Glossary

What is vishing?

Vishing (voice phishing) is a social engineering attack carried out over the phone.

Also known as
Voice phishing, phone scam
Channel
Phone calls: live, automated (IVR) or AI-generated voice
Typical goal
One-time codes, passwords, payments, remote access
Related term
Callback phishing

How it works

A trusted voice,
a small favour.

  1. 01

    Set the scene

    The caller claims to be IT, the bank fraud team, a courier or an official, sometimes with a spoofed caller ID.

  2. 02

    Build trust

    They use your name, role or recent activity, and sound calm and helpful.

  3. 03

    Create urgency

    A “suspicious login”, a blocked account or a penalty means you must act now, on this call.

  4. 04

    Make the ask

    Read out a code, confirm a password, approve a prompt, or install a tool “to fix it”.

Simulated examples

Two calls
worth hanging up on.

Simulated example
Automated call09:12

IVR message · unknown number

“Your KYC will expire today”

“Press 1 to speak to an agent and update your KYC now, or your account will be suspended.”

  • Automated threat of suspension
  • Asks you to press a key and share details
  • No way to verify who is calling

Questions buyers ask

Frequently asked questions.

Is vishing illegal?

Impersonating someone to obtain money or information by phone is generally treated as fraud. For specific legal questions, speak to a legal adviser or the relevant authorities.

How do I report a vishing call?

Tell your security team through your organisation’s reporting process, including the number, time and what the caller asked for. If it involved your bank, contact the bank on a number you already hold.

Can caller ID be faked?

Yes. Caller ID can be spoofed, so a familiar name or number on screen isn’t proof of who is calling.

Let’s connect the dots

See the human risk.
Change what happens next.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo