Vishing (Voice Phishing)
Learn how vishing (voice phishing) works, how to spot fraudulent phone calls impersonating banks, government agencies, and tech support, and how to protect yourself. Includes real-life examples, warning signs, and expert safeguarding tips.
Overview
What is vishing?
Vishing — a blend of "voice" and "phishing" — is a form of fraud carried out over the phone. A scammer calls you, or tricks you into calling them, while posing as a representative from a trusted institution: your bank's fraud team, HMRC or the IRS, a police officer, Microsoft technical support, or even your own employer's IT helpdesk. The goal is to persuade you to hand over sensitive information, transfer money, or grant remote access to your device — all while believing you are speaking with someone legitimate.
Unlike phishing emails or smishing texts, vishing is a human interaction. A real voice — increasingly replaced or augmented by AI-generated audio — creates a level of perceived authenticity that written messages cannot match. Scammers are skilled conversationalists trained to read your reactions, deflect scepticism, and steer the call toward their objective.
The most common scenarios involve a caller claiming your bank account has been compromised and must be urgently secured, a government agency threatening legal action or arrest for unpaid tax, or a tech support agent warning that your computer is infected and offering to fix it remotely. In each case, urgency, authority, and fear do the work that malicious code cannot.
Who is targeted: Anyone with a phone — but older adults, small business owners, and employees with access to financial systems are disproportionately affected. Vishing does not require the victim to click anything or download software; a convincing voice and a plausible story are often enough.
Why it works: A phone call feels real in a way a text or email does not. The presence of another person — their tone, their apparent knowledge of your details, their professional language — activates social compliance instincts that are difficult to override in the moment.
Scale & Statistics
How common is this scam?
Vishing has become one of the fastest-growing and most financially damaging forms of fraud, particularly as AI voice technology makes impersonation cheaper and more convincing than ever.
- $2.95 billion in losses were reported from phone fraud in the United States in 2023, according to the FTC — the largest single source of financial fraud loss that year
- 1 in 3 adults in the US reported receiving a suspected vishing call in 2024
- 68.4 million Americans reported losing money to phone scams in 2023, according to TrueCaller's annual US Spam & Scam Report
- $1,480 was the median individual loss from a phone scam in 2023 — more than three times higher than losses from email-based fraud
- AI voice cloning tools can now replicate a person's voice from as little as three seconds of audio, with multiple commercially available services costing under $10 per month
- Authorised push payment (APP) fraud — in which vishing convinces victims to transfer funds themselves — accounted for £460 million in losses in the UK in 2023 alone
- 85% of organisations reported experiencing vishing or phone-based social engineering attacks in 2024, up from 54% in 2021
Most affected demographics: adults aged 60 and over, small business owners, employees in finance or HR roles, and anyone who has recently experienced a data breach notification.
Sources: FTC Consumer Sentinel Network Data Book 2024; TrueCaller US Spam & Scam Report 2024; UK Finance Fraud Report 2024; Proofpoint State of the Phish 2024; Hiya Global Call Threat Report 2024
How It Works
How does it work?
Modern vishing attacks range from simple scripted cold calls to elaborately orchestrated multi-stage operations involving spoofed caller IDs, AI-generated voices, and coordinated teams of scammers working in shifts.
-
The scammer identifies a target and cover story — Targets are selected using data from breaches, purchased lead lists, or social media profiling. A cover story is chosen based on what will seem most plausible and urgent — bank fraud, an overdue tax bill, a virus alert, or a compromised national insurance or social security number.
-
The caller ID is spoofed — Using widely available VoIP tools, the scammer masks their real number and displays the genuine phone number of the bank, government agency, or company they are impersonating. The victim's phone shows a number that appears to be legitimate.
-
The call is made — The scammer calls the victim and delivers a rehearsed script designed to establish authority and create urgency. They may already know the victim's name, address, partial card number, or bank name — details harvested from previous breaches — which are used to establish false credibility.
-
Trust is built and resistance is lowered — The scammer guides the victim through a plausible narrative. A "bank fraud officer" walks the victim through "security steps." A "tax agent" explains the legal consequences of non-payment. A "tech support engineer" describes the infection on the victim's computer and offers to connect remotely.
-
The extraction takes place — The victim is persuaded to provide one-time passcodes (OTPs), full card or account details, online banking credentials, or remote access to their device via tools such as AnyDesk or TeamViewer. Alternatively they are instructed to transfer funds to a "safe account" controlled by the scammer.
-
Funds are moved or data is exploited — Money is transferred immediately through multiple accounts to prevent recovery. Credentials are used to access accounts in real time while the call is still in progress.
Platforms and tools commonly used: VoIP spoofing services, AI voice cloning software, remote desktop tools (AnyDesk, TeamViewer), prepaid SIM cards, and call centre infrastructure operated in organised crime hubs.
Recent variations in 2024–2025:
- AI voice cloning scams use audio harvested from social media videos or voicemails to impersonate a family member in distress — the so-called "grandparent scam" is now routinely executed with cloned voices
- Callback vishing (telephone-oriented attack delivery, or TOAD) begins with a phishing email containing a fake invoice or security alert and a phone number to call — directing the victim to initiate the call themselves, which bypasses suspicion and many spam filters
- Multi-operator fraud rings employ teams where one caller establishes contact and a supposed "senior manager" or "police officer" is brought in to reinforce authority and override resistance
- Deep fake audio in corporate fraud has been used to impersonate CFOs and senior executives in calls authorising large wire transfers, with documented cases in 2024 involving losses exceeding $25 million in a single incident
Psychological Tactics
What psychological tactics are used?
Vishing is among the most psychologically sophisticated forms of fraud because it operates in real time, with a human (or human-sounding) voice that can adapt to the victim's responses, overcome objections, and escalate pressure on demand.
| Tactic | How it is used |
|---|---|
| Authority | Impersonating a bank fraud officer, police detective, tax inspector, or senior IT engineer creates an automatic compliance instinct. Uniforms and titles command obedience even when invisible. |
| Urgency | "Your account is being drained right now." "A warrant will be issued if you do not pay within the hour." Artificial time pressure prevents the victim from pausing, consulting others, or verifying the call independently. |
| Fear | Threats of arrest, account closure, criminal charges, or computer infection activate a stress response that narrows attention and overrides critical judgement. |
| False validation | Scammers recite personal details — your name, address, partial account number, recent transactions — obtained from data breaches. Hearing accurate information about yourself makes the caller seem legitimate. |
| Isolation | Victims are told not to discuss the matter with anyone — including family members or bank staff — under the pretence of an active investigation or security protocol. This removes the most effective safeguard: a second opinion. |
| Reciprocity and rapport | Callers are trained to be friendly, patient, and helpful. A scammer who spends twenty minutes "helping" you feels harder to distrust or disconnect from than one who is abrupt. |
| Escalation | If initial resistance is encountered, a "supervisor," "police officer," or "senior fraud investigator" is introduced to reinforce authority and increase pressure. |
The defining vulnerability of vishing is that it happens in real time. Unlike a phishing email, which you can close and revisit later, a phone call compresses the entire deception into a single continuous interaction. The scammer controls the pace, the narrative, and the social cost of hanging up.
Real-Life Example
A real-life case
Case: AI-generated voice used to authorise $25 million wire transfer in multinational corporate vishing attack (2024)
In early 2024, a finance employee at a multinational firm based in Hong Kong was contacted and invited to join a video call with colleagues including the company's UK-based CFO to discuss a confidential financial transaction. Every participant on the call — including the CFO — appeared and sounded authentic. The employee, reassured by the familiar faces and voices, authorised a series of transfers totalling approximately $25 million (HKD 200 million) to accounts specified during the call.
The video call was subsequently discovered to be entirely fabricated. Every participant except the victim was a deepfake — AI-generated audio and video constructed using publicly available footage and recordings of the real executives. The fraud was only identified when the employee later contacted head office to confirm the transaction through an independent channel.
The outcome: Hong Kong police confirmed the case publicly in February 2024 and made several arrests, but the transferred funds were not recovered. The attack demonstrated that vishing has evolved far beyond scripted cold calls — it can now involve real-time AI impersonation of known, trusted individuals, eliminating the most reliable defence: recognising a familiar voice.
Source: Hong Kong Police Force press conference, February 2024; CNN, "Finance worker pays out $25 million after video call with deepfake CFO," February 2024; Reuters, February 2024
Red Flags to Watch
Red flags to watch for
- The caller claims to be from your bank, a government agency, law enforcement, or a tech company and asks you to act immediately to prevent a serious consequence
- The phone number appears to match a legitimate organisation, but the caller asks for information that organisation would never request by phone — such as a one-time passcode, full PIN, or online banking password
- You are told not to hang up, not to contact the organisation via any other channel, and not to discuss the matter with anyone else — framed as a security or investigation requirement
- The caller asks you to transfer money to a "safe account," purchase gift cards, or withdraw cash and hand it to a courier — no legitimate bank, government body, or tech company will ever request this
- A voice or video caller you believe you know is asking for an unusual favour involving money or account access, especially if contacted unexpectedly or from an unfamiliar number
- The caller uses your personal details — name, address, bank name — to establish trust, but then asks for additional sensitive information your bank already holds
- You are pressured not to end the call while "the matter is being resolved" — legitimate organisations will always allow you to call back independently
- A tech support caller claims your computer is infected and asks you to download remote access software to allow them to fix it
How to Identify
How to identify a vishing call
Ask yourself before acting:
- Did I initiate this call, or did it arrive without warning?
- Would this organisation really call me and ask for this information — especially a passcode, PIN, or request to move money?
- Can I verify this independently by hanging up and calling the organisation back on a number I find myself?
Verification steps:
- Hang up and call the organisation back using a number from their official website, the back of your bank card, or a previous genuine letter — never a number given by the caller.
- Wait several minutes before calling back if using the same phone line; some scammers keep the line open after you hang up so the next call you make is still to them.
- If the caller claims to represent a government agency, look up the agency's official contact number independently and call to confirm whether any action is genuinely outstanding on your account.
- Never share a one-time passcode (OTP) over the phone — your bank will never ask for this. An OTP is a verification code for you, not for the organisation contacting you.
- If asked to download software or grant remote access, end the call immediately. No legitimate bank, government body, or tech company will initiate this request by phone.
- Consult a trusted person — a family member, colleague, or friend — before taking any financial action prompted by a phone call.
Legitimate vs fraudulent — how to tell:
| Legitimate caller | Vishing caller |
|---|---|
| Encourages you to hang up and call back on an independently verified number | Insists you stay on the line or discourages you from calling back |
| Never asks for your full PIN, password, or one-time passcode | Requests security codes, PINs, or online banking credentials |
| Never asks you to transfer money to a new or "safe" account | Instructs you to move funds, buy gift cards, or hand cash to a courier |
| Never asks you to download remote access software | Requests installation of AnyDesk, TeamViewer, or similar tools |
| Allows time and gives multiple ways to verify the contact | Creates urgency and restricts your options to a single course of action |
How to Protect
How to protect yourself
Preventive habits:
- Adopt a simple personal rule: never act on an inbound call — hang up, verify the number independently, and call back before providing any information or taking any financial action
- Register your number with your national telephone preference service (TPS in the UK, Do Not Call Registry in the US) to reduce unsolicited calls, though be aware that scammers do not honour these lists
- Enable your mobile carrier's call screening or spam detection service — most major carriers offer this free of charge, and it can flag suspected spoofed or fraudulent numbers before you answer
- Discuss vishing with older relatives and family members who may be more frequently targeted; agree on a safe word or verification question for unexpected calls involving money or personal information
- Enable multi-factor authentication on all financial accounts so that credentials alone — even if extracted in a call — are not sufficient to access them
- Treat any call requesting a one-time passcode as an immediate warning sign and end the call
If you have already been targeted:
- End the call immediately if you suspect fraud is in progress — you are under no obligation to remain on the line
- If you have already shared banking credentials or passcodes, contact your bank immediately using the number on the back of your card to report the call and freeze your account
- If you have transferred money, report it to your bank at once — banks may be able to halt or recover transfers if reported quickly
- If you granted remote access to your device, disconnect it from the internet, contact your IT department or a trusted technician, and change all passwords from a separate, clean device
- Report the call to your national cybercrime authority (see Further Reading below)
- Monitor your accounts and credit file closely for unusual activity in the weeks that follow
Useful tools:
| Tool | What it does | Cost |
|---|---|---|
| Have I Been Pwned | Checks whether your personal data has appeared in known breaches — the same data scammers use to appear credible | Free |
| Hiya | Call-screening app that identifies and blocks suspected spam and fraud calls | Free / Paid |
| TrueCaller | Identifies unknown callers and flags numbers reported as scam or spam by other users | Free / Paid |
| 7726 (SPAM) | Forward suspicious SMS lures linked to callback vishing to 7726 — the free spam reporting shortcode used in the US, UK, and many other countries | Free |
Video Lesson
Watch: Vishing explained
A clear, accessible walkthrough of how vishing attacks are constructed, the social engineering techniques used to manipulate victims in real time, common scenarios including bank fraud and tech support scams, and practical steps to identify and avoid voice phishing. Suitable for viewers with no prior cybersecurity knowledge.
Further Reading
Further reading
Official resources
- FBI Internet Crime Complaint Center (IC3) — Report vishing calls and access the latest phone fraud statistics → ic3.gov
- CISA (Cybersecurity & Infrastructure Security Agency) — Guidance on voice phishing and social engineering threats → cisa.gov/phishing
- Action Fraud (UK) — Report vishing calls and get advice if you have been targeted → actionfraud.police.uk
- FTC (US Federal Trade Commission) — Report phone scams and access consumer guidance on impersonation fraud → reportfraud.ftc.gov
Research & reports
- Proofpoint — "State of the Phish 2024" — includes analysis of telephone-oriented attack delivery (TOAD) and callback phishing trends → proofpoint.com/state-of-the-phish
- Hiya — "Global Call Threat Report 2024" — annual benchmark report on phone fraud volumes, spoofing methods, and most impersonated organisations → hiya.com/insights
- UK Finance — "Annual Fraud Report 2024" — includes authorised push payment (APP) fraud data, a significant proportion of which originates with vishing → ukfinance.org.uk
Investigative coverage
- CNN — "Finance worker pays out $25 million after video call with deepfake CFO" — reporting on the landmark Hong Kong deepfake vishing case, February 2024 → cnn.com
- KrebsOnSecurity — ongoing coverage of vishing campaigns targeting corporate employees and financial institutions → krebsonsecurity.com
Related articles on this platform
- Phishing Email — fraudulent emails impersonating trusted organisations to steal credentials
- Smishing (SMS Phishing) — fraudulent text messages with malicious links, often claiming package delivery issues
- Business Email Compromise (BEC) — phishing that targets payment processes in organisations