Threats & Social EngineeringBeginnerAttack Technique3 validated evidence records

Vishing

Also known as: Voice phishing, Phone social engineering

30 sec

Phishing conducted by voice, phone, or voice-enabled communication in order to manipulate a person into granting access, revealing information, or taking an unsafe action.

Know

What is Vishing?

Vishing uses spoken interaction to create trust and urgency. Attackers may impersonate IT support, executives, financial institutions, vendors, or coworkers and can combine caller-ID spoofing, stolen personal information, voice cloning, and real-time coaching to make the interaction convincing.

Why it matters

Vishing became one of the clearest 2026 threat signals. CrowdStrike reported vishing intrusions doubled in the first half of 2026, while Google Cloud documented financially motivated groups using voice social engineering to compromise help desks, SSO accounts, and SaaS data.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Technical ValidationMeasured outcome

Cloud and SaaS incidents were dominated by identity compromise and data theft

2026-H1Google Cloud / MandiantCloud and SaaS

Google Cloud reports identity issues were used for initial access in 83% of major cloud and SaaS incidents it analyzed, while data theft was targeted in 73%. The report also documents vishing, help-desk manipulation, SaaS token abuse, living-off-the-cloud behavior, and compromised third-party trust.

Why this is evidence

The report connects identity, SaaS, cloud, social engineering, and trusted integrations into a single modern intrusion pattern rather than isolated threat categories.

See the source — Google Cloud: Cloud Threat Horizons Report H1 2026
Technical ValidationMeasured outcome

CrowdStrike observed 15x device-code phishing growth, 2x vishing growth, and exploitation windows collapsing to hours

2026-08-03CrowdStrike Counter Adversary OperationsCross-sector

CrowdStrike's 2026 Threat Hunting Report says monthly device-code phishing attempts rose 15x in 1H 2026, vishing intrusions doubled, 88% of observed exploitation involving public PoC occurred within 48 hours, cloud-conscious eCrime rose 171%, and adversaries increasingly targeted AI systems and software dependencies.

Why this is evidence

These measurements validate several of the fastest-moving 2026 threat themes and show that attackers are abusing trusted authentication, cloud, AI, software, and newly disclosed vulnerabilities at increasing speed.

See the source — CrowdStrike: 2026 Threat Hunting Report
Government / AuthoritativeGovernment advisory

FBI warned that scammers were using AI-generated videos and voice cloning to impersonate trusted authorities

2026-07-20FBI Internet Crime Complaint CenterPublic / Cross-sector

The FBI warned of ongoing schemes impersonating IC3 and FBI personnel using AI-generated videos, spoofed websites, social media personas, and voice cloning. The advisory notes scammers can use synthetic media in real-time video chats and private communications to make fraudulent identities appear authentic.

Why this is evidence

This is direct government validation that synthetic media is being used operationally for impersonation and fraud, reinforcing the need for independent identity verification rather than trusting voice or video appearance.

See the source — FBI / IC3: FBI Warns of Scammers Impersonating the IC3

Understand the mechanics

How it works

  1. 1

    The attacker researches the target and chooses a believable pretext.

  2. 2

    A call or voice message impersonates a trusted person or support function.

  3. 3

    The target is pressured to reset access, enroll MFA, disclose a code, install software, or approve an action.

  4. 4

    The attacker uses the resulting access for SaaS, cloud, financial, or data-theft activity.

Practice

What to watch for

  • Unexpected support call
  • Pressure to act immediately
  • Request for MFA code or enrollment
  • Request to bypass normal verification
  • Caller claims secrecy or senior authority
  • Request to install or authorize a tool

Perform

What to do

  1. 1

    End the call when identity cannot be independently verified.

  2. 2

    Call the organization or person back using a known number or internal directory.

  3. 3

    Report the attempt.

  4. 4

    If access was changed, immediately revoke sessions and investigate the account.

How to reduce the risk

  • Help-desk identity verification
  • No authentication reset based only on caller knowledge
  • Phishing-resistant MFA
  • Call-back procedures
  • Role-based vishing simulations
  • High-risk transaction verification

Business impact

  • Account takeover
  • SaaS data theft
  • MFA bypass
  • Financial fraud
  • Help-desk compromise

What different roles should do

Employee

  • Treat voice as a communication channel, not proof of identity

Help Desk

  • Use strong identity-verification procedures before resets or device enrollment

Framework & standards context

  • MITRE ATT&CK T1566 — Phishing
  • MITRE ATT&CK T1078 — Valid Accounts

Keep learning

Source transparency

Authoritative sources

Last reviewed: 2026-09-02