Glossary
What is vishing?
Vishing (voice phishing) is a social engineering attack carried out over the phone.
- Also known as
- Voice phishing, phone scam
- Channel
- Phone calls: live, automated (IVR) or AI-generated voice
- Typical goal
- One-time codes, passwords, payments, remote access
- Related term
- Callback phishing
How it works
A trusted voice,
a small favour.
- 01
Set the scene
The caller claims to be IT, the bank fraud team, a courier or an official, sometimes with a spoofed caller ID.
- 02
Build trust
They use your name, role or recent activity, and sound calm and helpful.
- 03
Create urgency
A “suspicious login”, a blocked account or a penalty means you must act now, on this call.
- 04
Make the ask
Read out a code, confirm a password, approve a prompt, or install a tool “to fix it”.
Simulated examples
Two calls
worth hanging up on.
IVR message · unknown number
“Your KYC will expire today”
“Press 1 to speak to an agent and update your KYC now, or your account will be suspended.”
- Automated threat of suspension
- Asks you to press a key and share details
- No way to verify who is calling
Questions buyers ask
Frequently asked questions.
Is vishing illegal?
Impersonating someone to obtain money or information by phone is generally treated as fraud. For specific legal questions, speak to a legal adviser or the relevant authorities.
How do I report a vishing call?
Tell your security team through your organisation’s reporting process, including the number, time and what the caller asked for. If it involved your bank, contact the bank on a number you already hold.
Can caller ID be faked?
Yes. Caller ID can be spoofed, so a familiar name or number on screen isn’t proof of who is calling.
Let’s connect the dots
See the human risk.
Change what happens next.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo