What Is Vishing?
Phishing usually involves emails, text messages, or fake sites that trick users into revealing sensitive information like bank details, passwords, or other data. Vishing is “Voice Phishing”, where scammers use fraudulent phone calls or voice messages to trick people into revealing information. Today’s post will go over what to look out for to avoid falling for a Vishing scam. Security: Vishing, the Latest Social Engineering Scam

Explaining Vishing
Vishing, or Voice Phishing, involves phone-based deception instead of an email or text message. The person doing the deception tries to impersonate someone that the victim trusts, like a family member, employer (HR, IT Department, Executive), bank, government agency, delivery service, or a major company’s tech support. This is done with the hope of gaining the victim’s confidence to get information out of them.
With the advancements in AI, realistic Vishing attacks are now very common. Some of the common tactics used
- Most everyone has received a call where you don’t hear anyone on the line. Human nature is to say “Hello”, “Hello, is anyone there”, or other comments of that type. The problem is that the other side may not be speaking but could be recording your voice. Then, AI could use your recorded voice to impersonate you to family members and claim you have been in an accident or are in jail and need money. I have directly had that happen to someone I know, who sent “bail” money for a family member that wasn’t actually in jail.
Another Vishing attack I have directly seen:
- Someone called a business and asked to speak with a department; once they got to that department, they claimed to be from HR and said they were calling to “confirm banking information to make sure direct deposit information was correct”.
Unfortunately, with the amount of information that is available online from data brokers, data breach information, and social media information you may post publicly, it isn’t that hard to have a foundation of information before a Vishing attack even starts.
What To Look Out For
Some of the common things seen in vishing attacks. The scammer
- Uses spoofed caller IDs and AI-generated recordings to sound legitimate.
- Tries to persuade users to share passwords, PINs, credit card/banking information, or other sensitive information.
- Tries to add a sense of urgency, pressuring the victim to act immediately
- Tries to get the user to access and log into a fake website sign-in page
- Tries to get the user to approve or provide information on a Multi-Factor Authentication (MFA). The code you get by text or app when trying to log in.
- Tells the victim that there will be consequences if they do not comply immediately.
Prevention Tips To Avoid Vishing
- Always avoid sharing sensitive information over unsolicited or unexpected calls.
- For family members, set up a “secret” word that isn’t shared with others. So, unless the caller knows the “secret” word, you can quickly figure out the call is fake.
- For business or legal calls, ask for their information and number, and tell them you will call them back. Then directly contact the business via official channels/numbers and confirm that the call you received is legitimate. Do not call back the number provided by the scammer.
- Stop and think before providing information. If something doesn’t feel right, it most likely isn’t.
- A BIG RED FLAG should be any call that involves urgent or threatening language. If they say that “if you don’t do what they say, you will be arrested or fired, that should tell you it’s a scam.
- If you realize you have fallen for a scammer, notify your bank and credit card companies immediately and also change all of your online account passwords. Notify your local law enforcement.
Final Thoughts
These tactics can happen to you as an individual or you as an employee. That makes it critical to stay alert, verify unexpected requests, and think before you share any information with any caller.
Vishing The Latest Social Engineering Scam







