Vishing
Vishing is a voice-based social engineering attack where a caller impersonates a trusted party over the phone to trick victims into revealing sensitive information or authorizing fraudulent actions.
Definition
Vishing, short for voice phishing, is a form of social engineering in which an attacker uses a phone call or voice message to impersonate a trusted entity, such as a bank, government agency, IT helpdesk, or company executive, and manipulate the victim into disclosing confidential information, transferring funds, or performing an action that benefits the attacker. Unlike email-based phishing, vishing exploits the immediacy and perceived authenticity of a live human voice, often combined with caller ID spoofing to make the call appear legitimate. It targets the human element directly, bypassing many technical email and web security controls.
A vishing attack typically begins with research on the target, then a call where the attacker establishes a pretext and applies pressure. Common tactics include impersonating a bank fraud department warning of suspicious transactions, posing as IT support requesting login credentials or a one-time passcode (OTP), or claiming to be a tax or police authority threatening legal consequences. Attackers frequently spoof caller ID so the number appears to match a real institution, and they may have gathered partial personal data beforehand to sound credible. Increasingly, attacks blend channels: a phishing email or SMS prompts the victim to call a fraudulent number, or an OTP stolen by phone is used to complete account takeover.
In regulated sectors like banking, vishing is a leading driver of financial fraud because a single successful call can yield an OTP that defeats one-time-password protections, or convince an employee to reset a password or approve a wire transfer. A well-known enterprise pattern is the helpdesk impersonation call, where an attacker phones IT support, impersonates a staff member, and requests a credential reset or MFA enrollment change to seize an account. The rise of AI voice cloning has made these attacks more convincing, allowing attackers to mimic a specific executive or colleague.
Vishing matters because voice is one of the least monitored attack surfaces. Email security gateways do not inspect phone calls, and people are conditioned to trust a human voice and respond quickly under pressure. Defenses are largely behavioral: verifying caller identity through an independent channel, never sharing OTPs or passwords by phone, enforcing callback procedures for sensitive requests, and training staff to recognize urgency and authority as manipulation cues. Technical controls such as caller ID authentication and phishing-resistant MFA reduce exposure but cannot replace human vigilance.
At a glance
- Severity
- High
- Prevalence
- Common, growing with AI voice cloning
- Primary targets
- Bank customers, employees, and helpdesk staff
- Also known as
- Voice phishing
How it works
- 1
Research: the attacker gathers partial personal or organizational details to sound credible on the call.
- 2
Spoofed call: they place a call, often with caller ID spoofing so the number appears to match a real bank, agency, or company.
- 3
Pretext and pressure: the caller impersonates a trusted role, such as a bank fraud investigator or IT support, and creates urgency or fear.
- 4
Extraction: the victim is pressured to disclose an OTP, password, or personal detail, or to approve a transaction.
- 5
Fraud or takeover: the attacker uses the disclosed information immediately, often within minutes, to complete a fraudulent transfer or account takeover.
Warning signs
- Unsolicited call claiming to be from your bank, IT support, or a government agency
- Caller creating urgency, fear, or secrecy around the request
- Request for a password, OTP, or PIN over the phone
- Caller ID that looks legitimate but the request feels unusual
- Pressure to act immediately without time to verify independently
How to defend
- Never share an OTP, password, or PIN over the phone, regardless of who is asking
- Hang up and call back using a number from the official website or your bank card, not the number that called you
- Treat urgency and authority as manipulation cues, not reasons to skip verification
- Enforce callback procedures for sensitive requests within your organization
- Use phishing-resistant multi-factor authentication that cannot be relayed over a phone call
Real-world example
A bank customer in Jakarta receives a call from someone claiming to be from the bank's fraud department, warning of a suspicious transaction and asking for the OTP just sent by SMS to reverse it. Trusting the caller ID that matches the bank's real number, the customer reads out the code, and the attacker uses it immediately to authorize a fraudulent transfer.
How Claro helps
Claro lets organizations run controlled vishing simulations to measure how employees respond to manipulative phone calls before real attackers test them. Using branching call scripts and per-tenant voice provider integration, security teams can simulate scenarios such as a fraudulent bank or IT helpdesk call, capture outcomes (complied, refused, or reported), and feed those results into individual and organizational human risk scores. When a user complies with a simulated call, Claro can trigger just-in-time awareness training, turning a moment of weakness into targeted learning. This closes the loop from measurement to behavior change, with full bilingual support for Indonesian regulated industries.
Frequently asked questions
How is vishing different from phishing?
Phishing is delivered through written messages like email, while vishing uses a live phone call or voice message. The immediacy and perceived authenticity of a human voice make vishing especially effective at pressuring victims into acting quickly.
Can caller ID be trusted?
No. Caller ID spoofing lets attackers make a call appear to come from a legitimate bank, agency, or company number, so a matching caller ID alone is not proof of authenticity.
Why has vishing become more dangerous recently?
AI voice cloning now lets attackers convincingly mimic a specific executive or colleague's voice, making impersonation calls far harder to detect by ear alone. This makes independent verification through a separate channel more important than ever.
What should I do if I already shared information on a vishing call?
Contact your bank or organization immediately through an official number to freeze the affected account or credential, change any exposed passwords, and report the incident to your security team so they can watch for follow-on fraud.
Related terms
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Smishing
Smishing is phishing carried out over SMS or other text messaging, where attackers send fraudulent texts to trick people into revealing data, clicking malicious links, or sending money.
Social Engineering
The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.
Multi-Factor Authentication (MFA)
A security method that requires two or more independent proofs of identity before granting access to an account or system.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo