# vishing

Source: https://startwithidentity.com/glossary/vishing/
Last updated: 2026-09-29
License: content by Start with Identity. Cite the source URL.

---

Vishing, short for voice phishing, is social engineering carried out over a phone call, in which an attacker impersonates a trusted party to get the target to reveal credentials, approve a sign-in, or reset an account.

In identity attacks the call usually has one of two goals: persuade a help desk to reset a password or MFA method for an account the attacker names, or persuade an employee to enter credentials or a one-time code into a lookalike sign-in page while the caller relays them. Groups such as Scattered Spider and ShinyHunters have used it to reach SSO accounts and then the SaaS data behind them, and attackers have used [passkey rollouts themselves as the pretext](https://startwithidentity.com/blog/2026-07-09-entra-passkey-enrollment-vishing-targets-microsoft-365-users/). The controls are procedural as much as technical: verified callback and identity checks before any help-desk reset, a published rule that IT never asks for codes or credentials by phone, and [phishing-resistant MFA](https://startwithidentity.com/glossary/phishing-resistant-mfa/) that a relayed session cannot satisfy.

See also: [help-desk social engineering](https://startwithidentity.com/techniques/help-desk-social-engineering/), [OTP relay social engineering](https://startwithidentity.com/techniques/otp-relay-social-engineering/), [account takeover](https://startwithidentity.com/glossary/account-takeover/), [Scattered Spider](https://startwithidentity.com/breaches/scattered-spider-helpdesk-social-engineering/)
