| Key Takeaways |
| Vishing is phishing over the phone, and the target has shifted. Employees and help desks are now called more often than consumers. |
| Attackers want one-time codes, passwords, and approvals. No bank or employer will ever ask you to read a code back to them. |
| Group-IB Fraud Protection catches the patterns behind these calls, including spoofed numbers, repeat callers, and unusual activity in your contact center, before one becomes a loss. |
What is Vishing in Cybersecurity?
Vishing, short for voice phishing, is a social engineering attack in which cybercriminals use phone calls or voice messages to trick individuals into sharing sensitive personal information, such as bank account information, credit card numbers, social security numbers, or login credentials.
Unlike traditional phishing attacks and email addresses, vishing relies on telephony-based deception. Attackers often pose as representatives from trusted organizations like banks, government agencies, or tech support teams to gain the potential target’s trust. Once trust is established, they pressure the individual into revealing sensitive data or performing actions that compromise their network security.
Historically, landline calls were seen as secure and credible, tied to physical locations and verified bill-payers. However, modern technology allows attackers to spoof caller IDs, making it easy to impersonate legitimate businesses and evade detection.
Vishing Attack Examples
One of the most emotionally manipulative vishing attack examples is the “grandparent scam.” In this scheme, fraudsters target elderly individuals, calling them while pretending to be a grandchild in trouble.
Here’s how vishing works:
“Grandma, I’ve been in an accident,” or “I’m stuck overseas, I need help.” The goal is to trigger panic. Once trust is gained, they send someone to physically collect cash or ask for a wire transfer. It’s cruel, personal, and sadly, still very effective.
Here are some more vishing attack examples that have shaken the world:
1. Twitter’s 2020 social engineering breach
In July 2020, Twitter experienced a significant data breach. Attackers used vishing techniques to impersonate IT staff and trick employees into revealing their credentials.
This allowed unauthorized access to internal systems and compromised several high-profile accounts, including those of Elon Musk and Barack Obama in the United States.
2. Deepfake executive impersonation on a video call
In March 2025, the finance director of a multinational in Singapore was contacted on WhatsApp by someone posing as the company’s chief financial officer and invited to a Zoom call about a regional restructuring. A man claiming to be a lawyer rang separately, stressed how confidential the project was, and had him sign an NDA.
On the call itself, the chief executive and other colleagues were on screen, and all of them were deepfakes. He moved US$499,000 out of the company’s HSBC account into what turned out to be a mule account.
He worked out what had happened the next day, when the same people came back asking for another US$1.4 million. Singapore’s Anti-Scam Center and the Hong Kong Police Force’s Anti-Deception Coordination Center traced and held the money within three days.
3. AIB bank impersonation attempt
In early 2025, a vishing scammer posing as a bank fraud team member targeted an Allied Irish Banks (AIB) business customer.
The attacker directed the victim to a fake AIB website, leading to the unauthorized initiation of a €41,000 payment. Fortunately, the financial transaction was intercepted before completion.
4. Vishing attack on UK financial institution
According to a 2024 report by Keepnet Labs, a UK-based financial institution suffered a significant loss when an executive was deceived by a convincing phone scam.
The attacker impersonated a trusted party, leading to the disclosure of sensitive credentials and subsequent financial loss.
5. Ferrari CEO impersonation attempt
In July 2024, a Ferrari executive picked up a call from someone who sounded exactly like chief executive Benedetto Vigna, down to the southern Italian accent. The caller said he was ringing from a different number about a confidential acquisition and needed an urgent currency transaction pushed through.
Something in the intonation sounded faintly mechanical, so the executive asked the caller to name the book Vigna had recommended to him a few days earlier. The call ended at once, and Ferrari opened an internal investigation. One unscripted question about a shared memory did what checking the number never could.
Types of Vishing
Let’s walk through the most common (and creative) types of vishing tactics you should be aware of:
1. Wardialing scams
In dialing scams, attackers use automated systems to dial numbers within a local area code. The voice on the other end may pose as your neighborhood credit union or local courthouse, warning you of a suspicious transaction or pending legal issue.
The goal of this common tactic is to pressure you into revealing sensitive information like account numbers or addresses quickly.
2. VoIP-based vishing
Voice over IP (VoIP) calls make it incredibly easy for attackers to disguise their identity. Using low-cost or free calling services, they can display what looks like a toll-free number, or even mimic your local area code.
In one known case, victims received calls that appeared to come from their pharmacy, only to be asked to confirm “account security questions” that later showed their financial details and personal details.
3. Trash tracing (modern dumpster diving)
It may sound old-school, but cybercriminals still launch cyber attacks using discarded paperwork. One scam involved fraudsters retrieving pre-shredded utility bills tossed behind an apartment complex’s leasing office.
With just a name, phone number, and billing info, they called tenants pretending to be from the water company. They claimed a payment failure and demanded card details to “avoid service suspension.”
4. Caller ID spoofing
This one’s tricky because the number and even the name on your screen look like they’re from a legitimate organization. A vishing call might show “Bank of America” or “City Police Department,” but it’s a facade.
Threat actors use caller ID spoofing to instill instant trust or fear. One variation even displays official-looking callbacks like “TAX OFFICE” to lure victims into confirming identity details under pressure for identity theft.
5. Tech support impersonation
You’re working, and suddenly your phone rings: “Hi, this is Microsoft. We’ve detected unusual activity on your system.” Sounds helpful, right? But it’s a trap.
The scammer walks you through installing remote access software under the guise of resolving a threat. Instead, they quietly steal files or plant malware while you watch the screen blink.
6. Government or Tax Authority Impersonation
These scams tap into fear or financial need. A scammer may pose as a revenue agency agent, claiming you’re due a refund or worse, that you owe back taxes and risk arrest.
They’ll demand your SIN number, banking info, or immediate payment via gift cards or crypto. One variant in 2025 even involved AI-generated voices mimicking actual government staff.
Vishing vs Phishing vs Smishing: What’s the Difference?
Vishing, phishing, and smishing are all social engineering attacks used by cybercriminals to trick individuals into revealing sensitive personal and financial information.
Although their goal is similar- stealing confidential data- the method and medium of execution differ. Understanding these differences is key to recognizing and preventing these types of attacks.
Key differences between vishing, phishing, and smishing at a glance
These three overlap more than the labels suggest, and a single campaign will often start in an inbox and finish on the phone. What separates them is the channel and how much room each one leaves you to stop and think.
| Aspect | Phishing | Vishing | Smishing |
| Delivery method | Phone calls or recorded voice messages | SMS, MMS, or messaging apps (WhatsApp, Telegram, etc.) | |
| Common targets | Individuals and employees (via personal or business email) | Individuals, especially seniors or banking customers | Any mobile phone user, often mass-targeted |
| Attack examples | Fake login pages, invoice scams, Business Email Compromise (BEC) | Fake bank/fraud department calls, tech support scams | Fake delivery notifications, promo offers, and account alert messages |
| Tools used | Spoofed domains, fake email templates, phishing kits | Caller ID spoofing, robocalls, voice cloning (AI-based in some cases) | Shortened URLs, fake app links, and impersonation via SMS |
| Emotional triggers | Urgency, fear (e.g., “account suspended”), curiosity, reward | Authority, panic (e.g., “Your account has been hacked”) | Urgency, reward (e.g., “You’ve won a prize”), or fear |
| Success rate factors | Depends on email filters, user awareness, and domain authenticity | Relies on the caller’s trust and voice tone to convince potential victims | High open and response rates (SMS: ~98% open, ~45% response) |
| Detection difficulty | Often flagged by spam filters or anti-phishing tools | More challenging to detect in real-time; relies on human judgment | Hard to detect unless reported; often appears as legitimate texts |
| Attack volume | Prevalent. As it is the most common attack method globally | Lower volume but often more targeted and personalized | Increasing sharply due to mobile dependency |
| Mitigation tips | Use spam filters, avoid clicking unknown links, and verify senders | Hang up and call official numbers directly; don’t give info over the phone | Don’t click on unknown links; block suspicious numbers |
| Business risk level | High. It can lead to credential theft, wire fraud, or ransomware | Medium to high. It can target employees in finance or admin roles | Medium. It targets users, but can also lead to data breaches |
| Often Used In | BEC and credential harvesting | Financial scams, tech support fraud, voice deepfake attacks | E-commerce scams, mobile malware distribution, and personal data harvesting |
What are the Signs of a Vishing Attack?
No single item on this list proves a call is fraudulent, because real institutions do sometimes ring out of the blue. What marks out a vishing attempt is two or three of these turning up together in the same short conversation.
- Unsolicited phone calls claiming to be from banks, government officials, or tech support
- Caller uses urgent or threatening language to pressure immediate action
- Requests for private information like PINs, passwords, OTPs, or account numbers
- Caller ID seems legitimate or spoofed (e.g., showing “Bank” or “Tax Office”)
- Emotional manipulation that uses fear, guilt, or excitement to cloud judgment
- Asked to download software or grant remote access to your device
- Unusual payment requests, such as prepaid cards, gift cards, or cryptocurrency
- Refusal to let you verify their identity or call back through official channels
- Poor call quality, robotic voices, or scripted responses
- Claims of suspicious activity or fraud on your account to lure you into “verifying” data
Common Targets of Vishing Attacks
For years, the typical vishing victim was an older person at home, and that picture still shapes how most companies train their staff for it. Attackers have moved on. The people they call now usually work inside the organization they are trying to break into.
IT help desks and support teams
A help desk exists to unblock people who are locked out, which makes it the one team in the building trained to be helpful to a stranger who sounds stressed. Attackers call pretending to be an employee, offer a name and job title they found on LinkedIn, and ask for a password reset or a new MFA device.
The 2023 ransomware attack on MGM Resorts started with a call like that, and the company later told the SEC it had cost roughly 100 million dollars in lost earnings across its Las Vegas and regional properties. Several UK retailers, including Marks & Spencer, were hit the same way in the spring of 2025.
Employees with access to customer data
Anyone who can log into a CRM, a billing platform, or a cloud admin console is worth a phone call. In 2025, Google’s threat intelligence team tracked a group it calls UNC6040, which rang staff at roughly twenty companies, posed as internal IT, and talked them through authorizing a modified app inside Salesforce. Nothing was hacked in the usual sense. The attackers asked, and someone clicked approve.
Older adults and retail banking customers
The consumer side of this has not gone anywhere. Fraudsters still phone people at home posing as a bank fraud department, a tax officer, or a grandchild in trouble, and the scripts work because they create panic before anyone has time to check.
Older adults get targeted more often for two boring reasons. They are more likely to answer an unknown number and more likely to have savings worth taking. Banks absorb much of this cost, which is why fraud teams have started treating inbound call verification as a security control rather than a customer service one.
What Information Do Vishing Attackers Try to Steal?
Mostly, whatever gets them into an account. One-time passcodes are the single most requested item on a vishing call, and the fact that they expire in under a minute hands the caller a ready-made reason to keep rushing you. Passwords and security question answers matter too, though it is the live code that turns a stolen password into a working login. Some callers never ask for a code at all and simply keep talking until you approve the push notification they have triggered on your phone.
After access comes money and identity. Card numbers, CVV codes, and account details get spent within hours, sometimes while the call is still running. National identity numbers, dates of birth, and home addresses are slower to turn into cash but do more lasting damage, because they let someone open accounts in your name months after you have forgotten the call happened. That is also why a caller who only asks you to confirm details you assume are already public is still worth hanging up on.
The less obvious target is information that looks worthless on its own. Who your manager is, which vendor runs payroll, what the internal ticketing system is called, whether the help desk sits in-house or with a contractor. None of that would ever appear on a list of sensitive data, and all of it makes the next call sound like it is coming from a colleague. Plenty of vishing calls are not trying to extract information in the first place.
How To Prevent Vishing Attacks?
Here are practical steps to protect against common vishing scams:
1. Never disclose personal information over the phone
Even if the call sounds official, treat every unexpected request for details with suspicion.
What to do:
- If someone asks for passwords, PINs, OTPs, credit card information, or bank details, hang up immediately.
- Banks, government agencies, federal agencies, and legit tech companies never ask for confidential information over a cold call or through an email address.
- If in doubt, call the institution or small business directly using the number from their official website, not the one you received the call from. Don’t fall for any of the social engineering tactics.
2. Be wary of unknown callers
Vishers are skilled impersonators. They’ll pretend to be from your bank, internet provider, or police.
What to do:
- Never engage with suspicious or high-pressure callers.
- Ask for their name, department, and a callback number, then verify it independently.
- Trust your instincts. If something feels off, it probably is.
3. Don’t trust caller ID alone
Caller ID spoofing makes it easy for scammers to appear to be calling from a trusted number.
What to do:
- If the call seems urgent or emotional, don’t make decisions based on caller ID alone.
- Always double-check by calling the official number yourself.
- Never rely on the “name” displayed; scammers can fake it easily.
4. Spread awareness
Prevention starts with knowledge. Educate yourself and those around you, especially the elderly or those less tech-savvy.
What to do:
- Share real-life vishing examples with friends, family, and coworkers.
- Run internal training sessions at work, using different type of phishing attacks/vishing simulations.
- Encourage open discussion; many people don’t report these calls out of embarrassment.
5. Never allow remote access to your devices
One of the most dangerous scams involves giving attackers access to your system under the guise of “tech support scams.”
What to do:
- Never install remote access tools (like AnyDesk or TeamViewer) based on an unsolicited call.
- If a caller says your device is infected, hang up. Actual companies won’t cold-call you about issues on your device.
- Report such scam calls to your IT department/security team or fraud hotline.
6. Be suspicious of unusual payment requests
If someone asks for payment in gift cards, wire transfers, or cryptocurrency, it’s almost always a scam.
What to do:
- Pause and think, why would legitimate companies ask for Amazon gift cards or Bitcoin?
- Always verify payment instructions through official websites or customer service lines.
- If asked to act “immediately,” take a step back and question the urgency.
7. Use security software with anti-vishing features
Some vishing calls can be flagged or blocked before they even reach you—if you have the right tools in place.
What to do:
- Install caller ID protection or call-blocking apps (like Truecaller or Hiya).
- Use mobile security software to detect spoofed calls or malicious links sent by SMS.
- For businesses, implement firewalls and endpoint protection tools that alert you to suspicious voice communication.
8. Implement technology to strengthen vishing detection
Companies are often targeted through finance or support teams. Proactive threat detection can stop these scams at the source.
What to do:
- Invest in fraud protection platforms like Group-IB Fraud Protection, which identifies high-risk patterns like:
- Repeated calls from the same number
- Abnormal call behavior to your support center
- Spoofed numbers impersonating your brand
- Integrate behavioral monitoring into your customer interaction platforms to catch red flags early.
Case in Point: How NVISO Supercharged Detection with Group-IB Threat Intelligence |
| When leading European cybersecurity provider NVISO needed deeper visibility into fast-moving threats, it turned to Group-IB’s Threat Intelligence. The goal was to strengthen incident response, threat hunting, and MDR services across multiple sectors.
The result:
Read the full case study here → GROUP-IB x NVISO Success Story |
How to Recover from a Vishing Attack
Most people work out what has happened somewhere between ten minutes and two days after the call ends. What you do in that first hour matters more than almost anything that follows, and the thing that usually gets in the way is embarrassment rather than a shortage of options.
Assess what information was compromised
Write down what you actually said while you still remember it clearly, because the details soften fast. There is a real difference between handing over information and taking an action, and the two need different fixes. Reading out a code or a card number is a disclosure. Installing software, approving a login prompt, or sending a payment means someone else now has a foothold, and that device should come off the network before you do anything else.
Notify your bank and financial institutions
Call the bank on the number printed on your card or taken from their official site, never the number the caller gave you. Say plainly that you were targeted by a phone scam, which routes you to the fraud team instead of general support, and ask them to freeze the account, recall any transfer, and flag the card.
Recall rates fall away sharply once the money has passed through a second account, which often happens within hours. If more than one institution holds your details, work through all of them rather than assuming the first call covers it.
Report the incident to the relevant authorities
Reporting rarely gets the money back, and it is still worth twenty minutes of your time. In the US that means the FBI at IC3.gov and the FTC at ReportFraud.ftc.gov, while the UK routes everything through Action Fraud and most other countries run an equivalent national fraud line or CERT. Be careful about anyone who contacts you afterward offering to recover your funds. The FBI has warned that criminals impersonate IC3 itself to target people who have already lost money once.
Strengthen your security to prevent future attacks
Change the password on the account that was targeted, then change it everywhere else you reused it, which is usually more places than you would guess. Swap SMS codes for an authenticator app or a hardware key, since a code that can be read aloud can also be handed over and a hardware key cannot. Organizations should treat one successful call as a verdict on the process rather than the person, because attackers will run the same script on the next employee within days.
Defend Against Vishing With Group-IB Fraud Protection
While vishing may not be new, attackers constantly refine their methods, using artificial intelligence tools, spoofed numbers, and psychological manipulation to appear more legitimate than ever.
Group-IB’s Fraud Protection platform helps your company detect and mitigate vishing attempts in real time. It monitors unusual patterns such as:
- Repeated calls from suspicious numbers
- High-frequency interactions with customer support
- Spoofed caller’s identity
- Potential signs of account details takeover or fraudulent access
In addition to behavioral detection, Group-IB leverages threat intelligence to identify known vishing techniques and proactively block them before they impact your users and make them potential victims.
Want to learn how Group-IB can help your organization stay ahead of vishing and other advanced threats?
Speak to our experts to get a personalized walk-through of how Fraud Protection works and how it can make a real difference in your cybersecurity strategy.
