Vishing — short for voice phishing — is a social engineering attack conducted over a phone or voice call, in which an attacker impersonates a trusted person or institution to extract money, credentials, or sensitive information. Unlike email phishing, vishing exploits the urgency and trust inherent in live conversation. For how VerifyTheCall enforces this, see Vishing Protection.

Vishing meaning: why the voice channel works

Email gave defenders twenty years to build filters, banners, and training. The voice channel has almost none of that. A ringing phone carries implicit urgency; a familiar voice carries implicit trust. Attackers combine the two, and since 2023 they have added a third ingredient: AI voice cloning, which can reproduce a specific person's voice from a few seconds of public audio — an earnings call, a conference talk, a podcast.

That upgrade changed vishing from a consumer nuisance into an enterprise finance problem. The classic corporate variant is CEO fraud: a cloned executive voice calls a subordinate with an urgent, confidential payment request.

How a vishing attack works

  1. Reconnaissance. The attacker maps the org chart from LinkedIn and collects voice samples of an executive from public recordings.
  2. Pretext. They construct a plausible scenario — an acquisition deposit, a vendor emergency, a confidential legal matter — that explains both the urgency and the secrecy.
  3. The call. Often placed late in the day or before a holiday, frequently from a spoofed number matching the executive's real caller ID.
  4. The ask. A wire transfer, a change of vendor bank details, or credentials. Sophisticated attackers deliberately keep the amount below the company's dual-approval threshold.
  5. Follow-through. A confirming email from a lookalike domain often arrives minutes later to make the request feel documented.

Vishing examples

The patterns below recur constantly. Recognizing the shape matters more than memorizing any script.

  • The urgent executive wire. "I'm boarding a flight, I need this sent before close." Urgency plus seniority plus secrecy is the signature triad.
  • The fake bank fraud department. "We've detected suspicious activity — to secure your account, confirm your credentials." The attacker manufactures the emergency they claim to be solving.
  • The IT helpdesk reset. A call to an employee "from IT" requesting an MFA code — the entry point in several major breaches.
  • The vendor bank-detail change. A "supplier" calls accounts payable to update payment details ahead of a real, expected invoice — vishing's overlap with invoice fraud.

How to stop vishing

1. Out-of-band verification, enforced

The single most effective control is the callback: hang up and call the person back on a number you already have on file — never one supplied during the call. The catch is compliance. Every finance team has this policy; very few can prove it was followed on any given payment. Enforcement — holding the payment until the callback is logged — closes that gap. See how to prevent wire transfer fraud.

2. Real-time voice analysis

Synthetic-voice detection can score a live call for signs of AI generation. It is a strong early-warning layer on channels that permit audio access (conferencing platforms, contact centers), and it should be treated as a trigger for verification, not a replacement for it.

3. Remove the information advantage

Attackers rely on knowing your thresholds and procedures. Vary verification behavior, avoid publishing approval limits, and train teams that any payment request by voice — regardless of amount — routes through the same verification path.

Protocol tipThe most dangerous vishing request is the one sized to slip under your dual-approval threshold. If your callback rule only applies above $50,000, your real exposure is everything below it.