Vishing (Voice Phishing)

What is it and how can we defend against it.

Vishing (short for voice phishing) is a type of social engineering attack where cybercriminals use phone calls or voice messages to trick individuals into revealing sensitive information or performing actions that compromise security.

Here's how it works:

  • Impersonation: The attacker pretends to be someone trustworthy—like a bank representative, tech support agent, government official, or even a coworker.
  • Urgency or Fear: They create a sense of urgency or fear (e.g., “Your account has been compromised!” or “You owe back taxes!”).
  • Information Extraction: The victim is pressured into providing personal details, such as:
    • Bank account or credit card numbers
    • Social Security numbers
    • Login credentials
    • One-time passcodes (OTPs)

How to Protect Yourself:

  • Hang up and call back using the official number from the company’s website.
  • Never share sensitive information over the phone unless you initiated the call.
  • Be skeptical of urgent or threatening language.
  • Use caller ID cautiously—it can be spoofed.
  • Report suspicious calls to your bank, employer, or local authorities.