Vishing is a phone-based social engineering attack where scammers impersonate a trusted source, a bank, a company IT desk, or a government agency, to trick victims into handing over sensitive information, money, or system access. The term combines “voice” and “phishing,” and unlike email-based attacks, vishing relies on real-time conversation, urgency, and caller ID spoofing to build false trust in seconds.
The threat has scaled fast: phishing attacks, which include vishing, cost businesses roughly $17,700 every minute, and voice-based social engineering has become the entry point for several of 2025’s most damaging breaches, including the Salesforce-linked attacks tied to ShinyHunters and Scattered Spider. As AI voice cloning makes impersonation calls nearly indistinguishable from the real thing, understanding how vishing works and how to shut it down before it costs you has become essential for individuals and security teams alike.
What Is Vishing?
Vishing is a form of social engineering in which an attacker uses a phone call, rather than email or text, to manipulate someone into revealing credentials, financial details, or remote access to a system. The word is a blend of “voice” and “phishing,” and it describes the same underlying goal, deception for financial or informational gain, carried out through a live or automated voice channel instead of a written message.
What makes vishing distinct is the pressure of real-time conversation. A phishing email can be read carefully, reread, and checked against a company’s actual domain. A vishing call often gives the target seconds to decide. At the same time, the caller manufactures urgency (“your account has been compromised,” “this payment needs to be verified now”) and uses caller ID spoofing to appear as a legitimate bank, vendor, or internal IT line. That combination of urgency and false authority is why vishing continues to succeed even against people who would never click a suspicious link.
Vishing vs. Phishing vs. Smishing
Vishing, phishing, and smishing are all social engineering attacks with the same objective: tricking someone into giving up sensitive information, but they differ by channel. Phishing happens over email, using fake login pages or malicious attachments. Smishing happens over SMS text messages, usually with a shortened malicious link. Vishing happens over a phone call, relying on voice, tone, and real-time pressure instead of a written hook. Attackers increasingly chain these together: an email that instructs the victim to call a number, which then leads into a vishing script, so the three are often part of a single coordinated attack rather than separate threats.
Vishing Meaning in Cyber Security
In a cybersecurity context, vishing is classified as a social engineering attack vector, not a technical exploit; it targets human trust rather than a software vulnerability, which is exactly why it bypasses spam filters, endpoint protection, and other technical defenses. Security teams treat it as a serious enterprise risk because a single successful vishing call can hand an attacker valid credentials or a live remote-access session, skipping the need to break through any technical perimeter at all. This is the mechanism behind several major 2025 breaches, including the Salesforce-linked incidents attributed to ShinyHunters and Scattered Spider, where attackers called employees directly and talked their way into OAuth access rather than exploiting a code-level flaw.
How Vishing Attacks Work
A vishing attack works by combining a believable pretext, a spoofed identity, and manufactured urgency into a single phone call designed to get the victim to act before they think to verify. Attackers typically research their target first, pulling a name, employer, or account details from a data breach or public source, then use that information to sound credible from the first sentence of the call. The goal isn’t a long con; most vishing calls are built to extract one piece of value (a password, a one-time passcode, a wire transfer, remote access) in a matter of minutes.

Common Vishing Scripts and Pretexts
Most vishing calls follow a recognizable script structure, even though the cover story changes. The attacker opens by establishing false authority, claiming to be from a bank’s fraud department, a company’s IT help desk, the IRS, or a delivery service, then introduces a problem that requires immediate action, such as a suspicious charge, a compromised account, or an unpaid tax bill. From there, the call moves quickly into a request: confirm your login, read back the code we just texted you, or install this remote access tool so we can fix it for you. The pretext works because it mirrors a real process the victim has experienced before, and the artificial time pressure discourages them from hanging up to verify independently.
Caller ID Spoofing and VoIP Abuse
Caller ID spoofing lets an attacker make a call appear to come from any number they choose, including a real bank’s customer service line or a company’s internal extension, and it’s the technical trick that makes vishing pretexts believable at first glance. This is made possible largely through VoIP (Voice over IP) systems, which allow the calling party to set an arbitrary outbound caller ID with little to no verification, unlike traditional telephone networks. The FCC has pushed telecom carriers to adopt STIR/SHAKEN call authentication standards specifically to curb this abuse. However, spoofed calls still reach victims regularly because adoption and enforcement remain inconsistent across carriers and, especially, international routes.
Types of Vishing Attacks
Vishing attacks fall into several distinct types, each defined by how the attacker initiates contact or what tools they use to build trust. While the end goal, stealing credentials, money, or access, stays the same, the delivery method has evolved well beyond a simple cold call, now spanning multi-channel setups, AI-generated voices, and highly targeted executive impersonation.

Hybrid Vishing
Hybrid vishing combines a phone call with another channel, usually email or SMS, to make the overall attack more convincing than either method alone. A common pattern is an email that warns of a suspicious charge and provides a phone number to “resolve” it; the number connects directly to the attacker, who then runs a live vishing script once the victim calls in. Because the victim initiates the call themselves, they arrive already primed to trust the person on the other end, which makes hybrid vishing notably harder to flag than a cold inbound call.
Reverse Vishing
Reverse vishing flips the usual setup: instead of calling the victim, the attacker tricks them into calling in. This often starts with a fake pop-up, voicemail, or email warning of a fraudulent charge or virus, urging the victim to call a listed “support” number immediately. Because the victim believes they’re the one taking control of the situation, they’re far less guarded than they would be on an unsolicited inbound call. This psychological edge makes reverse vishing especially effective against tech-support and banking-fraud pretexts.
AI and Deepfake Vishing
AI and deepfake vishing use synthetic voice technology to clone a real person’s voice- a CEO, a family member, a known colleague- often from just a few seconds of publicly available audio, and then use that cloned voice to issue urgent requests over the phone. This has moved vishing from a purely social attack into one with a technical multiplier: a scripted pretext is convincing, but a familiar voice asking for help is far harder to question. Security teams increasingly flag deepfake vishing as one of the fastest-growing variants, since falling voice-cloning costs have made it accessible well beyond well-funded threat actors.
Spear Vishing (Targeted Executives)
Spear vishing is a highly targeted version of vishing aimed at a specific individual, typically a C-suite executive, finance team member, or IT administrator with privileged access. Attackers research the target extensively beforehand, using LinkedIn, breached data, or company org charts. Hence, the call references real details like a colleague’s name, an ongoing project, or a recent internal event. This precision is what separates spear vishing from a generic scam call, and it’s the pattern behind several high-profile 2025 breaches where attackers impersonated IT support to convince employees to hand over OAuth access or reset credentials.
Real-World Vishing Attacks and Statistics
Vishing has moved from a nuisance scam tactic into the initial access method behind some of the most damaging enterprise breaches of the past two years, with CrowdStrike recording a 442% surge in vishing campaigns between the first and second half of 2024 alone. That jump lines up almost exactly with the rise of AI voice cloning, which lets attackers convincingly impersonate IT staff, executives, or coworkers using just a few seconds of sampled audio.

Salesforce / ShinyHunters and Scattered Spider Vishing Campaigns
Throughout 2025 and into 2026, threat actors linked to ShinyHunters (tracked as UNC6040) and Scattered Spider ran a sustained vishing campaign against Salesforce customers, calling employees while posing as internal IT support and walking them through authorizing a malicious connected app disguised as a legitimate Salesforce tool. The technique gave attackers OAuth-based access without needing to exploit any actual vulnerability in Salesforce itself, and it’s been tied to breaches at organizations across retail, aviation, insurance, and financial services, including a 2025 incident that exposed over 2.8 million customer records at Allianz Life. Cisco disclosed a related incident in July 2025, when a vishing call against a single employee gave an attacker access to a third-party CRM system and exposed basic profile data, names, emails, and phone numbers for a subset of Cisco.com users.
MGM Resorts and Cisco Vishing Incidents
The MGM Resorts breach in September 2023 remains the clearest illustration of how much damage a single vishing call can do: Scattered Spider members found an MGM employee’s profile on LinkedIn, then called the company’s IT help desk impersonating that employee to request an MFA reset. The call took roughly 10 minutes and gave the attackers super-administrator access to MGM’s Okta and Azure environments, leading to a ransomware deployment that shut down slot machines, hotel key cards, and booking systems, and cost MGM an estimated $100 million. The Cisco incident two years later followed the same core pattern at a smaller scale, proof that the help-desk vishing playbook that worked against a $34 billion casino operator still works against sophisticated technology companies today.
Vishing Statistics 2024–2026
Beyond the headline breaches, the broader data confirms vishing has become a mainstream attack vector rather than an edge case: Unit 42’s 2025 Global Incident Response Report found that 23% of all social engineering incidents involved callback or voice-based techniques, and IT help desks were the single most targeted point of entry, cited in 42% of vishing attacks specifically because of the credential-reset access they control. The financial exposure is significant too; Group-IB estimates that over 10% of banks have suffered deepfake-vishing losses exceeding $1 million, at an average of roughly $600,000 per incident.
How to Spot a Vishing Call, Red Flags
The clearest sign of a vishing call is pressure: a legitimate bank, government agency, or IT department will never demand an immediate decision, an MFA code, or payment while you’re still on the phone. Scammers rely on that moment of panic to short-circuit your judgment, so the single most reliable defense is simply slowing down, hanging up, and calling the organization back using a number you already know is real, not one the caller gives you.

Common Vishing Red Flags (FTC Guidance)
Several patterns show up consistently across vishing calls, and recognizing them in the moment is what actually stops an attack. A caller who claims your account has been compromised and then asks you to read back a one-time passcode you just received by text is one of the clearest indicators; no legitimate institution asks for that code over the phone, since it exists specifically to verify you, not them. Requests to pay or “resolve” an issue using gift cards, cryptocurrency, or a wire transfer are another near-certain sign of fraud, as the FTC notes no real business or government agency accepts payment that way. Trusting caller ID is also a mistake: spoofing tools let scammers display a bank’s real number or an internal company extension, so the name or number on the screen proves nothing about who’s actually calling. Finally, be wary of any caller asking you to download remote-access software “to fix the problem”; this is one of the most common vishing tactics used against both consumers and corporate help desks, since it hands the attacker direct control rather than just information. If a call shows more than one of these signs, the safest move is to hang up immediately and verify independently.
How to Prevent and Protect Against Vishing
Preventing vishing comes down to two things: verifying identity independently before acting on any request, and never letting a single phone call be the only authentication step for something sensitive. That principle holds whether you’re an individual protecting your own accounts or an organization trying to keep a single social engineering call from becoming a full network breach.

Prevention Best Practices for Individuals
The most effective habit against vishing is refusing to act while still on the call. If someone claiming to be your bank, a government agency, or a company you use says there’s an urgent problem, hang up and call the organization back using a number from its official website or the back of your card, never a number the caller provides. Individuals should also never read back a one-time passcode to anyone, regardless of who they claim to be, since that code exists to confirm your identity to the real institution, not to verify the caller’s. It’s worth treating every unexpected call about account security, unpaid taxes, or a “compromised” card with the same skepticism as a suspicious email, since vishing exploits the same trust vishing email and text scams do, just through a channel that feels more personal and harder to fake.
Vishing Prevention Tools and Employee Training
At the organizational level, vishing prevention depends less on technology and more on tightening identity verification at the points attackers actually target, most often the IT help desk, since it controls password resets and MFA enrollment. Companies are increasingly requiring callback verification, secondary identity checks, or in-person confirmation before processing any credential reset requested by phone, closing the exact gap that let Scattered Spider and ShinyHunters-linked actors compromise organizations like MGM Resorts and Cisco through a single convincing call. Security awareness training also has a measurable impact: organizations that run regular phishing and vishing simulations see employee reporting rates of around 21%, compared to just 5% at untrained organizations, a difference that can be the gap between an attempted call and a full-blown breach. Combined with phishing-resistant authentication methods like FIDO security keys, which can’t be read back or phished over a phone call, these controls address vishing at the level where it actually succeeds: human trust, not a technical vulnerability.
Is Vishing Illegal? Legal Consequences
Yes, vishing is illegal in the United States. A phone call used to deceive someone into handing over money, credentials, or personal information satisfies the definition of fraud under federal law, and prosecutors most commonly bring these cases as wire fraud, often paired with identity theft charges when the attacker used or obtained someone else’s personal information.

Vishing and Wire Fraud (18 U.S.C. § 1343)
Vishing calls are prosecuted almost exclusively under the federal wire fraud statute, 18 U.S.C. § 1343, since the law covers any scheme to defraud carried out using an interstate electronic communication, and a phone call qualifies just as clearly as an email or text message. To convict, prosecutors must prove the caller intentionally devised a scheme to defraud and knowingly used a wire communication to carry it out; the case doesn’t require the scam to have actually succeeded, only that the fraudulent scheme and the qualifying communication both existed. Wire fraud carries serious weight as a federal felony, with sentences of up to 20 years in prison per count, and because each call can be charged as a separate count, a vishing operation targeting multiple victims can expose the perpetrator to a substantial cumulative sentence.
Vishing and Identity Theft Charges
When a vishing call succeeds in extracting a Social Security number, account credentials, or other personal identifiers, prosecutors frequently add a charge under 18 U.S.C. § 1028A, aggravated identity theft, on top of the underlying wire fraud count. This statute carries a mandatory, consecutive two-year prison sentence, meaning it’s served in addition to, not alongside, any wire fraud sentence, specifically because Congress treats the unauthorized use of someone’s identity as a distinct harm from the financial fraud itself. This combination is exactly why large-scale vishing operations, like the help-desk social engineering campaigns tied to Scattered Spider and ShinyHunters, carry such significant legal exposure: each successful call that captures an employee’s credentials can support both a wire fraud count and a separate aggravated identity theft charge.
How to Report a Vishing Attack
Report a vishing attack to the FTC at reportfraud.ftc.gov and, if any money or credentials changed hands, to the FBI’s Internet Crime Complaint Center at ic3.gov, the two channels that actually feed law enforcement investigations and fraud-pattern tracking. Filing takes only a few minutes, and doing it even when nothing was lost still helps investigators connect a single call to a broader campaign.

Which agency to use depends on what happened during the call. The FTC’s reportfraud.ftc.gov is the right first stop for any vishing attempt, since it logs the incident into the Consumer Sentinel database shared with more than a thousand law enforcement agencies nationwide. If the call resulted in a wire transfer, cryptocurrency payment, or a significant financial loss, file with the FBI’s IC3 as well; speed matters here, since banks can sometimes recall a wire transfer within the first 24 to 72 hours if notified quickly. For calls involving a spoofed caller ID or illegal robocall, the FCC at fcc.gov/complaints handles enforcement specifically around caller ID fraud, which carries fines of up to $10,000 per spoofed call used to defraud someone. It’s also worth forwarding the number as a text to 7726 (SPAM), which most U.S. carriers use to flag the number at the network level for other customers, and contacting the impersonated company’s fraud line directly, since your report may be the detail that lets them block the number before it reaches someone else. If the caller obtained a Social Security number or other identifying information, follow the FTC report with a local police report; together, these create a formal Identity Theft Report that carries added legal weight when disputing fraudulent accounts.
Frequently Asked Questions (FAQ’s)
What does the term “vishing” stand for?
It’s a blend of “voice” and “phishing”, a scam carried out over a phone call instead of email or text. The goal is the same as any phishing attempt: trick someone into handing over sensitive information or access.
Can a scammer really fake a bank’s phone number?
Yes. Caller ID spoofing lets attackers display any number they choose, including a real institution’s customer service line, so the name on your screen proves nothing about who’s actually calling.
Is a voice phishing call actually a crime?
Yes, these calls are typically prosecuted as federal wire fraud, often with identity theft charges added if personal information was obtained. Penalties can include up to 20 years in prison per offense.
What’s the difference between vishing and a robocall?
A robocall is just an automated call, which may or may not be a scam. Vishing specifically refers to a call, automated or live, designed to deceive the recipient into giving up money or information.
Can businesses really be breached through a single phone call?
Yes, the MGM Resorts and Cisco breaches both started with one convincing call to an IT help desk. A successful call can hand an attacker credentials or system access without touching any software vulnerability at all.
How is AI changing these scams?
Voice cloning tools can now replicate a real person’s voice from just a few seconds of audio, making impersonation calls far more convincing. This has driven a sharp rise in deepfake-based scams targeting both individuals and companies.



