Vishing
Voice phishing conducted over phone calls where attackers impersonate trusted entities to extract sensitive information from victims.
Vishing, short for voice phishing, is a social engineering attack conducted over the telephone. Attackers call victims while impersonating trusted organizations — such as banks, government agencies, tech support teams, or even colleagues — to manipulate them into revealing confidential information, transferring funds, or granting remote access to their devices. The real-time, personal nature of a phone call adds a psychological pressure that written phishing lacks.
Modern vishing attacks have grown increasingly sophisticated with the advent of Voice over IP (VoIP) technology and caller ID spoofing. Attackers can make calls appear to originate from legitimate phone numbers, including those of real banks or government offices. Some advanced campaigns use AI-generated voice cloning to impersonate specific individuals, making the deception nearly impossible to detect by ear alone. Automated robocall systems allow vishers to reach thousands of potential victims per day at minimal cost.
Vishing is particularly effective against populations less familiar with digital threats, including the elderly, but even security-conscious professionals can be caught off guard. Business vishing campaigns — sometimes called voice-based BEC — target employees by impersonating IT departments or executives. Defending against vishing requires awareness training that extends beyond email, strict verification policies for phone-based requests, and technical solutions like call authentication protocols (STIR/SHAKEN).
Modern vishing attacks have grown increasingly sophisticated with the advent of Voice over IP (VoIP) technology and caller ID spoofing. Attackers can make calls appear to originate from legitimate phone numbers, including those of real banks or government offices. Some advanced campaigns use AI-generated voice cloning to impersonate specific individuals, making the deception nearly impossible to detect by ear alone. Automated robocall systems allow vishers to reach thousands of potential victims per day at minimal cost.
Vishing is particularly effective against populations less familiar with digital threats, including the elderly, but even security-conscious professionals can be caught off guard. Business vishing campaigns — sometimes called voice-based BEC — target employees by impersonating IT departments or executives. Defending against vishing requires awareness training that extends beyond email, strict verification policies for phone-based requests, and technical solutions like call authentication protocols (STIR/SHAKEN).
Examples
- A caller pretending to be from the IRS threatening legal action unless immediate payment is made via gift cards.
- A fake bank representative calling about suspicious activity and asking the victim to confirm their account number and PIN.
- An attacker impersonating IT support requesting remote access to an employee's workstation to fix a fabricated issue.
Prevention
- Never provide sensitive information over inbound calls; hang up and call the organization back using an official number.
- Train employees to verify the identity of callers before sharing any internal or personal information.
- Implement call authentication standards to reduce caller ID spoofing.
- Establish clear policies that IT and management will never request passwords or sensitive data over the phone.