Vishing is phishing conducted by voice. Using a live call and a fabricated identity, the attacker pressures a target into revealing credentials, authorizing a payment, or taking a harmful action — exploiting the immediacy, authority cues, and emotional pressure of real-time voice. The caller poses as a bank’s fraud department, a government agency, tech support, or the internal help desk, and manufactures a situation demanding immediate action.
Voice is a uniquely potent channel. It is real-time, denying the pause that email allows for inspection; there are no headers, URLs, or attachments to scrutinize, so the usual phishing tells are absent. Caller-ID is easily spoofed, so the number appears to be the real bank or agency. A confident human voice conveys authority and improvises around objections — and AI voice cloning now lets attackers imitate a specific person for a “family emergency” or executive-authorization call.
Vishing spans mass robocall fraud and highly targeted voice spear-phishing against specific employees — the July 2020 Twitter breach began with phone social engineering of staff, not a technical exploit. Its defining feature: the pressure of a live, authoritative voice pushing you to act now, before you can verify through an independent channel.