skip to content

Building the Lure

The three choices behind a believable lure: what to ask, how many hours to spend researching it, and whose identity to wear. Interviewers ask because the taught tells exist only at the cheap end.

on this pageshow

explore

questions

13

Why do pretext callers impersonate an outsourced desk engineer rather than a colleague on your floor?

level: juniorimportance: must knowfreq 58%

answer

  1. who could contradict this claim?
  2. unfamiliarity is expected here
  3. no internal directory holds them
  4. every check runs back through the caller

basics

~20 s

Impersonation works where the target has no sideways check. A colleague can be confirmed by walking over or asking someone who knows them; an outsourced overnight engineer is a name nobody has met, on a rota nobody here can read.

solid answer

~40 s

A borrowed identity is chosen for its unverifiability, not its authority. Impersonating someone on your floor fails on the first sideways check: you look up, you ask the next desk, you notice the voice is wrong. The named engineer on a supplier's overnight desk removes all of that. The receiver has never met them, cannot find them in an internal directory, has no colleague who would recognise the name, and knows that unfamiliar names on that rota are normal. The same property explains the travelling executive and the supplier's accounts contact: each is an identity whose absence and unfamiliarity are expected rather than odd. The pretext is then built so that every way of checking runs back through the caller.

go deeper

for a junior

Be ready to say in one sentence what makes an impersonated identity hard to challenge: nobody on the receiving side has a way to confirm it that does not run back through the caller.

for a middle

Explain why unfamiliarity is normal for the identities chosen - rotating supplier rotas, contractors, travelling staff - so the receiver's usual sense that something is off never fires.

for a senior

Show which classes of request in your estate can currently be actioned on a caller's word alone, and where an organisational boundary removes every independent way to place the person.

for a principal

Own the decision of which cross-organisation identities are agreed in advance with the supplier, versus improvised at 03:00 by whoever answers, and who bears the cost of that friction.

## The property that is actually being selected for A pretext has three moving parts: what is asked for, how much research went into it, and **whose identity the caller wears**. This is the third. The instinct is that an operator borrows the identity with the most *authority* — a director, a partner, a regulator. In practice the dominant selection criterion is different and much duller: the operator borrows the identity the receiver **cannot check sideways**. A sideways check is any confirmation that does not run through the caller. You turn your head and ask the person next to you. You look the name up in an internal directory. You recognise the voice because you have heard it in twenty stand-ups. You walk two floors up. None of these are formal controls, nobody wrote them down, and they are the reason internal impersonation is hard: the claim has to survive checks the caller neither controls nor even knows about. ## Three identities with no sideways check **The outsourced desk.** A supplier runs overnight support for a Linux server fleet. The rota rotates, staff turn over, and the receiver has never met anyone on it. There is no internal directory entry, no colleague who would recognise the name, and no in-person option at 03:00. Critically, *unfamiliarity is the baseline* — the receiver's usual instinct, "I don't know this person", carries zero information here because they do not know any of them. **The unreachable executive.** Travelling, in back-to-back meetings, on another continent. The sideways path exists on paper — an assistant, a colleague — but the pretext supplies a reason not to use it, usually confidentiality or time, and the receiver is often junior enough that walking into that office was never a real option anyway. **The supplier's accounts contact.** The relationship is real and the company is real; only the person is borrowed. The receiver deals with an organisation, not a face, and has no way to enumerate who works in its finance team. In each case the identity's *non-availability is normal*. That is the whole trick. An impersonation that requires a strange story to explain why you cannot verify it is fragile; an impersonation where verification was never available in the first place needs no story at all. ## The closing move: every path leads back to the caller Once the identity is chosen, the pretext is arranged so that any attempt to confirm it is satisfied *by the caller*. The number to call back on is read out on the call. The supplier contact to check with is named by the caller. The email thread that establishes context was started by the caller. This is what makes the whole class of "just verify them" advice hollow unless the verification path is one the receiver already held. ## Why this is worth knowing at all It predicts where the exposure is. Draw the boundary of your organisation and look at every party across it who can telephone or email someone here and be believed: suppliers, contractors, outsourced desks, managed providers, auditors, recruiters, couriers. Everyone across that line is an identity nobody inside can place, and the ones who contact you routinely are the ones whose contact will not surprise anybody. It also reframes what you should be suspicious of. The receiver cannot usefully be suspicious of the *person*, because the identity was chosen so that suspicion has nothing to attach to. What can still be unusual is the **request**: an ask that desk has never made before, an action outside what the contract covers, a first-ever change to where something is sent. Structure sits in the request, not in the caller. ## The counter-property If the attack depends on the absence of a path that does not run through the caller, the control class that removes it is a path that does not run through the caller — an address of record you already hold, a person on the supplier side you had a relationship with before this call, an attribute in a system the caller cannot influence. The rest of this area is about what such a path must satisfy to survive a caller who has done their homework, and about the two signals people wrongly treat as such a path: the number that appeared on the call, and the voice on the other end.

  • The receiver has never met anyone on that desk, so what would even count as unfamiliar here?
    Nothing about the person. Unfamiliarity is the baseline for a rotating third-party rota, which is why the identity was chosen. What can still be unusual is the request: a shape of ask that desk has never made, an action outside what the contract covers, or a first-ever change to where something is sent. That is a property of the ask, not of the caller.
  • Does this reasoning hold when the impersonated party is a senior executive rather than a supplier?
    Yes, for the same structural reason. An executive who is travelling or in back-to-back meetings is unreachable by design, and a junior receiver was never going to walk into their office to check. A sideways path exists on paper through an assistant or a peer, but the pretext supplies a reason not to use it, usually confidentiality or time pressure.

A stranger claiming to be the new night porter is far harder to challenge than one claiming to be your team lead: nobody on the night shift knows each other's faces, and that is exactly why the uniform gets borrowed.

saying these in an interview costs you the question

  • Says the caller always picks whoever has the most authority
  • Assumes an unfamiliar name on a supplier rota is itself suspicious
  • Thinks a convincing manner is what carries the pretext
  • Believes impersonating an internal colleague is equally easy
  • Advises 'just verify the caller' without asking through what path

context

open as a page

Why is a phishing request the recipient already performs weekly harder to refuse than an urgent one?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Because the recipient has no decision to make. A routine ask matches what they already do, so it runs on habit rather than judgment, while urgency and authority are exactly the pressure cues people are taught to notice and question.

open as a page

Why does an incoming call showing your company's own number prove nothing about the caller?

level: middleimportance: must knowfreq 64%

basics

~20 s

Calling-line identity is supplied by the originating side and relayed onward; nothing in a normal call path proves the caller is entitled to the number shown. The displayed name is usually just a lookup on that asserted number.

open as a page

Across bulk, spear and executive phishing lures, which rung pays most per operator hour?

level: middleimportance: must knowfreq 62%

basics

~20 s

Usually the middle rung. Spear reuses one block of organisation-level research across dozens of named recipients, so success per recipient rises steeply while hours per recipient stay small. Bulk yields commodity accounts; executive stakes a week on one attempt.

open as a page

We train staff to check sender domains and spot bad grammar — what does that actually catch?

level: seniorimportance: must knowfreq 50%

basics

~20 s

Only the cheapest rung. Both tells are artefacts of lures the operator paid nothing for, and both vanish once the message is sent from a real mailbox on a real domain, where prose and address are genuine.

open as a page

Which company-published facts make a phishing lure credible at zero research cost?

level: juniorimportance: should knowfreq 50%

basics

~10 s

The organisation's own published surface: job adverts naming internal systems and approval chains, certificate transparency and DNS entries naming hostnames, regulatory filings naming who signs, and conference bios naming who reports to whom.

open as a page

A 40-second webinar clip clones your CTO's voice on a call - what has actually changed?

level: middleimportance: should knowfreq 47%

basics

~10 s

The price, not the possibility. Voice was never an authenticator; it was a familiarity cue that used to be expensive to fake for a named person. Cheap cloning makes anyone with public audio impersonable.

open as a page

How does a hijacked email reply chain make a lure indistinguishable from a real thread?

level: middleimportance: should knowfreq 55%

basics

~20 s

The operator has a foothold in a third party's mailbox and replies to a conversation the recipient started. The threading fields, the quoted history and the sender are all genuine, so nothing is fabricated for the recipient to notice.

open as a page

What verification survives a caller who has the right voice, the right number and weeks of rapport?

level: seniorimportance: should knowfreq 42%

basics

~20 s

Only a check that consumes a fact the caller did not supply and cannot influence, reached over a path they did not choose. Shared knowledge fails - weeks of friendly contact is how that history was manufactured.

open as a page

How do you price the claim that serious attackers write a bespoke phishing lure per person?

level: seniorimportance: should knowfreq 45%

basics

~10 s

In operator hours the claim is cheap: forty recipients at two hours each is roughly two operator-weeks, and much of that reading is shared across all forty. Tailoring prices the message, not the sender.

open as a page

Your outsourced 24x7 desk has a 15-minute response SLA - which caller requests get an identity gate?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

Gate by the consequence of the action, not by suspicion about the caller. Then make it stick: carve verification time out of the SLA clock, agree the identity path in the contract, and let the desk delay anyone.

open as a page

A supplier's mailbox was hijacked to send real-thread requests — which requests get out-of-band confirmation?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

Scope by consequence, not by tone. Confirm requests that are irreversible or change a standing arrangement, keep the volume low enough that the step stays a real check, and use contact details you already hold.

open as a page

HR's job adverts name your internal tools. What do you ask them to change, and what does it buy?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Ask only for details with high lure value and low hiring value: internal system names and approval chains. It buys an operator an hour or two, not immunity, since filings and certificate transparency entries cannot be withdrawn.

open as a page