Security
Vishing (Voice Phishing)
By Myroslav Orshak · operates licensed carrier infrastructure · Updated September 2026
Vishing is phishing carried out by phone — someone calls pretending to be your bank, a supplier, or your own IT department, and talks a person into handing over a passcode, a payment, or access to a computer.
How it works
Every vishing call follows the same three-part shape, and recognizing it is most of the defense. First the caller establishes authority: they are from your bank's fraud team, your software vendor, or the head office. Then they create urgency — an account is compromised, a payment will bounce, an invoice is overdue today. Finally they make one specific request, and it is always a code, a payment, or remote access to a machine.
What makes it work in 2026 is that the supporting details are easy to fake. Caller ID can be set to display any number, including your own bank's, because the phone network was never built to verify it. Attackers research a company on its website and social media first, so they know your manager's name and your supplier's. And synthetic voice tools now make impersonating a specific person's voice practical rather than theoretical.
Why it matters
It works on businesses because it targets people rather than systems. A company can have flawless software security and still lose money because someone in accounts received a convincing call about a changed bank account. Attackers have largely moved to the phone for exactly this reason: the technical defenses that stopped email attacks do not apply to a conversation.
The defense is a rule rather than a product, and it costs nothing. Nobody legitimate ever needs a code you were sent, and nobody legitimate objects to being called back on a number you already have. Give every member of staff explicit permission to hang up and call back on the number from the bank card, the invoice, or the company directory — never the number the caller gives you. That single habit defeats nearly every version of this.
Displayed caller ID is supplied by the calling party, not verified by the network, so any number can be shown. The STIR/SHAKEN framework mandated by the FCC adds cryptographic attestation to reduce this, but coverage is incomplete and a familiar number on the screen is not proof of who is calling.
Related terms
Ready to pick a provider?
Compare providers on security terms →Frequently asked questions
What is the difference between vishing, phishing and smishing?
Only the channel. Phishing arrives by email, smishing by text message, and vishing by phone call. The goal is identical: get a person to hand over credentials, money, or access. Vishing tends to succeed more often because a live conversation applies pressure that an email cannot.
How do I know if a call is a vishing attempt?
Watch for the combination rather than any single sign: unexpected authority, manufactured urgency, and a request for a code, a payment or remote access. Real organizations do not ask for a code that was sent to you, and they never object to you hanging up and calling back on a number you already had.
Can caller ID be faked?
Yes, easily. The displayed number is supplied by whoever places the call and was never designed to be verified. STIR/SHAKEN is closing the gap but coverage is incomplete, so a call that appears to come from your bank's real number can still be an attacker.
What should my business actually do about it?
Write down one rule and tell everyone: any request for payment, bank-detail changes or credentials gets verified by calling back on a known number. Make it explicit that nobody will be criticized for hanging up on a real caller. Most losses happen because a junior member of staff did not feel able to say no.