Skip to content

Vishing

Vishing is voice-mediated social engineering conducted through phone calls, voicemail, voice messages, or voice notes. The attacker uses live or recorded voice contact to obtain information, secure approval, influence an action, or bypass an established process.

Voice interaction creates immediacy and social pressure. During live calls, attackers can alter tone, pace, and explanation in response to hesitation or resistance. Claimed authority, caller ID, technical language, or personal context may reinforce legitimacy.

Vishing may operate as a standalone interaction or one stage in a wider social engineering approach. An earlier email or message can establish context before a call, while the voice interaction applies pressure at the decision point.

Vishing appears through direct calls, call-back requests, voicemails, voice notes, contact centre interactions, and follow-up calls linked to earlier messages.

Common scenarios include:

  • support impersonation involving identity verification or account access
  • requests for MFA codes, recovery details, or remote session information
  • finance or supplier calls seeking payment or account changes
  • executive impersonation tied to an urgent approval
  • fake support interactions involving software installation or remote access
  • calls that gather internal details from reception, helpdesk, or customer service functions
  • voice contact used to reinforce a phishing, smishing, or business email compromise attempt

Callback phishing, sometimes described as reverse vishing or telephone-oriented attack delivery (TOAD), reverses the usual direction of voice contact by prompting the target to call a number supplied in an email, message, or document. Common lures include fake invoices, subscription renewals, and fraud alerts. These messages often contain no malicious URL or executable payload, which can reduce the effectiveness of controls focused on detecting malicious links or attachments. Once connected, the attacker may direct the caller towards remote access, payment, credential disclosure, or a secondary website or application.

Real-time conversation gives the attacker control over the pace and sequence of the request. Six elements recur across these interactions:

ElementWhat it meansExamples
Claimed callerThe person, function, organisation, or authority the caller claims to represent.IT support, bank, supplier, executive, government agency, courier, helpdesk, security team.
Call reasonThe explanation given for the contact.Account issue, suspicious activity, payment problem, support case, delivery issue, urgent approval.
Requested actionThe action sought during or after the interaction.Share information, approve access, install software, reset an account, transfer money, call another number.
Pressure tacticThe manipulation used to accelerate action or suppress scrutiny.Urgency, fear, technical language, claimed authority.
Verification gapThe missing or bypassed step that would establish whether the caller is genuine.No callback, no ticket, no known number, no internal confirmation, no official support record.
Follow-on pathThe channel, service, or action into which the target is moved next.Remote session, website, payment page, app download, MFA prompt, different phone number, messaging app.

Vishing indicators often arise from the relationship between the caller’s claimed identity, the request, and the verification path available during the interaction.

IndicatorWhat to look for
Unexpected or contextless callContact involving support, payments, account recovery, access, legal matters, or sensitive information occurs without an established reason or known preceding event.
Urgency or panicThe caller presents immediate financial loss, account compromise, service interruption, or another consequence that discourages delay.
Process bypassNormal verification, approval, finance, helpdesk, HR, legal, or security processes are framed as unnecessary or obstructive.
Code or credential requestPasswords, MFA codes, one-time passwords, recovery codes, remote session codes, or account verification details are requested verbally.
Remote access requestThe caller seeks software installation, screen sharing, device control, a remote support session, or security-setting changes.
Independent verification resistedCallback through an official number, internal confirmation, or another trusted verification path is refused or discouraged.
Caller ID used as identity proofA displayed phone number, organisation name, or claimed department is presented as sufficient evidence of identity.
Message prompting an unsolicited callAn email, invoice, or alert with no link or attachment to act on instead urges the recipient to ring a number to dispute a charge, renewal, or security problem.
Information harvestingQuestions progressively gather internal names, roles, schedules, suppliers, systems, ticket references, customer details, or account information.
Channel shiftThe interaction moves to an unfamiliar website, different number, messaging platform, QR code, or support path supplied by the caller.