What is Vishing?
Vishing is a social engineering attack that uses phone calls or voicemails to trick people into revealing sensitive information, transferring money, or granting system access. Attackers impersonate trusted figures such as IT support, bank staff, or executives, and increasingly use AI-generated voices to sound convincing.
What it is
Vishing stands for "voice phishing." An attacker calls a target directly, or leaves a voicemail, and pretends to be someone trustworthy. Common impersonations include:
- IT helpdesk staff asking to "verify" credentials
- Bank fraud teams warning of suspicious transactions
- Government agencies threatening legal action
- Executives requesting urgent wire transfers (a variant called CEO fraud or BEC)
Modern vishing campaigns use AI voice cloning to mimic real people. A short audio sample from a public video or voicemail is enough to generate a convincing fake voice. This lowers the skill barrier for attackers and raises the believability of the call.
Vishing is often combined with other techniques. An attacker may send a phishing email first, then call to "confirm" it. This multi-channel approach is sometimes called hybrid phishing or telephone-oriented attack delivery (TOAD).
Why it matters
Voice carries social pressure that email does not. People find it harder to say no to a live caller, especially one who sounds authoritative or urgent. A single successful vishing call can result in credential theft, fraudulent wire transfers, or unauthorized VPN access. Losses from business email compromise and related voice fraud run into billions of dollars annually across reported cases.
Remote and hybrid work has made vishing easier. Employees cannot walk down the hall to verify a caller's identity, and IT helpdesk calls are routine.
How tools address it
No tool blocks a phone call the way a spam filter blocks email. The primary defense is trained human judgment. Phishing simulation platforms, such as those in the Phishing Simulation category, increasingly include vishing scenarios alongside email tests. Some platforms use multi-channel simulations that include voice calls or voicemail drops to measure how employees respond. Security Awareness Training programs teach staff to recognize pressure tactics, verify caller identity through a separate channel, and report suspicious calls. Human Risk Management platforms track which employees fall for simulated vishing attempts and assign targeted follow-up training.