Vishing in Plain Terms
Vishing or voice phishing, is a social engineering attack carried out by phone. A criminal calls and impersonates someone the target trusts often IT support, a bank or a senior colleague to talk them into revealing a password or one-time code, approving a login or authorising a payment. The FBI notes that vishing now often uses AI-generated voices.
For years vishing was mostly a consumer scam, a fake call from the tax office or a bank. That has changed. The same technique is now used to break into companies because a person who trusts a caller can hand over the access that firewalls and filters are built to protect.
Three shifts made it worse. Remote work removed the in-person check of walking to a colleague’s desk. Attackers research their targets on LinkedIn before they call. And cheap AI voice tools can now clone a familiar voice from a short clip so the caller can sound like someone you know.
How Vishing Works
A vishing call needs two things, a believable pretext and pressure. The pretext is the story, for example that your account has been flagged or a payment needs urgent approval. The pressure is urgency and secrecy so the target acts before they check.

The number on your screen cannot be trusted. Attackers spoof caller ID so a call appears to come from a real bank, a colleague or an internal extension. In 2020 CISA and the FBI documented a campaign in which criminals began with internet-based phone numbers and then spoofed the numbers of the target’s own coworkers.
Many attacks pair the call with a fake website. In that same 2020 campaign the criminals registered look-alike domains and copied internal VPN login pages, then phoned remote staff posing as IT and walked them onto the fake page to capture their credentials.
Vishing got easier for practical reasons. internet calling makes spoofed calls nearly free. Public profiles hand attackers the names, roles and details that make a pretext convincing. And voice cloning, once specialist, is now a cheap online service which is why the FBI and ENISA both flag AI-generated voices in vishing today.
Types of Vishing Attacks
Vishing is a family of attacks that share one channel, the phone. These are the forms most likely to reach a business.
- Help-desk vishing: The attacker phones your IT help desk posing as an employee and asks for a password or MFA reset, the route into the MGM Resorts breach.
- IT-support pretext: The attacker phones an employee posing as internal IT and walks them onto a fake login page or asks for a code to fix a fake problem.
- Finance and CEO fraud: The caller poses as a senior executive or supplier and pressures a finance worker to authorise an urgent payment or change bank details.
- Bank and code interception: The caller poses as your bank’s fraud team and talks you into reading back the one-time code they have just triggered on your account.
- SIM-swap enabled: The attacker first moves your phone number onto their own SIM, then uses calls and texts to defeat phone-based verification.
- MFA-fatigue combos: An attacker who already has your password spams login prompts and calls posing as IT to talk you into approving one.
- Consumer scams: Fake calls from the tax office, a delivery firm or a bank remain common and often rehearse techniques later aimed at businesses.
Business Impact
A vishing call rarely ends with the call. It is an entry point. One talked-out credential or one approved reset can hand an attacker the same access as a stolen laptop and from there the damage follows the familiar paths of ransomware, wire fraud and data theft.
The numbers are not small. MGM Resorts told investors that a help-desk vishing attack in 2023 cut about 100 million dollars from a single quarter’s results. At national scale the FBI’s 2024 Internet Crime Report recorded phishing and spoofing, the family that includes voice phishing, as the most reported cybercrime type in the United States, with 193,407 complaints.
There is a reporting cost too. A vishing intrusion that exposes personal data or disrupts an essential service triggers tight notification deadlines under Swedish and EU law and can place personal responsibility on the board.
Real-World Cases
The 2020 Twitter Takeover
On 15 July 2020 attackers phoned Twitter employees and claimed to be from internal IT. They persuaded staff to enter their logins on a look-alike page and then approve the multi-factor prompts that followed.
With that access the attackers took over about 130 high-profile accounts and posted a bitcoin scam. They stole roughly 118,000 dollars before it was stopped. Regulated cryptocurrency firms reacted quickly and blocked around 6,000 attempted transfers worth about 1.5 million dollars according to the New York State Department of Financial Services.
The regulator found Twitter had no chief information security officer and weak internal controls at the time. The attack unravels the moment an employee stops to call IT back on a number they already trust.
The 2023 MGM Resorts Shutdown
In September 2023 the group tracked as Scattered Spider found an MGM employee on LinkedIn and phoned the company’s IT help desk to request an account reset. That call handed the attackers administrative access to MGM’s identity system.
Ransomware from the ALPHV group followed and about ten days of disruption hit MGM’s casinos and hotels from slot machines to room keys. MGM later told investors the attack cut about 100 million dollars from its third-quarter results. It did not pay a ransom. Caesars, hit in the same period, reportedly paid about 15 million dollars.
CISA and the FBI who documented the group’s help-desk technique are blunt about the fix. A help desk should not reset a password or add an MFA device on the strength of answers a stranger can research. A callback to the employee’s manager or another out-of-band check before any reset closes the door this attack walked through.
The 2023 Retool Breach
On 27 August 2023, during a real migration of staff logins to a new identity provider, Retool employees received text messages posing as IT about an account problem. One employee clicked the link and entered their credentials and a code on a fake portal.
Then the phone rang. A caller posing as IT whose voice Retool says was cloned, talked the employee into sharing a further code which let the attacker register their own device.
A cloud-sync feature then exposed the team’s one-time codes and turned multi-factor authentication into a single factor. The attacker reached 27 cloud customers and reporting linked a theft of about 15 million dollars from Fortress Trust to the breach.
Retool’s own account points at the lesson. A one-time code should be typed into a login screen you opened, never read aloud to a caller. Phishing-resistant hardware security keys which cannot be relayed down a phone line or entered on a fake page would have stopped the takeover outright.
Vishing and Compliance
For organisations in Sweden and the EU, defending against vishing is increasingly a legal duty. That duty reaches the board and everyday staff behaviour, well beyond the IT team.
Under the EU NIS2 Directive, the basis for NIS2 compliance in Sweden, security awareness training is a required security measure set out in Article 21. Sweden transposed NIS2 through Cybersäkerhetslagen (SFS 2025:1506) in force on 15 January 2026.
Article 20 makes the management body responsible for approving and overseeing these measures and supervisory authorities can hold board members personally accountable. Fines reach up to 10 million euro or 2 percent of global turnover for essential entities.
If a vishing attack becomes a significant incident, the reporting clock is short. Affected organisations must send an early warning to the National Cybersecurity Centre (NCSC) through CERT SE within 24 hours, a full notification within 72 hours and a final report within one month. NCSC then forwards the report to the relevant sector authority
Where a vishing breach exposes personal data, GDPR compliance adds its own duty. Article 33 requires notification to the Swedish authority IMY within 72 hours of becoming aware of the breach.
Financial entities carry a further obligation. DORA compliance requires ICT incident management under Article 17 supervised by Finansinspektionen. Finance is one of the sectors vishing targets most.
The EU AI Act governs legitimate use of AI including a duty to label deepfake content. Criminals cloning a voice will ignore it so it shapes the wider landscape rather than serving as a control against vishing.
How to Spot Vishing
You cannot rely on the number on your screen, and a good voice clone can fool the ear. So the reliable signals are in how the call behaves rather than how it sounds.

- Urgency and secrecy, a request that supposedly cannot wait or must be kept quiet.
- Pressure to skip a normal payment, sign-off or verification step.
- A request that arrives on an unusual channel such as a surprise call or a push to move to WhatsApp or Signal.
- Any ask for a password, a one-time code or a payment which a real IT team or bank will not request by phone.
- Reluctance to let you hang up and call back on a number you already hold.
- Audio tells in a cloned voice such as lag, a flat tone or odd phrasing though these are not reliable on their own.
Treat every one of these as a prompt to verify. None of them clears a call on its own. The FBI’s own guidance is candid that AI-generated voices can sound nearly identical to a real contact so the safe response to any doubt is to stop and verify through a separate channel.
How to Defend Against Vishing
Stopping vishing takes people, process and technology working together. No single control is enough but a few habits and settings remove most of the risk.
People: build one verification habit.
- Verify any unusual or high-value request on a second known channel before you act. Never use the channel the request arrived on.
- Never read out a password or a one-time code to anyone who calls you for any reason.
- Agree a code word for sensitive requests inside your team or family so an identity can be checked in seconds.
Process: make verification the default.
- Require two people to authorise payments and supplier bank-detail changes above a set amount.
- Give your IT help desk a strict identity check with no resets based on knowledge a stranger can find and a manager callback before any password or MFA change.
- Apply least privilege so one talked-out credential cannot open the whole network.
Technology: remove the payoff.
- Use phishing-resistant multi-factor authentication such as hardware security keys which cannot be relayed by phone or entered on a fake page.
- Restrict VPN and administrator access to managed devices so a stolen credential alone is not enough.
- Monitor for look-alike domains and unusual logins and keep the ability to roll changes back fast.
None of this depends on catching every clever call. It depends on a rule your people use without thinking, verify before you act, backed by controls that make a single mistake survivable. That habit is what training builds and keeps sharp.


