GreyFalcon Insight

A Scam Email Can Look Perfect. Check the Request Instead.

AI can remove the spelling and grammar mistakes employees were once taught to recognize. The safer approach is to examine the request and independently verify anything carrying real risk.

A polished email is not proof that the sender is legitimate. Scam messages can now use clean grammar, familiar business language, convincing signatures, and recognizable branding.

The useful question is no longer simply, “Does this email look real?” It is, “What is this email asking me to do?”

Stop and Verify When an Email Requests:

  • A payment, wire transfer, or gift-card purchase
  • New or changed banking information
  • A password, verification code, or other credential
  • Access to sensitive business or customer information
  • Installation of software or remote access
  • An exception to an established approval process
  • Urgent or confidential action

Internal Procedure: Verifying Suspicious Requests

Employees must independently verify any unexpected email request involving money, credentials, sensitive information, software installation, remote access, or a change to an established business procedure.

Verification must be performed through a trusted channel that was not supplied by the questionable message.

Acceptable verification methods include:

  • Calling a previously documented telephone number
  • Contacting the requester through an established Teams account
  • Starting a new email using a known address
  • Opening the service through a saved bookmark
  • Confirming the request directly with a supervisor

Employees must not use telephone numbers, links, or contact information contained in the questionable message to perform the verification.

No change to a vendor’s payment instructions may be accepted solely through email.

When verification cannot be completed, the employee must stop and report the request before taking further action.

If Someone Already Acted on the Message

  • Stop further communication with the sender.
  • Disconnect the affected computer if software was installed or remote access was granted.
  • Contact the designated IT or security provider immediately.
  • Notify management if money or sensitive information was involved.
  • Do not delete the message or related evidence.
  • Change affected credentials from a known-safe device when instructed.

The Rule to Remember

If the request involves money, credentials, sensitive information, or a change in normal procedure, verify it through a second channel.

This procedure can be incorporated into an employee handbook, security-awareness program, Written Information Security Plan, or internal operating procedure. The responsible manager should identify the approved reporting contact and verification channels before distributing it to employees.

For the fuller explanation behind this procedure, read the companion Briefing: The Scam Email Looks Real Now. Here’s What Your Team Should Check Instead.


Supporting guidance: UK National Cyber Security Centre and the FBI Internet Crime Complaint Center.