Skip to main content
Category: Fraud Typologies

Vishing

Also known as: Voice phishing
Simply put

Vishing, short for voice phishing, is a scam that uses phone calls, voicemails, or automated robocalls to trick people into handing over personal or financial information. Criminals rely on social engineering, often pretending to be a trusted party, to persuade victims to share sensitive details. It is the voice-based counterpart to phishing (email) and smishing (text messages).

Formal definition

Vishing is a telephony-based social engineering attack in which a threat actor uses live phone calls, voicemail, or automated robocalls to manipulate a target into disclosing sensitive financial or personal information, or into performing actions that aid fraud. It exploits the historical perceived trustworthiness of voice channels and typically involves pretexting or impersonation of a trusted entity. Vishing is intended to harvest data that may enable downstream fraud such as account takeover; the specific information solicited and the effectiveness of any given campaign vary by scenario, and these attacks are distinct from but related to phishing and smishing.

Why it matters

Vishing exploits a channel that many people still perceive as inherently trustworthy. Because landline and voice services have historically been associated with legitimate institutions, targets may lower their guard when a caller claims to represent a bank, card issuer, or other trusted party. This makes voice-based social engineering an effective way for criminals to solicit sensitive financial and personal information that email or text-based approaches might not obtain as easily.

The information harvested through a vishing call can feed downstream fraud. Details disclosed during a call may help an attacker attempt account takeover or other unauthorized activity, which is why the technique is a concern for institutions that hold customer accounts and for the customers themselves. Vishing sits alongside phishing (email) and smishing (text) as part of a broader family of social engineering attacks, and defenders often need to address all three channels rather than treating voice as a lower-risk vector.

The effectiveness of any given vishing campaign varies by scenario, and the specific information solicited depends on the attacker's goal. Because these attacks rely on human manipulation rather than a single technical vulnerability, they can be difficult to fully eliminate through technical controls alone, and awareness among staff and customers remains an important part of any defense.

Who it's relevant to

Fraud analysts and merchant risk teams
Vishing can be a precursor to account takeover and other fraud, since information gathered on a call may later be used to access accounts. Understanding how voice-based social engineering feeds downstream fraud helps analysts recognize patterns that originate outside their own systems.
Acquirers, issuers, and payment processors
Because attackers frequently impersonate banks, card issuers, and other trusted financial parties, institutions that hold customer accounts are common subjects of impersonation. This makes customer awareness and clear communication about how the institution will and will not contact customers relevant to reducing exposure.
Security and compliance teams
Vishing is one of a family of social engineering channels that also includes phishing and smishing. Teams responsible for security awareness and staff training should account for voice-based attacks alongside email and text-based ones rather than focusing on a single channel.
Customer-facing and support staff
Employees who handle calls may themselves be targets of pretexting or impersonation aimed at extracting information or triggering actions. Awareness of how these attacks are structured helps staff apply caution when a caller requests sensitive details or urgent action.

Inside Vishing

Voice-based social engineering
Vishing (voice phishing) is a social engineering attack conducted over telephone or voice channels in which an attacker impersonates a trusted party to manipulate a target into disclosing information or taking an action. It relies on human deception rather than a technical exploit.
Pretexting and impersonation
Attackers construct a plausible scenario, such as posing as a card issuer's fraud department, an acquirer, a payment processor, a bank, or internal support staff, to establish false trust and create urgency that pressures the target into complying.
Targeted data
Vishing may attempt to elicit cardholder data such as the PAN, cardholder name, and expiration date, and frequently targets sensitive authentication data such as CAV2/CVC2/CVV2/CID and PINs. Sensitive authentication data must not be stored after authorization even when encrypted, so its exposure through vishing is a direct account-compromise risk.
Delivery techniques
Vishing can use live callers, automated robocalls or interactive voice response prompts, and caller ID spoofing to make the calling number appear legitimate. It is often combined with other channels such as phishing emails or smishing text messages in a multi-step campaign.
Relationship to fraud outcomes
Information obtained through vishing can enable downstream fraud, including account takeover and card-not-present fraud. Vishing is the social-engineering vector; the resulting fraud type and applicable chargeback or liability rules depend on card brand and network rules, which vary by region and change over time.

Common questions

Answers to the questions practitioners most commonly ask about Vishing.

Is vishing just phishing conducted over the phone?
Not exactly. While both are social engineering attacks aimed at obtaining sensitive information, vishing specifically uses voice communication channels such as telephone calls or voice messages, often leveraging techniques like caller ID spoofing and urgency-based pressure that are distinct to voice interactions. The channel matters because voice interactions can bypass some technical email controls and exploit the perceived trust of a live conversation. Treating vishing as identical to email phishing may lead teams to overlook channel-specific detection and awareness controls.
Does answering a vishing call safely mean my cardholder data is protected as long as I don't read out my full PAN?
No. Vishing attacks may target more than the primary account number. Attackers may attempt to elicit sensitive authentication data such as the card verification value (CAV2/CVC2/CVV2/CID) or PIN-related information, as well as other cardholder data like the expiration date or cardholder name, and account credentials that enable account takeover. Because sensitive authentication data must not be captured or retained improperly, disclosing any of these elements over a voice channel can facilitate fraud even without a full PAN. Any disclosure of authentication elements or credentials can be enough to enable misuse.
How can an organization reduce the risk of vishing succeeding against its staff and customers?
Layered controls are intended to help reduce vishing success rates. These commonly include staff and customer awareness training focused on voice-based social engineering, defined verification procedures that do not rely solely on information an attacker could obtain, call-back procedures using independently verified numbers, and clear internal policies stating what information will never be requested by phone. No single control eliminates the risk, and effectiveness depends on consistent application and periodic reinforcement.
What verification practices help when handling inbound calls that request sensitive information?
Practices that may mitigate vishing include authenticating callers through methods that do not expose or rely on the very data being protected, avoiding disclosure of cardholder data or authentication elements during unsolicited or unverified calls, and using independent call-back to a known-good number rather than a number provided by the caller. Organizations should also define escalation paths for suspicious calls. These measures reduce but do not remove the possibility of a successful attack, and they should be validated against the organization's own risk profile.
How does vishing relate to PCI DSS scope and controls?
Vishing intersects with PCI DSS to the extent that voice channels or personnel handling account data are involved in the capture, transmission, or storage of cardholder data. Relevant control areas commonly include security awareness training and policies governing how account data is handled, though requirement numbering and wording differ between PCI DSS versions and should be confirmed against the current published standard. Where phone-based order-taking or call center operations touch cardholder data, those environments may fall within scope, and organizations should assess this based on their specific data flows rather than assuming vishing is out of scope.
How can vishing attempts be detected or monitored operationally?
Detection of vishing typically relies on a combination of staff reporting mechanisms, monitoring for patterns such as repeated calls seeking account data or credentials, and correlating suspected social engineering with downstream indicators like account takeover attempts. Because voice channels offer limited automated signals compared with email, detection often depends heavily on trained personnel recognizing and reporting suspicious calls. This approach carries trade-offs, including potential false negatives when attacks are convincing and false positives when legitimate calls are flagged; effectiveness depends on reporting culture and process maturity.

Common misconceptions

A verified or matching caller ID confirms the caller is genuine.
Caller ID can be spoofed, so a familiar or official-looking number does not authenticate the caller. Displayed numbers should not be treated as proof of identity.
Multi-factor authentication or 3-D Secure makes vishing irrelevant.
These controls address different points in a transaction and are intended to reduce specific risks, not eliminate social engineering. A victim who is manipulated into reading back a one-time code or authentication data over the phone can undermine those controls, so no single control prevents vishing-enabled fraud.
Vishing is only a consumer problem and is out of scope for payment security programs.
Vishing also targets employees at merchants, acquirers, and processors to obtain credentials or access. Because it can lead to exposure of cardholder data or sensitive authentication data, it is relevant to security awareness and access controls, though the specific PCI DSS requirements and their numbering should be confirmed against the current published standard.

Best practices

Train staff and inform cardholders that legitimate issuers, processors, and internal teams will not request full sensitive authentication data such as CVV2/CVC2/CID or PINs over the phone, and that such requests should be treated as suspicious.
Establish call-back verification procedures using independently obtained contact numbers rather than any number provided by or displayed during the inbound call, since caller ID may be spoofed.
Define and enforce out-of-band identity verification for any request that would expose cardholder data, grant access, or change account or payment details, so a single phone conversation cannot authorize sensitive actions.
Reduce the value of any data an attacker could extract by minimizing what agents can view, applying masking or truncation where appropriate, and confirming that sensitive authentication data is never stored after authorization.
Deploy detection and reporting channels so employees can quickly flag suspected vishing attempts, recognizing that awareness controls reduce but do not guarantee elimination of successful attacks and involve trade-offs between missed reports and false alarms.
Correlate suspected vishing with downstream fraud monitoring for account takeover and card-not-present activity, and apply chargeback and liability handling according to the current, region-specific card brand and network rules.