk, so what would even count as unfamiliar here?
    Nothing about the person. Unfamiliarity is the baseline for a rotating third-party rota, which is why the identity was chosen. What can still be unusual is the request: a shape of ask that desk has never made, an action outside what the contract covers, or a first-ever change to where something is sent. That is a property of the ask, not of the caller.
  • Does this reasoning hold when the impersonated party is a senior executive rather than a supplier?
    Yes, for the same structural reason. An executive who is travelling or in back-to-back meetings is unreachable by design, and a junior receiver was never going to walk into their office to check. A sideways path exists on paper through an assistant or a peer, but the pretext supplies a reason not to use it, usually confidentiality or time pressure.

A stranger claiming to be the new night porter is far harder to challenge than one claiming to be your team lead: nobody on the night shift knows each other's faces, and that is exactly why the uniform gets borrowed.

saying these in an interview costs you the question

  • Says the caller always picks whoever has the most authority
  • Assumes an unfamiliar name on a supplier rota is itself suspicious
  • Thinks a convincing manner is what carries the pretext
  • Believes impersonating an internal colleague is equally easy
  • Advises 'just verify the caller' without asking through what path

context