GRC Careers

HomeResourcesVishing

CS-037 · Email Security

Vishing

Voice-based social engineering that uses phone calls to deceive people into giving up access.

Executive Summary

Vishing is social engineering conducted over the phone, in which an attacker uses a voice call to impersonate a trusted party and manipulate the target into revealing credentials, sharing a one-time passcode, approving a login prompt, or granting remote access. Because a live conversation lets the attacker adapt in real time and apply personal pressure, vishing can be highly persuasive. It is often combined with phishing or smishing to increase credibility.

What It Is

Vishing, short for voice phishing, uses a telephone call rather than a written message to deceive a target. The caller commonly poses as technical support, a bank, a vendor, a government official, or an internal colleague, and constructs a scenario that justifies an urgent request. The goal may be to extract a password or one-time passcode, to have the target approve a push notification, to persuade them to install remote-access software, or to authorize a payment. What makes voice powerful is interactivity: the attacker can respond to hesitation, build rapport, invent reassurances, and escalate pressure in ways a static message cannot. Vishing frequently targets help desks and support staff, whose job is to be helpful, and it pairs naturally with other channels in blended attacks.

Why It Matters

A live human voice carries authority and urgency that text often lacks, and people are conditioned to be cooperative and polite on the phone. This makes vishing effective at extracting exactly the secrets that protect accounts, including the one-time passcodes and push approvals meant to stop attackers who already have a password. Help desks are a favored target because resetting credentials and granting access is their normal function, and a convincing caller can turn that helpfulness into a breach. Vishing has grown more dangerous as attackers use caller-ID spoofing and, increasingly, synthetic voice tools to impersonate specific people. For professionals, this makes strong identity verification procedures and skepticism toward unsolicited calls essential parts of defense.

How It Works

The attacker prepares a pretext and often gathers details in advance so the call sounds informed. They spoof or disguise the calling number to appear trustworthy and open with a believable reason for the call, such as suspicious activity, a required update, or a routine verification. Through conversation they build rapport and manufacture urgency, then make the real request: read back a code, approve a prompt, reset a password, or install a tool that gives them control. If the target hesitates, the attacker adapts, offering reassurance or invoking authority. Success gives them credentials, a bypassed second factor, or direct access, which they use immediately before the ruse is discovered. Defenses center on verifying the caller through independent means and never sharing secrets or approving prompts on an inbound call.

Architecture Diagram

Attacker prepares a pretext and spoofs the numberCalls posing as support, bank, or colleagueBuilds rapport and manufactures urgencyTarget shares a secret or approves accessAttacker uses the access before it is questioned
Vishing uses a live call and adaptive persuasion to extract secrets or access the attacker needs.

Visual Workflow

The attacker researches the target and prepares a believable pretext.They spoof the caller ID and open with a plausible reason for the call.Rapport is built and urgency is manufactured to lower the target's guard.The attacker requests a passcode, prompt approval, password reset, or remote access.The target complies, handing over credentials, a second factor, or control.Security teams verify identity procedures and reinforce that secrets are never shared on inbound calls.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

Phishing-resistant MFA
Uses factors that cannot be read aloud or approved without intent
Help-desk identity verification
Enforces strong, scripted checks before any reset or access grant
Caller authentication and screening
Reduces spoofed and fraudulent inbound calls reaching staff
Security awareness platform
Trains staff on voice pretexts, pressure, and safe callback habits

Industry Standards

NIST SP 800-63
Digital identity and authentication assurance, including account recovery
NIST SP 800-61
Incident handling for a compromise that follows a vishing call
CIS Critical Security Controls
Authentication and awareness safeguards that reduce vishing success

Career Relevance

Vishing defense spans identity verification, help-desk operations, and awareness. SOC analysts and incident responders handle account takeovers that begin with a phone call, and security awareness leads train staff and support teams on voice pretexts. Security engineers deploy phishing-resistant authentication that resists coaxed approvals, while GRC analysts assess help-desk verification and account-recovery controls. For the AI-Governance-Jobs.com audience, vishing is a key social engineering topic across security and governance work.

Interview Questions

Related Certifications

CompTIA Security+ ISC2 Certified in Cybersecurity (CC) GIAC Security Essentials (GSEC)

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

How is vishing different from phishing?

Vishing uses a voice phone call instead of a written message. The interactivity of a live conversation lets the attacker respond to hesitation, build trust, and escalate pressure in real time, which can make it more persuasive than a static email or text.

What is MFA fatigue?

MFA fatigue is when an attacker who has a stolen password triggers repeated login-approval prompts, sometimes reinforced by a vishing call, until a tired or confused user finally approves one. Number-matching prompts and phishing-resistant methods help prevent it.

How can I verify an unexpected caller?

Do not act on the call as received. Hang up and call the organization back using a number you already trust, such as the one on your card or official website. A legitimate caller will not object to you verifying independently.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

CompTIA Security+ISC2 Certified in Cybersecurity (CC)GIAC Security Essentials (GSEC)

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: Vishing
  3. Go deeper: Smishing
  4. Go deeper: Phishing
  5. Validate it: work toward CompTIA Security+
  6. Find the role: browse current openings

Related sheets

More in Email Security

Share this LinkedIn Facebook X Email