Vishing (Voice Phishing)
What is it and how can we defend against it.
Vishing (short for voice phishing) is a type of social engineering attack where cybercriminals use phone calls or voice messages to trick individuals into revealing sensitive information or performing actions that compromise security.
Here's how it works:
- Impersonation: The attacker pretends to be someone trustworthy—like a bank representative, tech support agent, government official, or even a coworker.
- Urgency or Fear: They create a sense of urgency or fear (e.g., “Your account has been compromised!” or “You owe back taxes!”).
- Information Extraction: The victim is pressured into providing personal details, such as:
- Bank account or credit card numbers
- Social Security numbers
- Login credentials
- One-time passcodes (OTPs)
How to Protect Yourself:
- Hang up and call back using the official number from the company’s website.
- Never share sensitive information over the phone unless you initiated the call.
- Be skeptical of urgent or threatening language.
- Use caller ID cautiously—it can be spoofed.
- Report suspicious calls to your bank, employer, or local authorities.
Tagged Vishing, Voice Phishing