S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.8
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Vishing

Telephony Vector · Voice Phishing · Very Common
High Alert
How It WorksSEC 01

Vishing is phishing conducted by voice. Using a live call and a fabricated identity, the attacker pressures a target into revealing credentials, authorizing a payment, or taking a harmful action — exploiting the immediacy, authority cues, and emotional pressure of real-time voice. The caller poses as a bank’s fraud department, a government agency, tech support, or the internal help desk, and manufactures a situation demanding immediate action.

Voice is a uniquely potent channel. It is real-time, denying the pause that email allows for inspection; there are no headers, URLs, or attachments to scrutinize, so the usual phishing tells are absent. Caller-ID is easily spoofed, so the number appears to be the real bank or agency. A confident human voice conveys authority and improvises around objections — and AI voice cloning now lets attackers imitate a specific person for a “family emergency” or executive-authorization call.

Vishing spans mass robocall fraud and highly targeted voice spear-phishing against specific employees — the July 2020 Twitter breach began with phone social engineering of staff, not a technical exploit. Its defining feature: the pressure of a live, authoritative voice pushing you to act now, before you can verify through an independent channel.

Warning SignsSEC 02
  • An unsolicited inbound call creating urgency, fear, or a "must act now" deadline.
  • Requests for passwords, full card numbers, or one-time passcodes — which legitimate institutions never ask for by phone.
  • Demands for payment by gift card, wire, crypto, or a "verification" transfer.
  • Instructions to install remote-access software.
  • Familiar caller-ID paired with an abnormal request (spoofing).
  • Pressure to stay on the line and not call back or consult anyone.
Frequently Paired WithSEC 03
  • Authority Impersonation · T14.7
    The identity layer vishing rides on
  • Smishing · T14.9
    Sibling vector; an SMS primes or follows the call
  • Tech-Support Scam · T24.3
    Consumer-fraud home for that variant
  • Shoulder Surfing · T14.6
    Captured details lend a call false legitimacy
How the Attack UnfoldsSEC 04
  • Stage 01 · Contact
    An unsolicited call (or induced callback) invokes a trusted authority — bank, agency, IT — with a spoofed familiar caller-ID.
  • Stage 02 · Pressure
    A manufactured crisis and a ticking deadline raise fear and suppress deliberation; the caller resists any move to hang up and verify.
  • Stage 03 · Extraction
    Under real-time pressure the target reads out a code, installs remote access, or approves a transfer — before an independent channel can be checked.
Counter-ProtocolSEC 05
Defense: Hang up and call back on a known number — caller-ID is not identity.
  • Treat inbound calls as unverified. Call back on the number from your card, the official site, or the directory — never a number the caller gives.
  • Never share passwords or one-time passcodes by phone. No legitimate institution needs them.
  • Refuse gift-card, wire, or crypto "payments," and never install software at a caller's direction.
  • Slow it down and unhook the fear. Agree a family verification word to defeat "emergency" and voice-clone calls.
  • Back it with phishing-resistant MFA (FIDO2/hardware keys) so a phoned-out code is useless, plus strict help-desk verification.