Cybersecurity glossary
What is Vishing?
Learn what vishing is, how attackers use phone calls and spoofed caller ID to steal credentials and payments, how live pretexting differs from email phishing, and how to verify inbound calls.
Definition
Vishing is voice-based phishing: a social-engineering attack conducted over a phone call in which the adversary impersonates a trusted institution, colleague, or vendor to extract secrets, payments, or remote access while adapting the story in real time.
Why a human voice still bypasses email-hardened users
People who would never open a strange attachment will still answer the phone. Vishing uses that leftover trust. The attacker does not need a perfect clone of a login page. They need a plausible identity, a reason the call cannot wait, and enough live conversation to talk past the victim’s first hesitation.
Caller ID spoofing makes the first glance look official. Help-desk scripts, bank “fraud departments,” and vendor collections teams are easy to imitate because employees have heard the real versions. Once the victim is speaking, the attacker can invent new details, request a second factor “to verify it is you,” or walk the person through installing a remote-support tool.
The channel also pairs with other lures. A smish says “call us about your delivery.” An email says “accounts payable will phone you.” The call then feels like confirmation instead of the attack.
How a vishing call is run
Pick a role the victim already obeys
IT support, bank fraud, tax authority, payroll, or a senior leader whose requests are rarely challenged.
Arrive with a number that looks local
Spoof caller ID, use a rented DID, or ask the victim to return a missed call so they initiate the session.
Open with a work-shaped emergency
Locked account, unpaid invoice, payroll error, data-leak notice, or a CEO who ‘cannot be reached any other way.’
Defeat verification theater
Read back leaked personal data, quote a fake ticket number, or stay on the line while the victim ‘checks’ a page the attacker also controls.
Extract the usable action
Collect OTPs, reset passwords, approve a payment, or install remote-access software and stay until the task is done.
Hold the victim in the conversation
Prevent a callback to the real help desk by insisting the ticket will close, the account will freeze, or the executive is waiting.
Payloads unique to the voice channel
One-time code harvesting
The caller times the conversation to a login they already started and asks the victim to read the SMS or app code aloud.
Remote-access foothold
The victim is talked into AnyDesk, Quick Assist, or a ‘required’ support agent that hands over an interactive desktop.
Payment under authority
A supposed executive or counsel stays on the line until a wire, gift-card, or crypto transfer is confirmed.
Help-desk credential reset
Attackers call IT posing as an employee, or call the employee posing as IT, and reset the identity that MFA was protecting.
Vishing compared with other social-engineering channels
| Channel | Can the attacker adapt live? | Common verification trap |
|---|---|---|
| Vishing | Yes—objections are handled in conversation | Trusting caller ID or data the attacker already leaked |
| Smishing | Only via follow-up texts | Tapping a short mobile URL |
| Email phishing | Limited until the victim replies | A lookalike domain with a valid certificate |
| BEC without a call | No live pressure | An email that looks like an executive instruction |
How to make inbound calls fail closed
- No inbound caller is authenticated by caller ID, voice familiarity, or knowledge of public employee details.
- Never read an MFA code, password, or recovery phrase to someone who contacted you. Real support does not need that.
- Hang up and call back using a number from the official app, badge directory, or vendor contract—not from voicemail or the inbound display.
- Forbid installation of remote-access tools from an unsolicited call, including tools you already own, unless you opened a ticket first.
- For payments, require a second person and an out-of-band check even if a ‘CEO’ is waiting on the line.
- Train help-desk staff against the inverse vish: someone calling in as an employee to reset MFA or forwarding.
- Log and report vishing like phishing, with audio notes if legally allowed; patterns repeat across a company faster than one victim realizes.
- Warn that AI voice clones exist; executive payment requests must follow the written dual-control process regardless of who ‘sounds right.’
Help desks are both target and impersonation costume
A mature vishing program attacks both directions. Criminals impersonate IT to users, and they impersonate users to IT. Identity verification at the service desk must not collapse to “they knew their manager’s name.” Use approved callbacks, manager attestation on a known channel, or phishing-resistant proof—not trivia from LinkedIn.
The practical takeaway
Vishing is phishing that can argue back. Spoofed numbers, stolen personal data, and live pressure make a careful email user vulnerable again.
Treat every inbound call that asks for access, codes, or money as untrusted. Authenticate the institution by calling a number you already had. If the request is real, it will survive a three-minute callback. If it is vishing, that callback is the entire defense.
Related security terms
Phishing
Email and web lures; vishing moves the same trust abuse onto a live call.
Smishing
SMS lures frequently provide the callback number that starts a vishing session.
Pretexting
The invented identity and emergency that the caller performs, and can rewrite, during the conversation.
Business Email Compromise (BEC)
Payment-fraud crews often add a confirming phone call so the wire request feels dual-channel.
Social Engineering
Vishing is social engineering at conversation speed, using authority, fear, and helpfulness.
Frequently asked questions
What is vishing in simple terms?
Vishing is a scam phone call. Someone pretends to be IT, a bank, a vendor, or the tax office and talks you into sharing codes, installing remote-access software, or sending money.
If the caller ID shows my bank or my company, is the call real?
Caller ID can be spoofed. Displayed names and numbers are not authentication. Hang up and call back using a number from the card, app, or internal directory—not from the inbound call.
How is vishing different from phishing?
Phishing is mostly a one-way message plus a page. Vishing is interactive. The caller can answer objections, add urgency, and keep you on the line until you comply.
Why do IT help-desk vishes work?
Employees expect occasional support calls, remote-access tools are already in the environment, and refusing a ‘security incident’ call feels like blocking a colleague.
Are AI-cloned voices a real vishing risk?
Yes. Recordings from webinars or social media can be used to impersonate an executive in a short, urgent request. Voice familiarity is no longer proof of identity.
What should I do if I already shared a code on a call?
Treat it as account compromise: hang up, contact the real institution on a known number, revoke sessions, rotate credentials, and report the call internally with time, number, and what was requested.
Can companies stop vishing with spam-call blocking?
Blocking reduces nuisance volume. Targeted vishes use local numbers, callback flows, and sometimes real compromised phones. Process—never share OTPs or grant remote access from inbound calls—is the durable control.
References
Explore authoritative guidance and frameworks related to vishing.
Explore every security definition
Return to the glossary to search by term, alias, starting letter, or security category.