What Is Vishing? How Voice Phishing Works and How to Protect Yourself

Vishing — voice phishing — is the telephone-based counterpart to email phishing and text smishing. A vishing attack involves a live or recorded phone call from someone impersonating a trusted authority — the IRS, your bank’s fraud department, the Social Security Administration, tech support, or even a family member — designed to extract personal information, payment, or remote access to your device.

Vishing is particularly effective because the telephone has historically been a trusted communication channel, and because the social pressure of a live conversation — or a convincing recorded voice — leaves less time for the reflection that might prevent a victim from complying.

In its most advanced modern form, vishing now uses AI voice cloning to synthesize the voice of someone the victim knows — a family member, a colleague, a boss — making it among the most psychologically sophisticated scams in existence.

What Is Vishing?

Vishing (voice phishing) is a social engineering attack conducted over the telephone in which an attacker impersonates a trusted entity to manipulate the victim into surrendering sensitive information, making payments, or granting access to their accounts or devices.

Unlike smishing (which sends a link for the victim to click) or email phishing (which requires the victim to act on a written message), vishing puts a human voice — or a convincing simulation of one — in direct, real-time contact with the victim. This live interaction allows the attacker to adapt to the victim’s responses, answer questions, overcome objections, and escalate pressure in ways that one-directional attacks cannot.

Common Vishing Scenarios

The IRS Scam Call

Among the most reported vishing attacks. The caller claims to be an IRS agent and tells the victim they owe back taxes and will be arrested, sued, or deported if they don’t pay immediately. Payment is typically demanded via wire transfer, gift cards, cryptocurrency, or Zelle — none of which the real IRS uses.

“This is the Internal Revenue Service. There is a warrant out for your arrest for unpaid taxes. Call us back immediately at [number] or you will be arrested today.”

The Bank Fraud Department Call

The caller claims to be from your bank’s fraud department, alerting you to suspicious transactions on your account. To verify your identity and stop the fraud, they need your account number, online banking password, or the one-time code the bank just sent you. (That code was triggered by the attacker trying to log into your account.)

The Social Security Administration Call

“This is the Social Security Administration. Your Social Security number has been suspended due to suspicious activity linked to money laundering. To avoid arrest, you must verify your identity immediately.” The real SSA does not suspend Social Security numbers.

Tech Support Vishing

A call from “Microsoft,” “Apple,” or a generic “IT support department” warning that your computer has been hacked, that viruses have been detected, or that your subscription is expiring. The goal is to get you to install remote access software (giving the attacker control of your computer) or pay for fraudulent “support services.”

The Grandparent / Family Emergency Scam

A call that appears to come from a grandchild, child, or other family member in distress — “I’ve been in an accident, I’m in jail, I’m in the hospital abroad.” They need money immediately and ask you not to tell anyone. AI voice cloning is increasingly used to make these calls sound exactly like the real person.

Business Email Compromise Vishing

A call targeting a company’s finance department from someone claiming to be the CEO, a senior executive, or a trusted vendor — asking to authorize an urgent wire transfer or change payment details. Often follows a corresponding spoofed email.

How AI Voice Cloning Has Changed Vishing

The emergence of commercially accessible AI voice cloning tools has fundamentally changed the threat landscape for vishing. With as little as 3 seconds of audio — available on any public social media video — an attacker can generate a synthetic voice that is nearly indistinguishable from the real person.

This technology has been used to:

– Clone the voice of a grandchild calling their grandparent from “jail”

– Clone the voice of a company CEO authorizing a wire transfer

– Clone the voice of a family member in a fake emergency situation

The FBI issued a formal warning in 2024 about the increasing use of AI voice cloning in fraud campaigns. The agency specifically warned about deepfake audio being used to impersonate senior government officials and corporate executives.

Protecting against AI voice cloning: establish a verbal “safe word” or “family code” with close family members that can be used to verify the caller’s identity in an emergency. This takes 30 seconds to set up and can prevent devastating family emergency scams.

How to Recognize a Vishing Call

Unsolicited contact about an urgent problem. Legitimate agencies like the IRS and SSA initiate contact by mail, not phone. Unsolicited calls about account problems, arrest warrants, or suspended benefits are almost universally fraudulent.

Pressure to act immediately and secretly. “Do not hang up.” “Do not tell anyone.” “You must pay today or you will be arrested.” Legitimate institutions give you time to think and encourage you to verify.

Unusual payment methods. Gift cards, wire transfers, cryptocurrency, Zelle, or cash apps are never legitimate payment methods for taxes, government fees, or bank fraud recoveries. If someone asks you to pay this way, it is a scam.

Requests for your passwords or verification codes. Your bank will never ask for your full password or for the one-time code that was just sent to your phone. These codes exist precisely to prevent unauthorized access — handing them over hands the attacker the keys.

Caller ID shows a government agency or official number. Caller ID is trivially easy to spoof. The number on your screen proves nothing about who is actually calling.

What to Do During a Suspected Vishing Call

Hang up. There is no polite way to handle a scam call. Hanging up is the right action. Fraudulent callers are skilled at keeping victims on the line — do not let them.

Do not call back the number they provided. If you want to verify the situation, look up the organization’s official phone number through their official website and call that number directly.

Do not provide any information. Never give your password, your SSN, your bank account number, or any one-time code to an unsolicited caller.

If a family member sounds like they’re in trouble — verify through a separate channel. Call another family member. Call the person directly at their known number. Ask the caller a question only the real person would know.

How to Protect Yourself From Vishing

Register with the National Do Not Call Registry. While it won’t stop scam calls (scammers don’t follow the law), it reduces legitimate telemarketing and makes unsolicited calls more obviously suspicious.

Use a call-blocking app. Nomorobo, Hiya, and Robokiller are effective at blocking known scam numbers. Your carrier may also offer call blocking tools.

Let unknown numbers go to voicemail. Legitimate callers leave messages. Scammers rarely leave detailed messages and never leave a message that holds up to scrutiny.

Establish a family code word. For family emergency scenarios — particularly relevant for seniors — agree on a verbal verification word that only family members know.

Never trust caller ID alone. If the call is important and you’re uncertain, hang up and call back through the official number.

Frequently Asked Questions

Q: Is vishing the same as phone fraud?

A: Vishing is a specific type of phone fraud — one that uses social engineering to impersonate trusted entities. Phone fraud is the broader category, which also includes robocall scams, telemarketing fraud, and other telephone-based crimes.

Q: Can I sue someone who vishses me?

A: In practice, vishing operations are often run from overseas and identifying individual perpetrators is extremely difficult. Reporting to the FTC (reportfraud.ftc.gov) and FCC contributes to enforcement actions against fraud operations.

Q: What should I do if I gave a visher my bank details?

A: Call your bank’s official fraud line immediately — use the number on the back of your card or your bank’s official website, not a number provided by the caller. Request new account numbers and review recent transactions for unauthorized activity.

→ Back to Pillar: https://www.scammed.org/phishing/

→ See also: https://www.scammed.org/phishing/smishing/

→ See also: https://www.scammed.org/seniors/ (vishing disproportionately targets seniors)