Vishing

Vishing, or voice phishing, is a type of phishing attack that takes place over the telephone. Bad actors use vishing attacks to steal sensitive information, which can then be used to carry out fraud or sold to other bad actors. 

Frequently asked questions

What type of information is commonly stolen through vishing attacks?

Vishing is perhaps most commonly associated with stolen financial information, such as bank account, debit card, credit card, and pin numbers. It can be used to steal any sensitive data that a bad actor might find valuable, including:

  • Identity information (Social Security numbers, ID numbers, dates of birth)
  • Log-in credentials (account numbers, user IDs, passwords, answers to security questions)

Stolen financial information can then be used to empty a bank account or make fraudulent purchases. Stolen identity information can be used to engage in identity theft or to skirt around identity verification measures. Stolen log-in credentials can also be used to take over an account.

How does vishing work?

In vishing attacks, victims are typically tricked into providing sensitive information to fraudsters. Fraudsters use many different techniques to achieve this goal, including:

  • Impersonation: The bad actor pretends to be someone that the individual knows, such as a friend, family member, coworker, or boss. AI-generated voices and other types of deepfakes are increasingly used to facilitate this.
  • Social engineering: The bad actor uses psychological manipulation to get the answers they are looking for, often by relying on social etiquette and norms that encourage individuals to answer their questions. This includes romance scams.
  • Caller ID spoofing: The bad actor changes their caller ID so that it appears the call is coming from a trusted source or individual — such as a utility company, bank, or government agency. This is often done to facilitate the strategies mentioned above. 
  • Automation: Vishing attacks are often carried out using automated systems, which don't require a live person to operate and which allows for much greater scale.

Ready to get started?

Get in touch or start exploring Persona today.