← All terms

Vishing

Vishing (voice phishing) is a social engineering attack conducted over phone calls to manipulate victims into revealing sensitive information or taking harmful actions.

Vishing — "voice phishing" — uses phone calls instead of email or text to manipulate targets. CrowdStrike's 2025 Global Threat Report documented a 442% increase in vishing between the first and second half of 2024, making it one of the fastest-growing initial-access techniques.

How it works

Vishing exploits the real-time, personal nature of a phone call:

  • IT helpdesk impersonation. The attacker calls an employee claiming to be from internal IT, walks them through "fixing" an issue, and captures credentials or installs remote access software in the process.
  • Bank or government impersonation. A call claiming to be from the fraud department or tax office pressures the victim into sharing account details or making a payment.
  • Callback phishing. The attacker sends an email or text with a phone number to call. When the victim calls, the attacker controls the entire interaction — there is no spoofed caller ID to inspect.
  • AI-generated voice. Attackers increasingly use deepfake voice cloning to impersonate a known executive or colleague, adding a layer of trust that traditional vishing lacked.

Phone calls create time pressure, emotional engagement, and a sense of authority that text-based attacks struggle to match. Victims have no link to hover over, no sender header to inspect — just a persuasive voice.

How to defend against it

  • Simulate vishing attacks as part of a multi-channel program. NOUSEC supports voice-channel simulations to test how employees respond to phone-based pretexts.
  • Train employees on verbal verification — hang up and call back on a known number, never share credentials or MFA codes over the phone, escalate unexpected requests.
  • Implement callback verification for any financial or access-change request received by phone.
  • Track vishing trends in your social engineering statistics to understand how the threat is evolving.
Full guide
Read the deep dive on this attack →

Related terms

PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.SmishingSmishing (SMS phishing) is a social engineering attack that uses text messages to trick recipients into clicking malicious links or sharing sensitive information.DeepfakeA deepfake is AI-generated synthetic media — audio, video, or images — used in social engineering to impersonate trusted individuals convincingly.PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo