Vishing
Vishing is phishing carried out by voice call. A caller impersonates a bank, a government agency, a technical support desk or a colleague, and persuades the target to disclose credentials, approve a transaction or move money. The channel adds something email cannot: a live human applying pressure in real time, adapting to every objection as it is raised.
| Name | A contraction of voice and phishing |
| Channel | Telephone — landline, mobile, or voice over IP |
| Common pretexts | Bank fraud department, tax authority, technical support, a senior colleague |
| Enabling technology | Caller ID spoofing, which is cheap and effective |
| Hybrid pattern | A text or email first, prompting the victim to call a number the attacker controls |
| What the channel adds | Real-time adaptation and interpersonal pressure |
| Recent escalation | Synthetic voice cloning of specific individuals |
| Frequent objective | A one-time code, a payment, or remote access to a device |
Why a live caller beats a written message
An email is fixed. A recipient can reread it, notice an oddity, forward it to a colleague, or simply close it and think. A phone call permits none of that.
The attacker adapts. Every objection gets an answer, tailored on the spot. A victim who says “this sounds like a scam” is met with agreement, reassurance, and an offer to have them call back on the number from their card — which the attacker does not disconnect from.
Time pressure is real rather than implied. Silence is uncomfortable on a call in a way it is not in an inbox, so the victim answers quickly rather than carefully.
Authority is easier to project. Caller ID spoofing displays the bank’s genuine number, and a confident caller using the right vocabulary supplies the rest. The victim is given no artifact to inspect.
Isolation is built into the script. The most effective versions instruct the victim to stay on the line, not to discuss the matter with branch staff, and to treat the call as confidential — which removes the intervention most likely to stop it.
The hybrid, and why it is the dominant form
Pure cold-calling is inefficient. The more effective pattern uses a written message to make the victim initiate the call.
A text or email reports a suspicious transaction and supplies a number. The victim, alarmed, dials it — and because they placed the call, the ordinary instinct to distrust an inbound caller is absent. They are already convinced something is wrong before anyone speaks.
This is why smishing and vishing are better understood as one technique with two stages than as separate categories. The message establishes the pretext; the call extracts the value.
Voice cloning changed the executive and family variants
Synthetic audio can reproduce a specific person’s voice from a small sample — a conference talk, an earnings call, a social media video. Two applications follow directly.
In an organizational setting this feeds CEO fraud: an urgent call from a voice the employee recognizes, requesting a transfer. The standard control — call the executive back to confirm — fails if the callback number was supplied by the attacker, and recognizing the voice is no longer evidence of anything.
The consumer variant targets families with a distressed relative claiming an emergency. It works because the voice is right and the emotional register removes deliberation.
The consequence for control design is specific: any process resting on recognizing a voice needs rebuilding around evidence rather than recognition. GenAI detection and deepfake analysis addresses the synthetic media; the process fix is out-of-band verification through a channel the recipient initiates independently.
Why this matters for identity verification
Vishing frequently ends at a control this glossary keeps returning to. A caller persuades a victim to read out a one-time code, and that code was the second factor — the relayable kind described under multi-factor authentication.
It is also the technique most often used against help desks rather than customers. An attacker calls support claiming to have lost their device, answers questions researched from public sources, and has the account reset. Recovery is designed to work for someone without their credentials, which is exactly the claim being made — and voice cloning now defeats the informal check of sounding like the right person.
Re-establishing identity there with an authenticated document and a live biometric asks for something a caller cannot talk their way past. That is where identity document verification touches this problem, and synthetic and stolen identity controls address what the access is used for.
What defenses can’t do
Caller ID proves nothing. Spoofing a displayed number is cheap, so the number on screen is not evidence of who is calling.
Training decays under pressure. People who can identify a phishing email in a classroom answer a convincing call differently, because the call gives them no time.
Call-back advice fails on a supplied number. The instruction only works if the number comes from an independent source — a card, a statement, the official site.
Voice recognition is no longer a control. Synthetic audio reproduces a specific person convincingly enough that familiarity is not verification.
Frequently asked questions
What is vishing?
Phishing carried out by voice call. The caller impersonates a bank, government agency, support desk or colleague and persuades the target to disclose credentials, approve a transaction or transfer money. The channel adds real-time adaptation and interpersonal pressure that written messages cannot.
Why is vishing more effective than email phishing?
Because the attacker adapts live. Every objection gets an immediate, tailored answer; silence is uncomfortable so the victim responds quickly rather than carefully; caller ID spoofing supplies apparent authority; and effective scripts instruct the victim to stay on the line and not discuss it with anyone.
What is hybrid vishing?
A text or email that prompts the victim to call a number the attacker controls. Because the victim placed the call themselves, the instinct to distrust an inbound caller is absent and they arrive already convinced something is wrong. It is now the dominant pattern.
Can voice cloning be used in vishing?
Yes. Synthetic audio can reproduce a specific person’s voice from a short public sample, which undermines both executive impersonation defenses and the family emergency scam. Any process that rests on recognizing a voice needs rebuilding around independently initiated verification.