Know
What is Vishing?
Vishing uses spoken interaction to create trust and urgency. Attackers may impersonate IT support, executives, financial institutions, vendors, or coworkers and can combine caller-ID spoofing, stolen personal information, voice cloning, and real-time coaching to make the interaction convincing.
Why it matters
Vishing became one of the clearest 2026 threat signals. CrowdStrike reported vishing intrusions doubled in the first half of 2026, while Google Cloud documented financially motivated groups using voice social engineering to compromise help desks, SSO accounts, and SaaS data.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
Cloud and SaaS incidents were dominated by identity compromise and data theft
Google Cloud reports identity issues were used for initial access in 83% of major cloud and SaaS incidents it analyzed, while data theft was targeted in 73%. The report also documents vishing, help-desk manipulation, SaaS token abuse, living-off-the-cloud behavior, and compromised third-party trust.
The report connects identity, SaaS, cloud, social engineering, and trusted integrations into a single modern intrusion pattern rather than isolated threat categories.
CrowdStrike observed 15x device-code phishing growth, 2x vishing growth, and exploitation windows collapsing to hours
CrowdStrike's 2026 Threat Hunting Report says monthly device-code phishing attempts rose 15x in 1H 2026, vishing intrusions doubled, 88% of observed exploitation involving public PoC occurred within 48 hours, cloud-conscious eCrime rose 171%, and adversaries increasingly targeted AI systems and software dependencies.
These measurements validate several of the fastest-moving 2026 threat themes and show that attackers are abusing trusted authentication, cloud, AI, software, and newly disclosed vulnerabilities at increasing speed.
FBI warned that scammers were using AI-generated videos and voice cloning to impersonate trusted authorities
The FBI warned of ongoing schemes impersonating IC3 and FBI personnel using AI-generated videos, spoofed websites, social media personas, and voice cloning. The advisory notes scammers can use synthetic media in real-time video chats and private communications to make fraudulent identities appear authentic.
This is direct government validation that synthetic media is being used operationally for impersonation and fraud, reinforcing the need for independent identity verification rather than trusting voice or video appearance.
Understand the mechanics
How it works
- 1
The attacker researches the target and chooses a believable pretext.
- 2
A call or voice message impersonates a trusted person or support function.
- 3
The target is pressured to reset access, enroll MFA, disclose a code, install software, or approve an action.
- 4
The attacker uses the resulting access for SaaS, cloud, financial, or data-theft activity.
Practice
What to watch for
- Unexpected support call
- Pressure to act immediately
- Request for MFA code or enrollment
- Request to bypass normal verification
- Caller claims secrecy or senior authority
- Request to install or authorize a tool
Perform
What to do
- 1
End the call when identity cannot be independently verified.
- 2
Call the organization or person back using a known number or internal directory.
- 3
Report the attempt.
- 4
If access was changed, immediately revoke sessions and investigate the account.
How to reduce the risk
- Help-desk identity verification
- No authentication reset based only on caller knowledge
- Phishing-resistant MFA
- Call-back procedures
- Role-based vishing simulations
- High-risk transaction verification
Business impact
- Account takeover
- SaaS data theft
- MFA bypass
- Financial fraud
- Help-desk compromise
What different roles should do
Employee
- Treat voice as a communication channel, not proof of identity
Help Desk
- Use strong identity-verification procedures before resets or device enrollment
Framework & standards context
- MITRE ATT&CK T1566 — Phishing
- MITRE ATT&CK T1078 — Valid Accounts
Source transparency
Authoritative sources
Last reviewed: 2026-09-02