My friend Jenni got a strange text one afternoon claiming her bank account had been frozen. Worried, he called the number in the message without thinking twice.
A calm voice on the line insisted they were from “bank security” and needed her login details to verify her identity. Jenni hesitated, but the caller sounded official enough to convince her. Minutes after sharing the information, she received alerts of withdrawals she didn’t recognize. Her heart dropped as she realized he’d been tricked.
She rushed to her real bank’s hotline, hoping it wasn’t too late. After hours of calls and frantic password resets, the bank managed to stop most of the transfers.
Jenni later admitted she never thought she would fall for something like that.
Now, anytime she gets a suspicious text, she calls me first!
What allowed the above to take place? Scams and social engineering attacks have evolved far beyond emails, texts and fake phone calls. As organizations embrace cloud platforms, AI tools and remote collaboration, their asset perimeters have expanded dramatically. These asset perimeters can be defined as the boundaries that protect valuable data, systems and intellectual property. The expansion of these boundaries has created new opportunities for cybercriminals to exploit weak points and human vulnerabilities.
Through the lens of defining scam-based attacks, one can view the attacks in four categories.
- Phishing and Smishing attacks where a fraudulent message designed to trick users into sharing credentials or installing malware.
- Business Email Compromise (BEC) attacks which impersonates executives or vendors to authorize fake wire transfers or data requests.
- AI-driven impersonation scams such as deepfakes and AI-generated messages that convincingly mimic trusted sources.
- Insider-Targeted Manipulation where attackers exploit employees’ trust or fatigue to gain unauthorized access.
In a mediated environment, where interactions often occur through digital systems rather than face-to-face , these attacks can blend seamlessly into legitimate workflows, making detection difficult.

To defend effectively, organizations must adopt a layered and adaptive security posture.
- Adopt a Zero-Trust Framework: That means that no user or device, inside or outside your network, is automatically trustworthy. Implement continuous authentication, least-privilege access and behavioral monitoring to verify every interaction.
- Enable your teams. Human error remains the top vector for scams. Regular training on how to identify suspicious requests, verify sender authenticity and report incidents can drastically reduce exposure. Simulated exercises help keep awareness sharp.
- Use validation tools that cross sectors. For client verifiable data, access systems that track the coloration phone numbers for the customer. Obtain second level verifiable data such as SIM swap data and email/address verification.
Treating scam attacks isn’t just about technology; it’s about culture. Every employee, partner and vendor should understand their role in protecting the organization’s perimeter. By integrating cybersecurity into everyday operations and decision-making, organizations can transform the human factor from a potential vulnerability into their strongest line of defense. In an era where scammers use sophisticated tools and AI-driven tactics, protecting your asset perimeters requires vigilance, education and modern defense technologies. The more interconnected and mediated our business world becomes, the more critical it is to treat security as a shared responsibility.
Let’s protect the Jenni’s of the world!
Jaime Zetterstrom, CFCA Secretary, VP of Product and Innovation, Somos Inc.




0 Comments