166 terms · 75/46/45
Threat № 029 · class: social eng.

voice phishing - Vishing

Vishing is phishing over the telephone. Instead of an email and a link, the attacker uses a voice, a phone number and the pressure of the moment. They present themselves as a bank, technical support, a courier, the police, the tax office, or somebody from the company, while trying to extract details or lead the victim into doing something they otherwise would not.

Term

description · examples · notes

Vishing is phishing over the telephone. Instead of an email and a link, the attacker uses a voice, a phone number and the pressure of the moment. They present themselves as a bank, technical support, a courier, the police, the tax office, or somebody from the company, while trying to extract details or lead the victim into doing something they otherwise would not.

Description

The telephone has one awkward advantage for the attacker: the conversation happens now. There is little time to check a sender address, a domain, a link or a message header. If the call is convincing enough, if the number looks familiar, and if a little urgency is added, a person easily starts cooperating with the attacker, thinking they are solving a sudden problem.

Vishing today need not be a crude call from a bad script. The number can be spoofed, the call can be automated, the voice can be synthetic, and the attacker may already know the name, the role, the bank, the supplier or the internal context. Vishing is therefore not solved by somebody recognizing a voice, but by the rule that sensitive things are never confirmed on an incoming call.

Examples

  • A call from the bank comes in about a suspicious transaction. The operator asks for the card number, the security code or the one-time code from an SMS, supposedly to stop the abuse.
  • Fake technical support calls an employee and asks them to install a remote access tool, because the computer is infected or the account has to be checked urgently.
  • The attacker presents themselves as a colleague from IT and asks for an MFA code, claiming that user accounts are being migrated.

Notes

  • A legitimate institution will not ask for a full password, a PIN, a CVV or a one-time code over the phone. If it does, the problem is not with your account but with the call.
  • You do not call back on the number the caller gave you. Hang up, then call the official or previously known number. A small difference in behavior, a large difference in consequences.

Mentioned in the news

Composite
Wikipedia

Techniques

carried out with 3

Techniques used to carry it out. Select one to open its page.

Defenses

countered by 3

How it is defended against. Select one to open its page.