A vishing attack is a targeted campaign against an organization: researched, rehearsed, and aimed at a specific payment process or set of credentials. That is a different animal from the opportunistic scam call that dials a million numbers hoping one person panics. The opportunistic call fails on volume; the targeted attack succeeds because it knows your context.
The four stages
Reconnaissance. Org charts, voice samples from public audio, and payment-process intel from breached mailboxes.
Pretext. A scenario explaining urgency and secrecy, matched to real company context — an acquisition, an audit, a vendor emergency.
Pressure. Time-boxing, authority, and channel control — keeping the victim inside the interaction.
Extraction. Payment, credentials, or a detail change; increasingly split across amounts and days to stay under thresholds and outside dual authorization.
Why phone-channel attacks beat email defenses
Twenty years of email filtering versus near-zero call filtering. Live pressure defeats reflection: there is no hovering over a link, no second read. Caller ID is spoofable and voices are clonable, so the two signals employees instinctively trust are exactly the two the attacker controls.
The corporate defense stack
- Enforced callback verification on all payment-affecting requests — see the callback protocol template.
- A no-exception executive culture.
- Vishing simulations that measure verification behavior.
- Real-time synthetic-voice scoring where channels allow.