MODULE 19🔊0:00SAFETY  50
AI Safety 101 by Mandrify

The Help Desk Call

IT is on the line. So is the attacker. The new account belongs to the attacker.

15 minutes. Three decisions under pressure, a red-flag sort, and a verification drill you can use the same day.

Before you start

  • One real attack pattern, played as decisions - no slides, no lectures.
  • You make timed choices; your score changes with your decisions.
  • You get a safety score with feedback on every decision - never a leaderboard, never your name.
  • Your firm sees completion evidence - never your answers. Teammates never see your score.
  • Finish and you get a certificate with a unique ID anyone can verify.

Free for everyone. All drills are free - finish and you get a verifiable certificate.

Why this module exists - the helpful call is the attack

About $100 million lost. It started with a phone call to the help desk.

~$100M
Impact MGM Resorts disclosed from its September 2023 cyberattack. Investigators and reporting tied the initial access to vishing - attackers calling the help desk, armed with employee details gathered from public research.
~$15M
Ransom Caesars Entertainment reportedly paid weeks earlier after attackers socially engineered an outside IT-support vendor (Wall Street Journal reporting, September 2023).

The caller sounds like support. They know your name, your title, maybe your manager. They have a ticket number and a deadline. None of that is proof - all of it is research.

The one thing they cannot get from research is the code on your phone. So the whole call is built to make you read it out loud. Never read a code or password to someone who called you.

The muscle memory: You never read a code or password to anyone. Hang up, call back on the number you already trust, and report the attempt the same day.

Sources: MGM Resorts Q3 2023 results disclosure (Oct 2023); Wall Street Journal reporting on Caesars Entertainment (Sep 2023); CISA guidance on vishing and social engineering.
Dramatized scenario - built from documented attack patterns

Thursday, 4:42 PM. Your phone rings. Caller ID: Brightpath IT.

You are Alex Morgan, client service associate at Harbor Point Advisors, a 40-person RIA. Your firm outsources IT to Brightpath Managed Services. Quarter-end reporting is due tomorrow.

INCOMING CALL - BRIGHTPATH IT4:42 PM
"Hi Alex, this is Dre from Brightpath support - ticket 88412. We're seeing a sign-in to your account from out of state, and we've blocked it for now.

I've got you as Alex Morgan, client service, extension 214 - is that right? Good. I need to verify it's really you before I can clear the block.

You should have a six-digit code on your phone right now. Read it to me and I'll confirm your identity.

If we can't verify in the next few minutes, policy says I have to lock the account - and with quarter-end tomorrow, I don't want that for you."

A text with a six-digit code did just arrive. The caller knows your name, role, and extension. Caller ID says Brightpath. All of that is public or spoofable.

Simulated scenario. Harbor Point and Brightpath are fictional.
Decision 1 of 3 - the verification ask

4:42 PM. The caller wants the code. You have 20 seconds.

Decision 2 of 3 - the pressure callback

You hung up and called the real Brightpath desk. They have no ticket 88412 and no Dre on staff. While you're on the line, the first caller rings again: "I see the account is still unverified. It locks in five minutes, and lockouts get reported to your compliance officer."

Decision 3 of 3 - the code is already out

Friday, 4:50 PM. Your teammate Priya mentions she got the same call an hour ago: "I read them the code - they knew my extension, it seemed fine. Should I do anything?" The weekend is ten minutes away.

The rule that matters

Never read a code or password to anyone who calls you.

The caller can know your name, your extension, your manager, your IT vendor's name. Caller ID can say anything. The code on your phone is the one thing they cannot research - it is the login. Whoever holds it, holds the account.

Never read a code or password to anyone who called you.

Hang up. Call back on the number you already trust. Report the attempt the same day. If a code got shared, it is an incident now - resets and session revocation, not a password change on Monday.

Red-flag sort - what actually proves safety?

Sort each card.

1 / 10
The control sequence - 5 lines

Complete each line of the rule.

1 / 5
Verification sprint - choose the trusted path

Pick the safest verification path.

1 / 6
Knowledge check - 5 questions
Module complete

0

Decisions-
Red-flag sort-
Control sequence-
Verification sprint-
Knowledge check-
AI Safety 101 by Mandrify - Official Certificate
AIS
101

This certifies that

has completed Module 20 - The Help Desk Call: never speak the code on with a safety score of /100 in of active time.

Safety score - vishing resistance: how your decisions held up, graded 0-100.

Objective: Identify voice phishing (vishing), refuse to share codes or passwords on any call, verify by calling back on known numbers, contain shared-code incidents fast, and report attempts the same day.

Seat time ~15-18 minutes. Verify this certificate at aisafety101.com/verify.

Evidence on record: module completion, seat time, final score, and certificate ID. This certificate ID verifies in your firm's admin report.

The safest move is the one you initiate. Hang up, call the number you already trust, and report the attempt the same day.