Vishing
Vishing, short for voice phishing, is a scam that uses phone calls, voicemails, or automated robocalls to trick people into handing over personal or financial information. Criminals rely on social engineering, often pretending to be a trusted party, to persuade victims to share sensitive details. It is the voice-based counterpart to phishing (email) and smishing (text messages).
Vishing is a telephony-based social engineering attack in which a threat actor uses live phone calls, voicemail, or automated robocalls to manipulate a target into disclosing sensitive financial or personal information, or into performing actions that aid fraud. It exploits the historical perceived trustworthiness of voice channels and typically involves pretexting or impersonation of a trusted entity. Vishing is intended to harvest data that may enable downstream fraud such as account takeover; the specific information solicited and the effectiveness of any given campaign vary by scenario, and these attacks are distinct from but related to phishing and smishing.
Why it matters
Vishing exploits a channel that many people still perceive as inherently trustworthy. Because landline and voice services have historically been associated with legitimate institutions, targets may lower their guard when a caller claims to represent a bank, card issuer, or other trusted party. This makes voice-based social engineering an effective way for criminals to solicit sensitive financial and personal information that email or text-based approaches might not obtain as easily.
The information harvested through a vishing call can feed downstream fraud. Details disclosed during a call may help an attacker attempt account takeover or other unauthorized activity, which is why the technique is a concern for institutions that hold customer accounts and for the customers themselves. Vishing sits alongside phishing (email) and smishing (text) as part of a broader family of social engineering attacks, and defenders often need to address all three channels rather than treating voice as a lower-risk vector.
The effectiveness of any given vishing campaign varies by scenario, and the specific information solicited depends on the attacker's goal. Because these attacks rely on human manipulation rather than a single technical vulnerability, they can be difficult to fully eliminate through technical controls alone, and awareness among staff and customers remains an important part of any defense.
Who it's relevant to
Inside Vishing
Common questions
Answers to the questions practitioners most commonly ask about Vishing.