Phone scams are no longer just random calls from careless fraudsters. Modern social engineering attacks are researched, coordinated, and often connected to criminal ecosystems that specialize in stealing access instead of breaking software. Groups tied to The COM, Lapsus$, and similar networks show how one convincing phone call can lead to stolen credentials, exposed company data, financial loss, and serious trouble for regular users and businesses.
The COM Changed Cybercrime
The COM is best understood as a loose English-speaking cybercriminal ecosystem, not one single gang with a clean command structure. It includes overlapping communities, threat actors, tactics, and services tied to social engineering, SIM swapping, account theft, cryptocurrency theft, extortion, and access brokering. That loose structure is part of what makes it difficult to understand and even harder to stop.
Earlier corners of this ecosystem were often focused on usernames, social media accounts, online status, and stolen digital property. As the money grew, the tactics changed. Criminals realized that access itself could be more valuable than a single hacked account. A compromised email inbox could unlock password resets. A stolen phone number could intercept codes. A tricked employee could create a path into a corporate network.
This shift mirrors a broader cybercrime trend. The World Economic Forum’s Cybercrime Atlas describes cybercrime as an ecosystem involving threat actors, services, infrastructure, and financial networks rather than isolated hackers acting alone. That framing matters because modern attacks often depend on multiple people performing different roles.
One person may collect leaked data. Another may make the phone call. Another may sell credentials. Someone else may handle extortion or cryptocurrency laundering. The victim sees one scam, but the attack may be part of a larger criminal supply chain.
That is why The COM matters. It reflects how cybercrime has become more social, more specialized, and more repeatable.
Crime-as-a-Service Fuels Attacks
Cybercrime now behaves more like an underground service economy than a single technical skill set. Attackers do not always need to build their own tools, find their own victims, or write their own malware. In many cases, they can buy access, rent infrastructure, purchase stolen data, or work with specialists who handle one stage of the attack.
Europol’s report on crime-as-a-service explains how cybercriminal structures have become more professionalized, with services and marketplaces helping different actors carry out attacks at scale. That same businesslike pattern helps explain why social engineering groups can move so quickly.
This does not mean every scam is advanced. Many attacks still begin with a simple phone call, fake support request, or stolen password. The difference is that the simple step may connect to a much larger operation behind the scenes.
A caller may not be the person who found the target. The stolen information used in the call may come from a breach the caller had nothing to do with. The account access may later be sold to another criminal group. That division of labor makes each attack more efficient.
For regular users, this means small mistakes can travel further than expected. Sharing one code, approving one login, or trusting one fake caller can give criminals access that gets reused, resold, or expanded into a larger breach.
Why Vishing Still Works
Vishing, or voice phishing, works because it reaches people in real time. A fraudulent email can sit in an inbox and give the reader time to think. A phone call creates pressure immediately. The caller can react, explain, interrupt, reassure, and push for action before the target has time to verify anything.
CISA’s guidance on social engineering and phishing explains that attackers use human interaction to trick people into revealing information or compromising systems. That is exactly why phone-based scams remain effective. The attacker is not always trying to beat the computer. The attacker is trying to influence the person using it.
The caller may claim to be from IT support, a bank, a phone carrier, a software company, a vendor, or a government office. The tone may be friendly or stern. Sometimes the caller sounds helpful. Sometimes the caller sounds irritated. Either way, the goal is the same: create enough trust or urgency to force a quick decision.
Modern vishing calls can also sound personal. Attackers may reference a real name, job title, email address, employer, phone provider, or recent breach. That information may come from old leaks, public profiles, data broker sites, or previous compromises.
The dangerous part is that some of the details may be true. Accurate details do not make the caller legitimate. They only prove that personal information can be found, bought, stolen, or reused.
Lapsus$ Proved the Risk
Lapsus$ became one of the most visible examples of how damaging social engineering can be. The group and related actors were linked to attacks involving major organizations, stolen credentials, extortion, data leaks, SIM swapping, and help desk manipulation. The attention around Lapsus$ made one point very clear: expensive technology can still fail when identity and access processes are weak.
The Cyber Safety Review Board’s Lapsus$ report found that Lapsus$ and related threat actors used techniques such as social engineering, SIM swapping, credential theft, and weaknesses in identity systems to compromise organizations. The report also highlighted that these attacks were not always technically sophisticated in the traditional sense.
That is the lesson. A breach does not need to begin with advanced malware. It can begin with a person pretending to be someone else.
Help desks are especially attractive targets because they exist to restore access. If identity checks are weak, a criminal can pose as an employee, claim to be locked out, and push for a password reset or MFA change. Once the attacker gets in, the account may look legitimate to security tools because the login uses real credentials.
From there, the attacker may search email, access cloud files, open internal dashboards, join chat systems, or look for more accounts to compromise. One phone call can become a full security incident.
How One Call Opens a Door
Most social engineering phone scams follow a familiar pattern. The caller creates a problem, claims authority, and pushes the target toward a fast action. The exact story changes, but the emotional pressure is usually the same.
The FBI and CISA previously warned about a vishing campaign targeting remote workers in which attackers used phone calls and fake login pages to steal VPN credentials. That warning showed how criminals can combine voice calls, stolen information, and fake websites to make a scam feel believable.
Common pressure tactics include:
- Claiming an account will be locked unless action is taken immediately.
- Pretending to verify suspicious activity that the caller invented.
- Asking for a code “only to confirm identity.”
- Saying a manager, bank, vendor, or IT department already approved the request.
- Warning that delay will cause payroll, service, billing, or data problems.
The goal is to interrupt normal judgment. A rushed person is more likely to comply. A calm person is more likely to pause, hang up, and verify through an official channel.
Once access is stolen, attackers may move quickly. They may create mailbox forwarding rules, add recovery methods, approve new devices, search for invoices, or look for saved passwords. In a business environment, they may move from one account to another until they find sensitive systems.
The call is only the beginning. The real damage happens after the victim opens the door.
Regular Users Feel the Fallout
The COM and similar criminal ecosystems may sound like a corporate security problem, but regular users are often affected. When companies are breached, the stolen information may include names, email addresses, phone numbers, billing details, account history, or support records. That information can later be used to create more convincing scams.
The Federal Trade Commission’s guidance on verification code scams makes the rule clear: anyone asking for an account verification code is trying to get into an account. A code is meant for the account owner, not for a caller, texter, support agent, buyer, seller, or stranger.
This rule stops many scams because verification codes are often the final barrier between a criminal and an account. The scammer may already know the email address. The password may already be stolen. The account recovery flow may already be triggered. The code is what completes the takeover.
No legitimate bank, software company, phone carrier, payment app, or government agency should need a one-time login code read over the phone. If a caller asks for it, the safest move is to end the conversation and verify independently.
The same applies to push notifications from authentication apps. An unexpected login prompt should not be approved just because someone on the phone says it is required.
Strong Habits Beat Pressure
The strongest defense against social engineering is not panic. It is a repeatable routine. Scammers win when each call becomes a fresh emotional decision. They lose when the same safety rules apply every time.
CISA’s Secure Our World campaign emphasizes strong passwords, multifactor authentication, software updates, and phishing awareness as core security behaviors. Those habits are not complicated, but they work because they reduce easy openings.
Practical habits include:
- Never share verification codes, temporary passwords, or MFA prompts.
- Hang up and contact the company through its official website, app, or statement.
- Use unique passwords for important accounts.
- Turn on MFA, preferably through an authenticator app or hardware security key.
- Keep recovery email addresses and phone numbers current.
- Remove old devices and unknown sessions from account settings.
- Treat urgency, fear, secrecy, and pressure as warning signs.
For businesses, the same concept applies at scale. Employees should be allowed to slow down suspicious requests. Help desks should use strong identity verification. Managers should not create a culture where staff feel punished for questioning a strange call.
A good security habit is boring by design. It removes drama from the moment. When the caller demands speed, the routine creates friction.
Device Health Supports Security
Social engineering targets people first, but device health still matters. A cluttered, unstable, or poorly maintained computer can make problems harder to spot and harder to fix. Slow performance, failed updates, strange browser behavior, and leftover files create noise. In that noise, real warning signs are easier to miss.
The National Cyber Security Centre’s phishing guidance recommends layered defenses that reduce the chances and impact of phishing attacks. That layered mindset is important because no single habit or tool can stop every scam. Better protection comes from combining awareness, account security, system updates, backups, and cleaner device maintenance.
A stable system does not stop a scammer from calling. It does help reduce confusion. When a computer behaves predictably, strange activity stands out more clearly. When updates work properly, known security issues are less likely to linger. When unnecessary clutter is removed, troubleshooting becomes easier.
Maintenance should be seen as part of a broader security routine, not a magic shield. Strong passwords, MFA, cautious verification, and updated software still matter most. Clean system habits simply make that routine easier to maintain.
That matters for home users and small businesses because complicated security routines often get ignored. The best routine is the one that can actually be followed.
JENI® Supports Safer Routines
JENI® helps Windows and macOS users keep device maintenance simple, practical, and on demand. It is not a replacement for smart account habits, MFA, strong passwords, backups, or careful verification. It supports the device-health side of a safer routine.
That distinction matters. Social engineering defense starts with the person, but a cleaner and more stable machine can reduce frustration and confusion. A device that runs better is easier to manage. A system with fewer leftover files, broken maintenance tasks, and unnecessary clutter is easier to trust.
JENI® supports safer routines through:
- System cleanup that removes unnecessary files and leftover clutter.
- Native Windows repair support for common maintenance needs.
- macOS maintenance options for everyday system refresh tasks.
- Privacy-conscious operation without unnecessary data harvesting.
- On-demand use without heavy background activity.
This approach fits the reality of modern security. Most people do not need more noise. They need clear habits, fewer distractions, and tools that make upkeep easier to perform.
Privacy also matters because criminals use personal information to make scams believable. A maintenance tool should not add unnecessary data collection to the problem. JENI® is designed to help maintain the device without turning the user into the product.
A safer routine is built from small pieces. Verification codes stay private. Suspicious callers get checked through official channels. Passwords stay unique. MFA stays enabled. Devices stay updated and maintained. JENI® helps with the maintenance part of that routine.
FAQ
What is The COM?
The COM is a loose English-speaking cybercriminal ecosystem connected to social engineering, account theft, SIM swapping, extortion, and related access-based crimes. It is not one traditional gang, but a broader network of actors, tactics, services, and online communities.
How do phone scams steal accounts?
Phone scams often steal accounts by tricking someone into sharing a verification code, approving a login, resetting a password, or installing remote access software. Once access is granted, the attacker may move through email, cloud accounts, financial apps, or company systems.
Why is vishing so dangerous?
Vishing is dangerous because a live caller can create pressure, answer objections, and make a fake request feel legitimate. A convincing voice can exploit trust faster than many people can verify what is happening.
Can MFA stop social engineering?
MFA can stop many account attacks, but it is not perfect if a person is tricked into sharing a code or approving a login. The safest approach is to use MFA while refusing unexpected requests for codes, approvals, password resets, or account changes.
Does JENI® prevent phone scams?
JENI® does not prevent scammers from calling and does not replace careful account behavior. It supports safer daily habits by helping keep Windows and macOS devices cleaner, more stable, and easier to maintain.
Build the Habit Before the Call
Social engineering works because it reaches people during normal moments: while working, paying bills, handling support issues, or reacting to an alert. The attacker does not need unlimited technical skill. A believable story, a little stolen information, and enough pressure can be enough.
The best defense is a habit formed before the call arrives. Codes stay private. Unexpected callers get verified through official channels. Account security stays current. Devices stay maintained. Suspicious pressure gets treated as a warning sign, not a reason to rush.
The COM and similar ecosystems will keep changing because cybercrime rewards adaptation. Phone scams will become more polished. Impersonation will become more personal. Attackers will keep looking for the easiest account, employee, device, or company process to exploit.
A slower response can break the attack chain. A stronger routine can make fraud harder to pull off. A cleaner device can reduce confusion. JENI® supports that daily routine by helping users keep systems maintained without turning security into another source of noise.
Related Articles
Phishing and Malware Warning Signs:
See how phishing and malware tricks steal passwords, spread infections, and pressure users into unsafe clicks before real account damage starts online now fast.
Account Takeover Risks Explained:
Learn how account takeover attacks work, why stolen logins are valuable, and warning signs users should treat as urgent red flags before damage starts now fast.
Dark Web Data Exposure Risks:
Understand how exposed personal data reaches the dark web and why old breaches can make future phone, email, and text scams convincing fast for users worldwide.
Passkeys and Security Keys for Safer Logins:
Compare passkeys, security keys, and stronger login protections that can reduce account takeover risk after phishing or vishing attempts happen online each day.
