Start with Identity
Threat

Vishing (Voice Phishing)

Vishing, short for voice phishing, is social engineering carried out over a phone call, in which an attacker impersonates a trusted party to get the target to reveal credentials, approve a sign-in, or reset an account.

In identity attacks the call usually has one of two goals: persuade a help desk to reset a password or MFA method for an account the attacker names, or persuade an employee to enter credentials or a one-time code into a lookalike sign-in page while the caller relays them. Groups such as Scattered Spider and ShinyHunters have used it to reach SSO accounts and then the SaaS data behind them, and attackers have used passkey rollouts themselves as the pretext. The controls are procedural as much as technical: verified callback and identity checks before any help-desk reset, a published rule that IT never asks for codes or credentials by phone, and phishing-resistant MFA that a relayed session cannot satisfy.

See also: help-desk social engineering, OTP relay social engineering, account takeover, Scattered Spider

Last reviewed By SWI Community TeamSuggest a correctionHow we research