Attackers don’t always need malware or a software flaw to get past your controls. Sometimes a phone call and a helpful employee are enough.

What is Vishing?

Vishing, or voice phishing, is phone-based social engineering designed to persuade someone to bypass a normal security process.

No payload. No CVE. Just a conversation with whoever answers the phone.

That’s part of a broader shift toward identity-based attacks. Recent reporting backs this up: most observed activity in 2025 didn’t depend on malware. Attackers go after valid accounts, trusted sessions, and normal administrative processes instead, because those paths draw less attention than malicious software.

Vishing works because attackers borrow trust, urgency, and authority. The caller is an employee locked out of an account, an executive facing a deadline, a vendor trying to close a support ticket.

Every version of the story has the same purpose: make the request sound routine enough that the person on the phone acts before verifying who’s calling.

AI Voice Cloning Makes Verification Harder

Vishing has grown well past a niche tactic. Industry reporting measured a 442% increase in vishing activity between the first and second halves of 2024. 1 Later reporting showed the technique still climbing, through help desk impersonation and callback-based attacks.

Recent financial-sector reporting linked a highly active criminal group to repeated vishing operations. The group used phone-based social engineering to get into business environments, then sold some of the access to ransomware operators.

That’s the business risk. One successful call can lead to a compromised account, access to internal systems, and an entry point an attacker uses later for extortion or ransomware.

AI makes impersonation easier. An attacker doesn’t need to imitate an executive or employee unassisted anymore. A credible script, some public information, and a bit of recorded audio are enough to produce a convincing synthetic voice.

The FBI has warned that AI-generated voices now sound believable enough to make voice recognition unreliable. Research and timing still matter. But hearing a familiar voice no longer counts as proof of identity.

How an Authorized Vishing Assessment Works

Before the first call, penetration testers study the target the same way a real attacker would, using Open-Source Intelligence (OSINT).

They review employee roles, office locations, company terminology, support procedures, and public details that feed a believable story. An early call asks harmless questions to learn how the help desk identifies callers. A later call uses those answers to test whether the process allows a password reset, MFA replacement, or a new device enrollment.

The staged approach matters. It shows where verification procedures hold, and where small pieces of information add up to a bigger weakness.

CISA has documented attackers using this exact pattern against help desks. Early contacts taught them the support procedures. Later calls used those details to compromise accounts and move MFA enrollment to devices under attacker control.

Five Controls That Reduce Vishing Risk

  1. Call back using a trusted number. When someone requests a password reset or account change, end the call. Contact the employee using a number stored in company records. Never use a number supplied by the caller and never treat caller ID as proof.
  2. Limit what one help desk agent approves. No single agent should reset a password, replace an MFA factor, or enroll a new device based on one call. Sensitive changes need verification through a separate company-controlled channel.
  3. Adopt phishing-resistant MFA. FIDO2 and WebAuthn cut out the reusable codes and approval prompts attackers rely on. Account recovery and MFA replacement still need strict procedures, because that’s exactly where attackers turn next.
  4. Treat every voice as unverified. Confidence, familiarity, and knowledge of internal terminology aren’t dependable identity signals anymore. Confirm sensitive requests through another channel, no matter how legitimate the caller sounds.
  5. Test, don’t just train. Training explains the procedure. Testing shows whether employees follow it under pressure. Simulated vishing calls expose weak processes before an attacker finds them.

Test the Process Before Someone Else Does

Vishing works because people want to help. That instinct is worth protecting, not training out of your staff.

Build verification procedures that don’t depend on someone catching a fake voice in real time. Then test those procedures yourself, through an authorized vishing assessment, before an attacker puts your help desk to the same test.

References