Most of us have learned to be suspicious of email. So the people who write phishing have moved: to text messages, QR codes, voice calls and collaboration tools. The tricks are the same — urgency, familiarity, a link — but they arrive where your guard is down.
The current favourites
- Text messages about a parcel, a toll, a bank alert. Short, plausible, with a link that opens a convincing login page.
- QR codes in emails, on posters, even stuck over the real ones on parking meters. A QR code is just a link you cannot read.
- Phone calls from "IT support" asking you to install a "tool" or read out a code from your phone. Your real IT provider knows your name, your company and your ticket history, and will never ask for an MFA code.
- Teams and chat messages from an external "colleague" with a shared file.
- MFA fatigue — repeated approval prompts until someone taps "approve" to make them stop. If you did not just sign in, the answer is always deny, and then call us.
The same three-second rules apply
Were you expecting it? Is it in a hurry? Where does the link really go? And the move that beats all of them: go in the front door — open the app or website yourself rather than following anything you were sent.
A note on the "IT" call
Spicsoft engineers do call customers. Here is how you know it is us: we will already know who you are, we will reference a ticket or a conversation you recognise, and we will never ask for a password or an MFA code. If in doubt, hang up and call the support line you already have. We will not be offended — we would rather you checked.

