Human Verification Under Pressure

Use independent verification and consequence-based decisions to resist urgent requests across email, chat, voice, video, and QR codes.

Pressure changes tempo, not truth

Urgency, authority, familiarity, scarcity, and fear can narrow attention. Treat pressure as a signal to slow the decision, not as proof that the request is false. A short pause creates room to identify what the requester needs you to do.

Name the requested action in plain language: send money, reveal a code, install software, approve a prompt, change a recovery address, or keep the request secret. This separates consequence from the story wrapped around it. A genuine colleague can wait while a high-impact request follows policy. Use a prepared phrase such as, “I cannot approve this in this channel; I will verify it through our normal process,” so the response does not depend on inventing words under pressure.

Classify the requested consequence

Classify the consequence before judging appearance. Money movement, credential entry, sensitive disclosure, software execution, account recovery, and security-control changes deserve stronger verification than a routine low-impact request.

Match the check to the possible loss. A meeting-time change may need little friction; a supplier bank change may require a callback to a number already on file and a second approver. Credential and MFA requests should never be satisfied for an unsolicited contact. For data release, confirm the recipient, purpose, minimum fields, approved channel, and authority. Urgency can change which escalation route is used, but it should not remove the control.

Leave the attacker-controlled channel

Do not verify a message by replying to it, calling a supplied number, or following its QR code. Find the person or organization through a known directory, established application, bookmarked site, or previously verified contact route.

Changing devices is not enough if the trust source stays the same. Scanning a QR code with a phone still follows the sender’s route; calling the number in an email still trusts the email. Leave the interaction, retrieve contact details independently, and initiate a new conversation. If the request claims to reference a ticket, payment, or alert, open the official system yourself and locate the record rather than accepting a screenshot or reference number as proof.

Use a genuinely independent route

An independent path must not inherit the same attacker-controlled information. Confirm both identity and the exact request, especially for payment changes, recovery actions, privileged access, and unusual secrecy. Realistic audio or video is not identity proof.

Ask the verified person to restate the consequential action: “Did you request that invoice 742 be paid to this new account?” A vague “did you contact me?” can confirm an unrelated conversation. For voice or video impersonation, end the call and use a known number, internal directory, or second authorized person. Secret phrases help only when established privately and protected; documented business workflows and dual approval are more durable for teams.

Report early without blame

Report suspicious contact and accidental interaction promptly. Preserve the message, channel, time, requested action, and any data entered. Teams learn faster when reporting is safe and blame-free. Similar discipline applies when AI-assisted CTI introduces persuasive but unverified material.

If interaction occurred, report the facts without self-investigation: which link opened, which credentials or codes were entered, which file ran, and which approval was given. Use another trusted device if the original may be compromised. Managers should reward early reporting, provide a clear route, and avoid public blame; delay often creates more harm than the initial mistake. Review the workflow afterward to make the safe path easier, faster, and recognizable next time.