Vishing
Vishing is voice-mediated social engineering conducted through phone calls, voicemail, voice messages, or voice notes. The attacker uses live or recorded voice contact to obtain information, secure approval, influence an action, or bypass an established process.
Voice interaction creates immediacy and social pressure. During live calls, attackers can alter tone, pace, and explanation in response to hesitation or resistance. Claimed authority, caller ID, technical language, or personal context may reinforce legitimacy.
Vishing may operate as a standalone interaction or one stage in a wider social engineering approach. An earlier email or message can establish context before a call, while the voice interaction applies pressure at the decision point.
How it appears
Section titled “How it appears”Vishing appears through direct calls, call-back requests, voicemails, voice notes, contact centre interactions, and follow-up calls linked to earlier messages.
Common scenarios include:
- support impersonation involving identity verification or account access
- requests for MFA codes, recovery details, or remote session information
- finance or supplier calls seeking payment or account changes
- executive impersonation tied to an urgent approval
- fake support interactions involving software installation or remote access
- calls that gather internal details from reception, helpdesk, or customer service functions
- voice contact used to reinforce a phishing, smishing, or business email compromise attempt
Callback phishing
Section titled “Callback phishing”Callback phishing, sometimes described as reverse vishing or telephone-oriented attack delivery (TOAD), reverses the usual direction of voice contact by prompting the target to call a number supplied in an email, message, or document. Common lures include fake invoices, subscription renewals, and fraud alerts. These messages often contain no malicious URL or executable payload, which can reduce the effectiveness of controls focused on detecting malicious links or attachments. Once connected, the attacker may direct the caller towards remote access, payment, credential disclosure, or a secondary website or application.
Real-time conversation gives the attacker control over the pace and sequence of the request. Six elements recur across these interactions:
| Element | What it means | Examples |
|---|---|---|
| Claimed caller | The person, function, organisation, or authority the caller claims to represent. | IT support, bank, supplier, executive, government agency, courier, helpdesk, security team. |
| Call reason | The explanation given for the contact. | Account issue, suspicious activity, payment problem, support case, delivery issue, urgent approval. |
| Requested action | The action sought during or after the interaction. | Share information, approve access, install software, reset an account, transfer money, call another number. |
| Pressure tactic | The manipulation used to accelerate action or suppress scrutiny. | Urgency, fear, technical language, claimed authority. |
| Verification gap | The missing or bypassed step that would establish whether the caller is genuine. | No callback, no ticket, no known number, no internal confirmation, no official support record. |
| Follow-on path | The channel, service, or action into which the target is moved next. | Remote session, website, payment page, app download, MFA prompt, different phone number, messaging app. |
Indicators
Section titled “Indicators”Vishing indicators often arise from the relationship between the caller’s claimed identity, the request, and the verification path available during the interaction.
| Indicator | What to look for |
|---|---|
| Unexpected or contextless call | Contact involving support, payments, account recovery, access, legal matters, or sensitive information occurs without an established reason or known preceding event. |
| Urgency or panic | The caller presents immediate financial loss, account compromise, service interruption, or another consequence that discourages delay. |
| Process bypass | Normal verification, approval, finance, helpdesk, HR, legal, or security processes are framed as unnecessary or obstructive. |
| Code or credential request | Passwords, MFA codes, one-time passwords, recovery codes, remote session codes, or account verification details are requested verbally. |
| Remote access request | The caller seeks software installation, screen sharing, device control, a remote support session, or security-setting changes. |
| Independent verification resisted | Callback through an official number, internal confirmation, or another trusted verification path is refused or discouraged. |
| Caller ID used as identity proof | A displayed phone number, organisation name, or claimed department is presented as sufficient evidence of identity. |
| Message prompting an unsolicited call | An email, invoice, or alert with no link or attachment to act on instead urges the recipient to ring a number to dispute a charge, renewal, or security problem. |
| Information harvesting | Questions progressively gather internal names, roles, schedules, suppliers, systems, ticket references, customer details, or account information. |
| Channel shift | The interaction moves to an unfamiliar website, different number, messaging platform, QR code, or support path supplied by the caller. |