Vishing (voice phishing) is a type of social engineering attack where attackers use phone calls to trick victims into revealing sensitive information—bank account numbers, credit card details, social security numbers (SSN), login credentials, or MFA codes. Attackers impersonate trusted entities (bank fraud department, IRS, tech support, government agencies, delivery services) using caller ID spoofing (fake phone numbers) and urgency tactics ("Your account has been compromised"). Vishing bypasses email filters and often preys on elderly victims who are less technically savvy.
Attack Prevalence: 75% of organizations experienced vishing attacks in 2023. $2.5 billion lost to vishing scams (2020-2023, FTC data). 65% of victims are over age 60. Average financial loss per vishing victim: $12,500.
Common vishing attack impersonations:
Attacker spoofs caller ID to appear as legitimate entity (bank number, government agency, tech support). VoIP services (Twilio, SIP) enable spoofing.
Attacker poses as fraud department, IRS agent, or tech support. Uses official-sounding language, scripted scenarios.
"Your account has been compromised", "IRS will arrest you", "Your computer is infected". Creates panic, bypasses rational thinking.
Victim provides bank account details, SSN, MFA codes, or installs remote access software. Attacker drains accounts, commits identity theft.
Attacker uses VoIP services (Twilio, Bandwidth, SIP trunking) to fake caller ID. Call appears from legitimate number (bank, IRS, police department). Victims trust caller ID.
Attacker calls victim pretending to be bank fraud department. "Unauthorized transaction detected", "Your account has been compromised". Requests account number, password, MFA code.
Attacker claims victim owes back taxes, threatens arrest or lawsuit. Requests immediate payment via gift cards, wire transfer, or cryptocurrency.
"Your computer is infected with a virus", "We've detected suspicious activity from your IP address". Victim provides remote access (TeamViewer, AnyDesk) or installs malware.
// Vishing statistics (FBI IC3, FTC, 2023)
- 75% of organizations experienced vishing attacks (2023)
- $2.5 billion lost to vishing scams (2020-2023, FTC data)
- 65% of vishing victims are over age 60
- Average financial loss per vishing victim: $12,500
- 45% of vishing attacks impersonate banks
- 30% impersonate IRS/government agencies
- 15% impersonate tech support
- 10% impersonate delivery services/utilities
- 80% of vishing attacks use caller ID spoofing
- Only 30% of victims report vishing to law enforcement
// Major vishing scams
1. Bank Impersonation (2021-2023): $1.2 billion stolen
2. IRS Scam (2020-2022): $800 million stolen
3. Tech Support Scam (2022-2023): $500 million stolen
This demonstration simulates a vishing attack where an attacker poses as bank fraud department:
This is a simulated demonstration. Real vishing attacks can steal bank account details, SSN, MFA codes, and drain accounts. Never share sensitive information over phone. Hang up and call back using official number (from bank statement, credit card, official website). Banks never ask for full SSN, PIN, or MFA codes over phone. Enable MFA on all accounts.
Never share information over unsolicited calls. Hang up and call back using official number (from bank statement, credit card, official website). Do not use caller ID number (can be spoofed).
Legitimate organizations never ask for MFA codes (Google Authenticator, SMS codes) over phone. Attackers use MFA codes to bypass account security.
Enable carrier spam blocking (AT&T ActiveArmor, Verizon Call Filter, T-Mobile Scam Shield). Use third-party apps (Hiya, Nomorobo). Block unknown callers.
Train employees: verify caller identity, never share credentials, hang up and call back. Report vishing attempts to IT security.
Best Practice - Hang Up & Call Back: Never share sensitive information over unsolicited phone calls. Hang up immediately. Call back using official number from bank statement, credit card, or official website (not the number provided by caller). Banks never ask for full SSN, PIN, or MFA codes over phone. Enable MFA on all accounts. Report vishing to FTC (ftc.gov/complaint).
Vishing (voice phishing, wire fraud) is illegal in all jurisdictions with severe penalties:
Vishing (voice phishing) is illegal. Penalties include:
Important: This guide is for educational and defensive purposes only. Vishing is illegal and harmful.
Report vishing scams to Federal Trade Commission (FTC).
Report vishing and wire fraud to FBI Internet Crime Complaint Center.