Your accounts manager receives a Teams meeting invite from what looks like a supplier. The page shows other participants already waiting. A prompt appears: "Install required update to join." Thirty seconds later, attackers have remote access to your network.
This exact situation is playing out across Australian businesses right now. Security researchers at Netskope recently found a phishing campaign using fake video conference invitations for Zoom, Microsoft Teams and Google Meet. The fake pages look almost identical to the real thing, complete with fake participants appearing to join the call in real time. The "software update" victims download is remote access software that gives attackers full control of the computer.
There is a simple way for your team to spot these fakes with a checklist. Automated phishing tests can train staff to apply these checks naturally, without you needing to run training sessions yourself.
Reasons video call phishing is effective
Video conferencing has become second nature for most office workers. We click meeting links dozens of times per week without much thought. Attackers know this.
The pressure to join a meeting on time creates urgency. Nobody wants to be the person holding up a call while they check whether a link is legitimate. Research on phishing behaviour shows that interruptions during tasks increase the likelihood of employees falling for scams. A meeting invite that arrives when someone is already busy creates exactly this kind of pressure.
The fake pages in this campaign include clever touches. Animated avatars of "participants" appear to be waiting. Countdown timers suggest the meeting is about to start. These details make people rush through security checks they might otherwise perform.
The 5-Point Video Call Safety Checklist
Print this checklist and stick it near your team's workstations. It takes less than 30 seconds to run through before clicking any meeting link.
1. Check the Sender's Email Address
Look at the actual email address, not just the display name. Attackers often use display names like "Zoom Meeting" or "Microsoft Teams" while the actual sending address is something like "[email protected]" or "[email protected]".
Legitimate meeting invites come from domains you recognise: your colleagues' work emails, or official domains like zoom.us, zoom.com, teams.microsoft.com, or meet.google.com.
2. Hover Before You Click
On a computer, hover your mouse over any link without clicking. A small preview shows where the link actually goes. On a phone, press and hold the link to see the destination.
Real Zoom links go to zoom.us or zoom.com. Real Teams links go to teams.microsoft.com. Real Google Meet links go to meet.google.com. Anything else, like "zoom-meeting-join.com" or "teams-conference.net", is a fake.
3. Question Unexpected Software Prompts
This is the big one. Legitimate video conferencing platforms almost never require you to install updates at the moment you're joining a call. If you see a prompt to download or install anything, stop.
Zoom, Teams and Google Meet all update through their normal application processes or app stores. A required update that appears only when joining a specific meeting is a red flag.
4. Verify Through a Second Channel
If a meeting invite seems unusual (unexpected sender, strange timing, unfamiliar topic), verify it separately. Call the person who supposedly sent it. Send them a message through a different platform. Check your calendar for the original invitation.
This takes an extra minute but can prevent a breach that costs your business thousands in recovery and lost productivity.
5. Report Suspicious Invites
Create a simple process for staff to report dodgy meeting invites. This could be as straightforward as forwarding them to a designated email address or dropping a message in a Slack channel.
When one person spots a fake, warning others can prevent multiple people falling for the same campaign. Attackers often target several people in the same organisation simultaneously.
Why Automated Phishing Tests Make This Stick
Reading a checklist is one thing. Applying it under pressure when a "meeting" is about to start is another.
This is where employee cyber training through fake attacks becomes valuable. When your team receives realistic fake meeting invites as part of automated phishing tests, they practise spotting the warning signs in conditions that feel real. The stakes are low (it's a test), but the learning sticks because it happens in context.
The Australian Cyber Security Centre (ACSC) reports that business email compromise remains a significant threat to Australian companies. For small businesses, AI-powered phishing tests offer a practical way to build resilience without hiring security specialists.
Platforms like Phishing Training Australia send fake attacks automatically. The system researches your business to create relevant examples, sends fake meeting invites (and other phishing attempts) on a schedule you choose, and automatically assigns training to anyone who clicks. You set it up once and it runs without ongoing effort from you.
Putting the Checklist Into Practice
Here's how to roll this out across your team:
- Share the checklist at your next team meeting. Spend five minutes walking through each point with a real example.
- Print physical copies for desks. A visible reminder helps when people are rushing.
- Set up automated testing to reinforce the training. Staff who fail fake attacks get immediate feedback explaining what they missed.
- Review results monthly to see which team members need extra support and whether your overall click rates are improving.
The combination of clear guidelines and regular practice creates habits that hold up under pressure. Your team stops relying on conscious thought ("Is this link safe?") and starts responding naturally ("I always check the sender address before clicking").
What Happens If Someone Clicks Anyway
Even with training, mistakes happen. Have a simple incident response plan ready:
- Disconnect the affected computer from your network (unplug the ethernet cable or turn off WiFi).
- Contact your IT support or managed service provider immediately.
- Change passwords for any accounts accessed on that computer.
- Check for unusual activity in your business systems over the following days.
If you work with an MSP, they should have procedures for this. If you handle IT yourself, consider documenting these steps and keeping them accessible to all staff.
Professional services firms handling client data face particular obligations here. Accounting firms are now primary targets for email compromise attacks, and a breach involving client information triggers mandatory notification requirements under the Privacy Act and the Notifiable Data Breaches (NDB) scheme. The ACSC recommends that all Australian businesses have a clear response plan in place to mitigate these risks.
Building a Security-Aware Team
The fake video call campaign found by Netskope is one of many tactics attackers use. Your team will encounter fake invoice requests, password reset scams, and messages pretending to be from the ATO or your bank. The same principles apply: check the sender, hover before clicking, question unexpected requests, verify through separate channels, and report anything suspicious.
Regular employee cyber training through automated tests builds these instincts across your whole team. New staff get tested from their first week. Everyone receives ongoing practice that adjusts to their skill level. You get reports showing your organisation's security posture improving over time, useful for compliance documentation and client assurance.
If you want to see how your team would respond to a fake video call invite right now, sign up for a free trial and send yourself a test email. You'll experience exactly what your employees would see, and get a sense of whether your current training is working.