Vishing (Voice Phishing)
What it is
A phone call, often with a spoofed caller ID, in which the caller impersonates a bank, government agency, help desk, or vendor to extract information, credentials, or payments in real time.
How it works
Real-world examples
- •Twitter's July 2020 breach began with what the company itself called a "phone spear phishing attack" on employees, leading to the hijacking of accounts belonging to Barack Obama, Elon Musk, and Apple to run a bitcoin scam.
- •In September 2023 MGM Resorts suffered a multi-day outage after attackers called its IT help desk posing as an employee found on LinkedIn and talked their way into a credential reset.
- •The "bank fraud department" call: a spoofed number, a claim that suspicious charges were detected, and a request to "move your money to a safe account" that belongs to the caller; the FTC found bank impersonation the most-reported text and call scam of 2022.
- •One-time-passcode relay: the caller asks the victim to read out the six-digit code the bank just texted "to confirm your identity"; the code was triggered by the caller logging in with the victim's stolen password.
Ethical guidelines
- ●Impersonating an institution by phone to obtain money or access is fraud; it has no legitimate use.
- ●Authorized voice tests against an organization's help desk require executive sign-off, must not impersonate real named employees without their consent, and must end in training rather than blame.
- ●Legitimate institutions should never ask customers to read back one-time codes or to move money "to protect it", and should say so on every statement so the script becomes recognizable.
How to defend against it
- ►Hang up and call back on the number printed on your card, your statement, or the official website you typed yourself; never on a number the caller gives you.
- ►Never read a one-time passcode to anyone on a call. Banks send codes so you can log in; a caller asking for one is logging in as you.
- ►No legitimate bank, agency, or company will ask you to move money to a "safe" account, buy gift cards, or install remote-access software; each of these ends the call.
- ►Caller ID is not identification. Spoofing is trivial, and the STIR/SHAKEN framework reduces but does not eliminate it; treat the displayed number as decoration.
- ►Help desks should require a callback to a number of record or an in-person check before resetting passwords or MFA, and should log every reset request.
From the Defense Playbook
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.
No bank, agency, or company will ever ask you to move, withdraw, convert, or hand over your money to keep it safe, so any such request identifies the person making it as the threat.
Treat any demand to pay a debt, fine, fee, bail, or "security deposit" with gift cards, cryptocurrency, a wire to a stranger, a payment app, or cash handed to a courier as proof of fraud, because no legitimate institution collects money that way.
Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.
Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Mitnick, K. D., & Simon, W. L. (2002). The Art of Deception: Controlling the Human Element of Security. WileyExtended case studies of telephone social engineering against help desks, receptionists, and employees.
- Federal Trade Commission (2024). Consumer Sentinel Network Data Book 2023. Federal Trade Commission · linkPhone calls carry the highest median per-person loss of any fraud contact method; imposter scams as the most-reported category.
- Federal Bureau of Investigation, Internet Crime Complaint Center (2024). 2023 IC3 Elder Fraud Report. FBI IC3 · linkTech-support fraud as the most-reported crime type among complainants over 60, with losses for that age group above 3.4 billion dollars.
- Twitter, Inc. (2020). An update on our security incident. Twitter company blog · linkCompany statement that the July 2020 breach began with a phone spear-phishing attack on employees.
Related Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.