Skip to content

Vishing: Voice Phishing Attacks and How to Defend

What vishing is, how attackers use phone calls and AI voice cloning to bypass technical defences, the real-world attacks that start with a call, and how to defend.

Invadel TeamAugust 27, 20265 min read

Vishing , voice phishing , is social engineering conducted over the phone. Where email phishing sends a message, vishing makes a call, and that change of channel is precisely the point: a phone call bypasses every email filter you own and exploits something no software patches, which is a person’s instinct to be helpful to a voice on the line.

It is one of the most effective techniques in a real attacker’s toolkit, and one of the least defended, because most security spending goes to the inbox and almost none to the phone.

Why the phone is such an effective channel

Three things make voice uniquely dangerous:

It defeats your technical stack. Email security has matured , filters, authentication, link analysis. A phone call has none of that between the attacker and your employee. There is no spam folder for a ringing phone.

It is real-time and high-pressure. Email gives a target time to think and check. A live call does not. A skilled caller manufactures urgency , “I need this before the system locks in five minutes” , and works the target through the decision before doubt can form.

It carries built-in trust. A human voice, especially one that is calm, confident, and armed with a few true details about you, is instinctively more credible than text. We are wired to cooperate with a person who sounds like they belong.

How a vishing attack actually runs

A competent vishing call is rehearsed, not improvised:

Research first. The same OSINT that powers spear phishing , names, roles, vendors, recent events , so the caller can drop real details that establish legitimacy in the first ten seconds.

A pretext with authority or helpfulness. The two reliable frames are authority (“this is IT security, we’ve detected a problem with your account”) and helpfulness (“I’m the new person in finance and I’m stuck, can you help me?”). Both bypass scrutiny , one through deference, the other through goodwill.

Caller ID spoofing. The number shown is trivially faked to display your own IT department, a known vendor, or a local number. The display cannot be trusted, but almost everyone trusts it.

The extraction. The goal is a password, a multi-factor code read aloud, a “click this link I’m sending you now,” or an action , resetting a credential, approving a request. The MFA-code-over-the-phone attack is especially common: the attacker already has the password, triggers the login, and calls to talk the victim into reading back the six-digit code.

The AI escalation , voice cloning

This has moved from theory to reality. A few seconds of someone’s recorded voice , from a conference talk, a podcast, a webinar, a voicemail greeting , is now enough to clone it convincingly. That enables an attacker to place a call that sounds like your CEO instructing a finance employee to process an urgent transfer. Combined with a spoofed number and a plausible pretext, it is extraordinarily persuasive, and it has already produced multi-million-dollar losses. Any current defence has to assume the voice itself can be faked.

The help desk is the soft target

The single most-attacked point is the IT help desk, and the reason is structural: help desks exist to be helpful, are measured on speed and resolution, and are staffed to say yes. An attacker calls posing as a locked-out employee and asks for a password reset or an MFA re-enrolment. If identity verification is weak , “what’s your employee ID?” , the attacker who did their OSINT passes it. This is how several major breaches began: not with malware, but with a convincing call to a help desk that reset the wrong person’s access. Testing this specific path is one of the highest-value things an assessment can do.

How vishing is tested

Authorised vishing is a component of social engineering penetration testing and red team engagements. Testers place controlled calls using realistic pretexts against agreed targets , frequently including a scripted attempt against the help desk , and measure what information is given up and which verification steps hold. The output is concrete: where your people and processes yield to a voice, and exactly which scripts got through. Because it exercises the channel your email defences never touch, it routinely surfaces risk that inbox-focused testing misses entirely.

How to defend against it

Vishing is defended with process and training, not products:

  • Verification procedures that do not rely on caller ID , a call-back to a known internal number, or an out-of-band confirmation, before anything sensitive is done.
  • Hardened help-desk identity checks , strong, consistent verification before any password reset or MFA change, with no exception for a caller who sounds senior or urgent. This is the highest-priority fix.
  • A “never read codes aloud” rule , no MFA code or password is ever spoken on a call, full stop. Make it a bright line everyone knows.
  • Phishing-resistant MFA , FIDO2 security keys and passkeys cannot be phished over the phone the way a one-time code can.
  • Training that includes voice , most awareness programmes cover email and stop there. Staff need to know the phone is an attack channel, that a voice can be cloned, and that ending a suspicious call to verify is always acceptable.

The short version

Vishing attacks the phone line your email security cannot protect, using real-time pressure, a trustworthy human voice, and spoofed caller ID , now amplified by AI voice cloning that can convincingly impersonate your executives. The help desk is the favourite target because it is built to be helpful. The defences are procedural: caller-ID-independent verification, hardened help-desk identity checks, a firm rule against reading codes aloud, and phishing-resistant MFA. And the only way to know your defences hold is to have someone call and try.

Want to know whether a well-researched phone call would get past your people and your help desk? A controlled vishing test is part of every social engineering assessment we run. Scope one here.

Written by

Invadel Team

Senior penetration testers writing from real engagements — the same team that scopes, tests, and reports for our clients. About Invadel →

All articlesRed Teaming

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire?
Start the conversation