Human layer

What is Vishing?

Voice phishing turns a single trusted-sounding phone call into a breach. This is how vishing works, the real cases and the one habit that stops it.

Key takeaways
  • Vishing (voice phishing) is a social engineering attack by phone, where a criminal impersonates a trusted party to extract a credential, a code, an approval or a payment.
  • It is no longer just a consumer scam. The same technique is now used to breach companies, often by targeting the IT help desk.
  • Caller ID cannot be trusted. Attackers spoof numbers to look like your bank, a colleague or an internal line.
  • AI voice cloning has made calls more convincing, and the FBI and ENISA both flag AI-generated voices in vishing.
  • Phishing and spoofing, the family that includes voice phishing, was the most reported cybercrime type in the FBI’s 2024 report, with 193,407 US complaints.
  • A single help-desk vishing call caused about ten days of disruption at MGM Resorts and, by the company’s own account, cut about 100 million dollars from one quarter.
  • You cannot reliably spot a good voice clone by ear, so verification beats detection.
  • The one rule: verify any unusual or high-value request on a second known channel and never on the channel it arrived on.
  • Never read a one-time code or password to anyone who calls you, and never disable MFA.
  • In Sweden and the EU, security awareness training is a legal duty under NIS2 and Cybersäkerhetslagen, with boards personally accountable.

Vishing in Plain Terms

Vishing or voice phishing, is a social engineering attack carried out by phone. A criminal calls and impersonates someone the target trusts often IT support, a bank or a senior colleague to talk them into revealing a password or one-time code, approving a login or authorising a payment. The FBI notes that vishing now often uses AI-generated voices.

For years vishing was mostly a consumer scam, a fake call from the tax office or a bank. That has changed. The same technique is now used to break into companies because a person who trusts a caller can hand over the access that firewalls and filters are built to protect.

Three shifts made it worse. Remote work removed the in-person check of walking to a colleague’s desk. Attackers research their targets on LinkedIn before they call. And cheap AI voice tools can now clone a familiar voice from a short clip so the caller can sound like someone you know.

How Vishing Works

A vishing call needs two things, a believable pretext and pressure. The pretext is the story, for example that your account has been flagged or a payment needs urgent approval. The pressure is urgency and secrecy so the target acts before they check.

How Vishing Works

The number on your screen cannot be trusted. Attackers spoof caller ID so a call appears to come from a real bank, a colleague or an internal extension. In 2020 CISA and the FBI documented a campaign in which criminals began with internet-based phone numbers and then spoofed the numbers of the target’s own coworkers.

Many attacks pair the call with a fake website. In that same 2020 campaign the criminals registered look-alike domains and copied internal VPN login pages, then phoned remote staff posing as IT and walked them onto the fake page to capture their credentials.

Vishing got easier for practical reasons. internet calling makes spoofed calls nearly free. Public profiles hand attackers the names, roles and details that make a pretext convincing. And voice cloning, once specialist, is now a cheap online service which is why the FBI and ENISA both flag AI-generated voices in vishing today.

Types of Vishing Attacks

Vishing is a family of attacks that share one channel, the phone. These are the forms most likely to reach a business.

  • Help-desk vishing: The attacker phones your IT help desk posing as an employee and asks for a password or MFA reset, the route into the MGM Resorts breach.
  • IT-support pretext: The attacker phones an employee posing as internal IT and walks them onto a fake login page or asks for a code to fix a fake problem.
  • Finance and CEO fraud: The caller poses as a senior executive or supplier and pressures a finance worker to authorise an urgent payment or change bank details.
  • Bank and code interception: The caller poses as your bank’s fraud team and talks you into reading back the one-time code they have just triggered on your account.
  • SIM-swap enabled: The attacker first moves your phone number onto their own SIM, then uses calls and texts to defeat phone-based verification.
  • MFA-fatigue combos: An attacker who already has your password spams login prompts and calls posing as IT to talk you into approving one.
  • Consumer scams: Fake calls from the tax office, a delivery firm or a bank remain common and often rehearse techniques later aimed at businesses.

Business Impact

A vishing call rarely ends with the call. It is an entry point. One talked-out credential or one approved reset can hand an attacker the same access as a stolen laptop and from there the damage follows the familiar paths of ransomware, wire fraud and data theft.

The numbers are not small. MGM Resorts told investors that a help-desk vishing attack in 2023 cut about 100 million dollars from a single quarter’s results. At national scale the FBI’s 2024 Internet Crime Report recorded phishing and spoofing, the family that includes voice phishing, as the most reported cybercrime type in the United States, with 193,407 complaints.

There is a reporting cost too. A vishing intrusion that exposes personal data or disrupts an essential service triggers tight notification deadlines under Swedish and EU law and can place personal responsibility on the board.

Real-World Cases

The 2020 Twitter Takeover

On 15 July 2020 attackers phoned Twitter employees and claimed to be from internal IT. They persuaded staff to enter their logins on a look-alike page and then approve the multi-factor prompts that followed.

With that access the attackers took over about 130 high-profile accounts and posted a bitcoin scam. They stole roughly 118,000 dollars before it was stopped. Regulated cryptocurrency firms reacted quickly and blocked around 6,000 attempted transfers worth about 1.5 million dollars according to the New York State Department of Financial Services.

The regulator found Twitter had no chief information security officer and weak internal controls at the time. The attack unravels the moment an employee stops to call IT back on a number they already trust.

The 2023 MGM Resorts Shutdown

In September 2023 the group tracked as Scattered Spider found an MGM employee on LinkedIn and phoned the company’s IT help desk to request an account reset. That call handed the attackers administrative access to MGM’s identity system.

Ransomware from the ALPHV group followed and about ten days of disruption hit MGM’s casinos and hotels from slot machines to room keys. MGM later told investors the attack cut about 100 million dollars from its third-quarter results. It did not pay a ransom. Caesars, hit in the same period, reportedly paid about 15 million dollars.

CISA and the FBI who documented the group’s help-desk technique are blunt about the fix. A help desk should not reset a password or add an MFA device on the strength of answers a stranger can research. A callback to the employee’s manager or another out-of-band check before any reset closes the door this attack walked through.

The 2023 Retool Breach

On 27 August 2023, during a real migration of staff logins to a new identity provider, Retool employees received text messages posing as IT about an account problem. One employee clicked the link and entered their credentials and a code on a fake portal.

Then the phone rang. A caller posing as IT whose voice Retool says was cloned, talked the employee into sharing a further code which let the attacker register their own device.

A cloud-sync feature then exposed the team’s one-time codes and turned multi-factor authentication into a single factor. The attacker reached 27 cloud customers and reporting linked a theft of about 15 million dollars from Fortress Trust to the breach.

Retool’s own account points at the lesson. A one-time code should be typed into a login screen you opened, never read aloud to a caller. Phishing-resistant hardware security keys which cannot be relayed down a phone line or entered on a fake page would have stopped the takeover outright.

Vishing and Compliance

For organisations in Sweden and the EU, defending against vishing is increasingly a legal duty. That duty reaches the board and everyday staff behaviour, well beyond the IT team.

Under the EU NIS2 Directive, the basis for NIS2 compliance in Sweden, security awareness training is a required security measure set out in Article 21. Sweden transposed NIS2 through Cybersäkerhetslagen (SFS 2025:1506) in force on 15 January 2026.

Article 20 makes the management body responsible for approving and overseeing these measures and supervisory authorities can hold board members personally accountable. Fines reach up to 10 million euro or 2 percent of global turnover for essential entities.

If a vishing attack becomes a significant incident, the reporting clock is short. Affected organisations must send an early warning to the National Cybersecurity Centre (NCSC) through CERT SE within 24 hours, a full notification within 72 hours and a final report within one month. NCSC then forwards the report to the relevant sector authority

Where a vishing breach exposes personal data, GDPR compliance adds its own duty. Article 33 requires notification to the Swedish authority IMY within 72 hours of becoming aware of the breach.

Financial entities carry a further obligation. DORA compliance requires ICT incident management under Article 17 supervised by Finansinspektionen. Finance is one of the sectors vishing targets most.

The EU AI Act governs legitimate use of AI including a duty to label deepfake content. Criminals cloning a voice will ignore it so it shapes the wider landscape rather than serving as a control against vishing.

How to Spot Vishing

You cannot rely on the number on your screen, and a good voice clone can fool the ear. So the reliable signals are in how the call behaves rather than how it sounds.

How to Spot Vishing
  • Urgency and secrecy, a request that supposedly cannot wait or must be kept quiet.
  • Pressure to skip a normal payment, sign-off or verification step.
  • A request that arrives on an unusual channel such as a surprise call or a push to move to WhatsApp or Signal.
  • Any ask for a password, a one-time code or a payment which a real IT team or bank will not request by phone.
  • Reluctance to let you hang up and call back on a number you already hold.
  • Audio tells in a cloned voice such as lag, a flat tone or odd phrasing though these are not reliable on their own.

Treat every one of these as a prompt to verify. None of them clears a call on its own. The FBI’s own guidance is candid that AI-generated voices can sound nearly identical to a real contact so the safe response to any doubt is to stop and verify through a separate channel.

How to Defend Against Vishing

Stopping vishing takes people, process and technology working together. No single control is enough but a few habits and settings remove most of the risk.

People: build one verification habit.

  • Verify any unusual or high-value request on a second known channel before you act. Never use the channel the request arrived on.
  • Never read out a password or a one-time code to anyone who calls you for any reason.
  • Agree a code word for sensitive requests inside your team or family so an identity can be checked in seconds.

Process: make verification the default.

  • Require two people to authorise payments and supplier bank-detail changes above a set amount.
  • Give your IT help desk a strict identity check with no resets based on knowledge a stranger can find and a manager callback before any password or MFA change.
  • Apply least privilege so one talked-out credential cannot open the whole network.

Technology: remove the payoff.

  • Use phishing-resistant multi-factor authentication such as hardware security keys which cannot be relayed by phone or entered on a fake page.
  • Restrict VPN and administrator access to managed devices so a stolen credential alone is not enough.
  • Monitor for look-alike domains and unusual logins and keep the ability to roll changes back fast.

None of this depends on catching every clever call. It depends on a rule your people use without thinking, verify before you act, backed by controls that make a single mistake survivable. That habit is what training builds and keeps sharp.

Myths & Facts

Myth

Vishing is just old-fashioned phone scams aimed at pensioners.

If the caller ID shows a real number, the call is genuine.

I would recognise a fake voice.

Multi-factor authentication stops vishing.

Only careless employees fall for it.

This is an IT problem to solve with technology.

Fact

It targets businesses too. Attackers now phone IT help desks, finance teams and remote staff to steal credentials and authorise payments, as the MGM Resorts and Twitter breaches showed.

Caller ID is easy to spoof. Attackers routinely make calls appear to come from a real bank, a colleague or an internal extension, so the number proves nothing.

You probably would not. Cheap AI tools can clone a familiar voice from a short clip, and the FBI warns these can sound nearly identical to a real contact.

Not on its own. Vishing works by talking people into reading out the code or approving the prompt. Phishing-resistant hardware keys are the reliable backstop, because they cannot be read aloud or relayed.

Trained, senior people fall for it under pressure and a good pretext. The fix is a verification process everyone follows, which protects even people who are rushed.

It targets finance, HR and the help desk, and the core control is a human habit of verifying on a separate channel. Technology supports that habit. It does not replace it.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. You work on the IT help desk. A caller gives an employee's name and details from LinkedIn and asks you to reset their password and add a new MFA device, saying they are locked out before a big meeting.

    What do you do?

    • Reset it quickly so they make the meeting
    • Call the employee's manager or a known number to confirm first
    • Ask two more security questions, then reset
  2. Your phone rings. The caller says they are from your bank's fraud team, that a payment is being blocked, and that they have sent a one-time code you must read back to verify your identity.

    What is the safe response?

    • Read the code so they can stop the fraud
    • Hang up and call the bank on the number on your card
    • Give the code only after they confirm your account number
  3. A caller says they are from internal IT fixing an email outage and asks you to log in at a link they will send and approve the prompt that appears on your phone.

    What do you do?

    • Log in and approve the prompt to get email back
    • Decline, then contact IT through your normal internal channel
    • Log in, but only if the link looks like your company domain
  4. You handle payments. Your CEO calls, the voice sounds right, and asks you to rush a confidential payment to a new supplier today and keep it quiet until the deal is announced.

    What is the right move?

    • Pay it, since the voice and the story match the CEO
    • Follow the two-person approval process and verify on a known number
    • Pay a small amount now and the rest after checking

Knowledge Test

  1. What does vishing use to attack its target?

    • A phone call or voice message
    • A software vulnerability
    • An infected USB drive
    • A malicious email attachment

    Vishing is voice phishing, a social engineering attack carried out by phone or voice message.

  2. Why can you not rely on caller ID to trust a call?

    • Because numbers can be spoofed to look legitimate
    • Because caller ID is always blank
    • Because phones do not show numbers
    • Because only mobiles show caller ID

    Attackers routinely spoof caller ID so a call appears to come from a bank, colleague or internal line.

  3. Which control most reliably stops vishing that targets login codes?

    • Phishing-resistant hardware security keys
    • SMS one-time codes
    • A longer password
    • Antivirus software

    Hardware keys cannot be relayed over the phone or used on a fake page, unlike codes that can be read aloud.

  4. In the 2023 MGM Resorts attack, how did the criminals get in?

    • By phoning the IT help desk to get an account reset
    • By guessing an admin password
    • By a phishing email to the CEO
    • By exploiting unpatched software

    Scattered Spider used a help-desk vishing call to obtain access that led to a major ransomware outage.

  5. Under NIS2 and Sweden's Cybersäkerhetslagen, who can be held personally accountable for security measures?

    • The management body or board
    • Only the IT department
    • Only the external auditor
    • No one

    Article 20 makes the board responsible for approving and overseeing measures, with personal accountability.

  6. What is the single best habit against vishing?

    • Verify unusual requests on a second known channel before acting
    • Answer every call to stay responsive
    • Trust requests that sound urgent
    • Share codes quickly to resolve issues

    Verifying on a separate trusted channel defeats a caller relying on pressure and a convincing story.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Vishing is a human-layer attack, so the strongest defence is a workforce that knows the pattern and has a habit to fall back on. Most people have never rehearsed what to do when a confident caller asks for a code or a payment, and under pressure they default to being helpful.

Regular security awareness training changes that default. It teaches staff to expect the pretext, to pause on urgency and to verify on a separate channel before acting, and phishing simulations let them practise on safe, realistic calls and messages. In Sweden and the EU this is also a duty under NIS2 and Cybersäkerhetslagen.

eBuilder Security provides security awareness and phishing-simulation training that builds exactly this verification habit across finance, IT and the wider team.

Frequently Asked Questions

What is vishing (voice phishing)?

Vishing, or voice phishing, is a social engineering attack carried out over the phone. A criminal impersonates a trusted party such as IT support, a bank or a manager and uses a believable story and pressure to make the target reveal a password or code, approve a login or send a payment.

What is the difference between phishing, vishing and smishing?

All three are the same trick on different channels. Phishing arrives by email, smishing by text message and vishing by phone call or voice message. Vishing is often the most persuasive because a live human voice, now sometimes AI-cloned, adds pressure and trust that written messages cannot.

What is an example of a vishing attack?

In September 2023 attackers phoned MGM Resorts' IT help desk, posed as an employee and obtained an account reset that led to a major ransomware outage. The company later reported the incident cut about 100 million dollars from one quarter's results. The entry point was a single phone call.

Is vishing a social engineering attack?

Yes. Vishing is a form of social engineering, which means it manipulates people rather than exploiting software. Instead of breaking a system, the attacker uses trust, authority and urgency over the phone to talk a person into giving up access or money. That is why training and verification are the main defences.

How can I tell if a phone call is a vishing scam?

Watch how the caller behaves rather than trusting the number, because caller ID is easy to spoof. Be suspicious of urgency, secrecy, pressure to skip normal checks and any request for a password, a one-time code or a payment. A real bank or IT team will let you hang up and call back on a trusted number.

Does multi-factor authentication stop vishing?

Not by itself. Vishing works by talking people into reading out a one-time code or approving a login prompt, which defeats app and SMS-based MFA. Phishing-resistant hardware security keys are far stronger, because they cannot be relayed over the phone or used on a fake login page.

How do I protect my company from vishing?

Build one habit and back it with controls. Train staff to verify any unusual or high-value request on a second known channel, never share codes by phone and give the help desk a strict identity check before any reset. Add phishing-resistant MFA and least privilege so one mistake is survivable.

What should I do if I think I fell for a vishing call?

Act fast. Contact your IT or security team and your bank straight away using numbers you already trust. Change any exposed passwords, revoke active sessions and watch for further calls, because attackers often use one victim to reach others. Then report the incident to the relevant authorities.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.