voice phishing - Vishing
Vishing is phishing over the telephone. Instead of an email and a link, the attacker uses a voice, a phone number and the pressure of the moment. They present themselves as a bank, technical support, a courier, the police, the tax office, or somebody from the company, while trying to extract details or lead the victim into doing something they otherwise would not.
Term
description · examples · notesVishing is phishing over the telephone. Instead of an email and a link, the attacker uses a voice, a phone number and the pressure of the moment. They present themselves as a bank, technical support, a courier, the police, the tax office, or somebody from the company, while trying to extract details or lead the victim into doing something they otherwise would not.
Description
The telephone has one awkward advantage for the attacker: the conversation happens now. There is little time to check a sender address, a domain, a link or a message header. If the call is convincing enough, if the number looks familiar, and if a little urgency is added, a person easily starts cooperating with the attacker, thinking they are solving a sudden problem.
Vishing today need not be a crude call from a bad script. The number can be spoofed, the call can be automated, the voice can be synthetic, and the attacker may already know the name, the role, the bank, the supplier or the internal context. Vishing is therefore not solved by somebody recognizing a voice, but by the rule that sensitive things are never confirmed on an incoming call.
Examples
- A call from the bank comes in about a suspicious transaction. The operator asks for the card number, the security code or the one-time code from an SMS, supposedly to stop the abuse.
- Fake technical support calls an employee and asks them to install a remote access tool, because the computer is infected or the account has to be checked urgently.
- The attacker presents themselves as a colleague from IT and asks for an MFA code, claiming that user accounts are being migrated.
Notes
- A legitimate institution will not ask for a full password, a PIN, a CVV or a one-time code over the phone. If it does, the problem is not with your account but with the call.
- You do not call back on the number the caller gave you. Hang up, then call the official or previously known number. A small difference in behavior, a large difference in consequences.
Mentioned in the news
- 22. APR 2026. Caller-as-a-Service prevara danas liči na organizovan call centar →
- 14. APR 2026. Napadi na Okta naloge sve češće idu preko help deska i MFA resetovanja →
- 20. MAR 2026. Aura potvrdila incident koji je zahvatio oko 900.000 korisničkih zapisa →
- 5. MAJ 2026. Bluekit phishing kit uvodi AI asistenta i automatsku registraciju domena →
- 28. MAR 2026. Google i Mandiant: kriminalne grupe sve brže predaju početni pristup →
Techniques
carried out with 3Techniques used to carry it out. Select one to open its page.
Defenses
countered by 3How it is defended against. Select one to open its page.