A vishing attack is a targeted campaign against an organization: researched, rehearsed, and aimed at a specific payment process or set of credentials. That is a different animal from the opportunistic scam call that dials a million numbers hoping one person panics. The opportunistic call fails on volume; the targeted attack succeeds because it knows your context.

The four stages

Reconnaissance. Org charts, voice samples from public audio, and payment-process intel from breached mailboxes.

Pretext. A scenario explaining urgency and secrecy, matched to real company context — an acquisition, an audit, a vendor emergency.

Pressure. Time-boxing, authority, and channel control — keeping the victim inside the interaction.

Extraction. Payment, credentials, or a detail change; increasingly split across amounts and days to stay under thresholds and outside dual authorization.

Why phone-channel attacks beat email defenses

Twenty years of email filtering versus near-zero call filtering. Live pressure defeats reflection: there is no hovering over a link, no second read. Caller ID is spoofable and voices are clonable, so the two signals employees instinctively trust are exactly the two the attacker controls.

The corporate defense stack

  • Enforced callback verification on all payment-affecting requests — see the callback protocol template.
  • A no-exception executive culture.
  • Vishing simulations that measure verification behavior.
  • Real-time synthetic-voice scoring where channels allow.
Protocol tipAttackers rehearse the call. Your team shouldn't have to improvise the response — that's what a written, enforced protocol is for.