Vishing Simulation
Voice phishing simulations that branch based on what the target actually says
Run automated or guided vishing campaigns from branching call scripts with typed nodes, opener, branch, data-request, and outcome, so a scripted call adapts to a keypress response the way a real social-engineering call would.
Opener
Automated bank call center
Branch
Press 1 to verify, 2 to decline
Data request
Asks for OTP over the phone
A vishing script editor shows a branching call flow, from opener node through to each possible outcome.
Voice phishing rarely follows a single linear script, a real vishing call adapts based on how the target responds, and Claro's script builder is designed the same way. Scripts are built from typed nodes: an opener sets up the pretext, branch nodes route the call based on the target's DTMF keypress, data-request nodes prompt for information, and outcome nodes close the call. TwiML is generated per node, so a caller's keypress resolves directly to the next node in the script through the same branching logic an experienced social engineer would use on a live call.
Campaigns run in either automated or guided mode, using per-tenant Twilio credentials that are AES-256-GCM encrypted at rest, drawing from a caller-ID pool and respecting a configured call window and timezone so calls only go out at hours your organization has approved. Every call resolves to a specific, meaningful outcome, complied, refused, reported, no-answer, voicemail, partial compliance, or hung up immediately, and that outcome feeds directly into risk scoring, just-in-time training assignment, and gamification, the same behavioral pipeline used for email and WhatsApp simulations. A preflight check validates the script, disclosure language, provider configuration, target coverage, and call window before a campaign can start, and campaigns support pause, resume, and cancel at any point.
What you get
Branching scripts with typed nodes
Scripts are built from opener, branch, data-request, and outcome nodes, so a call can route differently based on the target's DTMF response, not follow one fixed path.
Automated and guided campaign modes
Run fully automated voice campaigns or guided calls where an operator follows the branching script live, depending on how hands-on your program needs to be.
Per-tenant encrypted Twilio credentials
Voice provider credentials are AES-256-GCM encrypted per tenant, with a caller-ID pool, configured call window, and timezone so calls only go out at approved hours.
Rich outcome capture
Every call resolves to a specific outcome, complied, refused, reported, no-answer, voicemail, partial compliance, or hung up immediately, not just a binary answered/not-answered.
Feeds the same risk and training pipeline
Call outcomes flow into risk scoring, just-in-time training assignment, and gamification, the same behavioral pipeline that email and WhatsApp simulations use.
Preflight checks and full campaign controls
A preflight check validates the script, disclosure language, provider setup, target coverage, and call window before launch, and campaigns can be paused, resumed, or cancelled at any point.
Built for Indonesia
A dedicated compliance control for voice-based attacks
Vishing is a growing vector against Indonesian call centers and branch staff, and Claro's control-coverage engine tracks it as its own dedicated control (OJK-VISHING-01), so a vishing program has a direct line to your OJK-facing compliance evidence rather than sitting outside your reporting entirely. The whole vishing stack, including Twilio credential storage, can run on-premise.
- OJK-VISHING-01 compliance control tracks vishing program activity directly in your regulatory reporting
- Per-tenant encrypted voice-provider credentials, never shared across tenants
- Vishing outcomes feed the same risk score and JIT training used for email and WhatsApp
Frequently asked questions
No. Scripts branch based on typed nodes, opener, branch, data-request, and outcome, so the call routes differently depending on the target's DTMF keypress response.
Related pages
WhatsApp Phishing Simulation
Simulate the phishing channel Indonesian employees actually use most, with localized WhatsApp templates and outcomes feeding the same risk pipeline.
Learn morePhishing Simulation
Launch realistic, multi-channel phishing campaigns with a full state machine, localized templates, and a live monitor tracking every click and report.
Learn moreSecurity Awareness Training
Bilingual micro-learning with four card types, SCORM 1.2 support, learning paths, and game-based drills that build lasting recognition skills.
Learn moreSee it running on your own domain
Book a walkthrough with our team and we'll show you this capability configured for your organization's compliance requirements and language needs.
Book a walkthrough