The examples below are the recurring shapes of vishing attacks. Scripts change daily; the shapes don't. Recognizing the pattern matters more than memorizing any wording.
- The urgent executive wire. A senior figure requests an immediate, confidential transfer. The red flags are authority, urgency and secrecy arriving together — and the amount is often sized under approval thresholds, the pattern described in CEO fraud.
- The bank fraud department. A caller claims your account is under attack and manufactures the emergency it claims to solve. The tell is the remedy: you are asked to "secure" the account by revealing credentials or moving money.
- The IT helpdesk MFA reset. A caller posing as internal support targets employees for one-time codes that defeat MFA. This pattern has been the entry point in several major breaches, and the red flag is any request for a code you did not initiate.
- The vendor bank-detail change. A supposed supplier calls accounts payable to update payment details, timed to precede a real expected invoice — the voice-channel form of invoice fraud. The tell is a detail change arriving by phone rather than through the vendor-master process.
- The government or tax agency call. Threat-based pressure: arrest, penalties, licence suspension. Payment is demanded in unrecoverable forms, and real agencies do not open with threats or improvised payment channels.
- The tech-support remote-access call. A caller reports a problem on your machine and offers to fix it. The red flag is the fix itself: it requires installing remote-control software that hands over the endpoint.
- The callback-baiting email or text. A message plants a phone number for a fake charge or subscription. The victim initiates the call and therefore trusts it — the inversion described in smishing vs vishing.
- The family-emergency voice clone. A cloned relative's voice in distress asks for money urgently, targeting individuals. The corporate variant clones a colleague, and the tell in both cases is refusal to be called back.
- The delayed second call. A follow-up "verification" call from a spoofed number references the first contact to build false continuity. The red flag is that the verification arrives from the same source as the request.
Every pattern above dies against the same control — end the inbound interaction and verify on a number you already hold. See call verification.