Social Engineering & FraudMANIPULATIVE

Vishing (Voice Phishing)

What it is

A phone call, often with a spoofed caller ID, in which the caller impersonates a bank, government agency, help desk, or vendor to extract information, credentials, or payments in real time.

How it works

A phone call denies the target the two things that protect them in email: time and a written record to inspect. The caller controls the pacing, fills silences, answers objections instantly, and can escalate emotion in a way text cannot. Spoofed caller ID supplies borrowed authority (the bank's real number on the screen), and a rehearsed script anticipates the target's doubts, sometimes inviting the target to "verify" by calling back a number the caller supplies. Vishing is also how attackers reach corporate systems: a help-desk agent or a new hire is talked through an MFA reset or a password change by someone who already knows their manager's name and employee number. The FTC's data consistently show that fraud initiated by phone produces the highest per-person losses of any contact method, particularly for older adults, and the FBI's 2023 elder-fraud report lists tech-support and government-impersonation calls among the top complaint types for people over 60.

Real-world examples

  • Twitter's July 2020 breach began with what the company itself called a "phone spear phishing attack" on employees, leading to the hijacking of accounts belonging to Barack Obama, Elon Musk, and Apple to run a bitcoin scam.
  • In September 2023 MGM Resorts suffered a multi-day outage after attackers called its IT help desk posing as an employee found on LinkedIn and talked their way into a credential reset.
  • The "bank fraud department" call: a spoofed number, a claim that suspicious charges were detected, and a request to "move your money to a safe account" that belongs to the caller; the FTC found bank impersonation the most-reported text and call scam of 2022.
  • One-time-passcode relay: the caller asks the victim to read out the six-digit code the bank just texted "to confirm your identity"; the code was triggered by the caller logging in with the victim's stolen password.

Ethical guidelines

  • Impersonating an institution by phone to obtain money or access is fraud; it has no legitimate use.
  • Authorized voice tests against an organization's help desk require executive sign-off, must not impersonate real named employees without their consent, and must end in training rather than blame.
  • Legitimate institutions should never ask customers to read back one-time codes or to move money "to protect it", and should say so on every statement so the script becomes recognizable.

How to defend against it

  • Hang up and call back on the number printed on your card, your statement, or the official website you typed yourself; never on a number the caller gives you.
  • Never read a one-time passcode to anyone on a call. Banks send codes so you can log in; a caller asking for one is logging in as you.
  • No legitimate bank, agency, or company will ask you to move money to a "safe" account, buy gift cards, or install remote-access software; each of these ends the call.
  • Caller ID is not identification. Spoofing is trivial, and the STIR/SHAKEN framework reduces but does not eliminate it; treat the displayed number as decoration.
  • Help desks should require a callback to a number of record or an in-person check before resetting passwords or MFA, and should log every reset request.

From the Defense Playbook

Out-of-Band Verificationminutes

Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.

The Callback Ruleminutes

When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.

Never Pay (or Move Money) to Protect Moneyseconds

No bank, agency, or company will ever ask you to move, withdraw, convert, or hand over your money to keep it safe, so any such request identifies the person making it as the threat.

Gift Cards Mean Scamseconds

Treat any demand to pay a debt, fine, fee, bail, or "security deposit" with gift cards, cryptocurrency, a wire to a stranger, a payment app, or cash handed to a courier as proof of fraud, because no legitimate institution collects money that way.

Verify, Then Trust (for Authority Claims)minutes

Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.

Multi-Factor Authentication and Passkeysminutes

Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. Wiley
    Extended case studies of telephone social engineering against help desks, receptionists, and employees.
  2. Federal Trade Commission (2024). Consumer Sentinel Network Data Book 2023. Federal Trade Commission · link
    Phone calls carry the highest median per-person loss of any fraud contact method; imposter scams as the most-reported category.
  3. Federal Bureau of Investigation, Internet Crime Complaint Center (2024). 2023 IC3 Elder Fraud Report. FBI IC3 · link
    Tech-support fraud as the most-reported crime type among complainants over 60, with losses for that age group above 3.4 billion dollars.
  4. Twitter, Inc. (2020). An update on our security incident. Twitter company blog · link
    Company statement that the July 2020 breach began with a phone spear-phishing attack on employees.
Last reviewed
Suggest a correction

Detect Vishing (Voice Phishing) in any text

Paste any message, email, or article into our free Manipulation Detector to see if Vishing (Voice Phishing) or other techniques are being used on you.

Related Articles