Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Vishing
Jan 31, 2026
5 Mins Read
Sep 13, 2026

What Is Vishing?

Vishing is phishing conducted through telephone or voice communication.

Attackers impersonate banks, support teams, government agencies, executives, or vendors and use urgency, caller-ID spoofing, account context, or voice cloning to obtain credentials, codes, payments, or remote access.

Key Takeaways

  • Bank and government impersonation is a central category or capability.
  • Reliable assessment requires identity, timing, source, and operational context.
  • Detection should correlate external, identity, device, network, and cloud evidence.
  • Response should preserve evidence and remove every reusable access path.
The main stages and decision points associated with vishing.
The main stages and decision points associated with vishing.

How Vishing Works

The sequence above provides a practical operating model. Individual stages may overlap, repeat, or involve different people and services, so analysts should validate each step against the available evidence.

Attackers impersonate banks, support teams, government agencies, executives, or vendors and use urgency, caller-ID spoofing, account context, or voice cloning to obtain credentials, codes, payments, or remote access.

Common Types and Techniques

  • Bank and government impersonation
  • Technical-support and remote-access fraud
  • Executive and vendor payment requests
  • OTP capture and voice-cloning scams

Security and Business Risks

  • Financial theft and account takeover
  • Remote-access malware installation
  • Business email compromise support
  • Identity theft and data disclosure
Common vishing risks paired with practical defensive controls.
Common vishing risks paired with practical defensive controls.

Warning Signs and Detection

Review call source cautiously, request context, recent account events, OTP generation, new payees, device enrollment, and remote-tool installation.

Prevention and Response

Never share passwords or codes, verify through a known official number, use phishing-resistant MFA, restrict remote tools, train staff, and require independent payment approval.

How SOCRadar Can Help

SOCRadar combines external visibility, threat intelligence, Dark Web monitoring, brand protection, vulnerability context, and indicator enrichment to help teams investigate exposure connected to vishing.

Explore SOCRadar Brand Protection or request a demo to strengthen threat-informed prevention and response.

Frequently Asked Questions

What Is Vishing and How Does It Differ From Email Phishing?

Vishing is phishing conducted through telephone or voice communication instead of email links or attachments. Attackers impersonate banks, support teams, government agencies, vendors, or executives and use live conversation, urgency, and spoofed caller identity to obtain credentials, one-time codes, payments, or remote access. Because there is no malicious link for email filters to catch, vishing often reaches targets that standard email defenses do not see.

What Role Does Caller-ID Spoofing Play in Vishing Attacks?

Caller-ID spoofing lets attackers display a trusted number, such as a bank’s support line or an internal office number, so the call appears legitimate at first glance. This false legitimacy lowers the victim’s guard and discourages callback verification. Treat displayed caller identity as unverified and confirm unexpected requests by calling the organization back on a known official number.

How Does Voice Cloning Change Modern Vishing Scams?

Voice cloning uses short audio samples, often taken from public recordings, to imitate an executive, colleague, or family member. Combined with context such as job titles, ongoing projects, and vendor relationships, cloned voices make urgent payment or credential requests far more convincing. Voice alone should not be treated as proof of identity, so verify requests through a separate, pre-established channel.

What Information Are Vishing Callers Trying to Obtain?

Common targets include account passwords, one-time passcodes (OTPs), payment approvals or new payee additions, personal details usable for identity theft, and agreement to install remote-access software. Some callers also walk victims through new device enrollments. Each outcome gives the attacker either a reusable access path or a direct route to funds.

What Warning Signs Suggest an Incoming Call Is a Vishing Attempt?

Frequent indicators include:

  • Unsolicited contact combined with urgency or threats of account suspension
  • Requests for passwords, OTPs, or payment approval during the call
  • Pressure to install remote-support or screen-sharing software
  • Claims of suspicious activity you cannot verify through your own account access
  • Reluctance to let you hang up and call back an official number

Any of these signs justifies ending the call and verifying the matter independently.

Which Account Events Should Security Teams Check After a Suspicious Call?

Review OTP generation and authentication logs, new device or MFA enrollments, newly added payees or changed payment rules, recent account or contact-detail updates, and remote-tool installations around the time of the call. Correlating these identity, device, and payment events with reported call timing helps confirm whether an attempt succeeded and how far the attacker progressed.

What Should Someone Do Immediately After a Suspected Vishing Call?

If credentials or codes were disclosed, reset the affected password and revoke active sessions where the platform supports it, since a password reset does not automatically terminate stolen sessions on every service. Contact the bank or provider through a known official number, report the incident internally, and preserve call records and related evidence. If remote-access software was installed, isolate the device for review before returning it to normal use.

Which Controls Reduce Vishing Risk Beyond Employee Training?

Phishing-resistant MFA such as FIDO2 security keys or passkeys resists OTP capture, restricting remote-administration tools to approved deployments limits remote-access fraud, and independent approval requirements for payments and new payees disrupt executive and vendor impersonation. Callback verification procedures add a further check. These controls reduce reliance on individual judgment under pressure, though no single measure removes the risk on its own.

How Does Vishing Support Business Email Compromise and Payment Fraud?

Vishing frequently supports business email compromise by harvesting mailbox credentials over the phone, after which attackers monitor correspondence and inject fraudulent payment requests by email. Attackers may also impersonate executives by voice to pressure finance staff into urgent transfers. The call builds the trust and urgency that the later email or payment step exploits.

Does Simply Answering a Vishing Call Compromise Your Device?

Answering a call by itself does not infect a device; compromise requires an action such as disclosing credentials, reading back an OTP, or installing software. Even a short conversation can confirm a number is active and reveal details attackers reuse in follow-up attempts. Hanging up on unsolicited requests for codes, payments, or access keeps that information out of the attacker’s hands.

How Is Vishing Related to Smishing?

Vishing uses voice calls, while smishing delivers phishing lures through SMS or other messaging apps. Attackers often chain the two, sending a text to establish context and following up with a call to extract codes or payment approval. Both rely on the same social-engineering core of impersonation plus urgency.