What is vishing? Voice phishing explained
Vishing is voice phishing: an attacker impersonates a trusted organization or person during a phone or internet call to obtain information, money or access. The caller may spoof a familiar number, use information gathered online and combine the call with texts, email or a fake website.
How a vishing call works
A vishing attempt often begins with a plausible trigger: suspicious bank activity, a tax issue, a delivery problem, technical support or an internal request from an executive. The caller creates urgency, establishes authority and asks the target to disclose a code, install remote-access software, move money or visit a website.
Caller ID is not proof of identity. Telephone networks and internet calling services can display a name or number selected by the caller. Recorded voices, live operators and AI-generated speech may all be used. The safest response is to end the call and contact the organization through a number printed on a card, statement or official website.
Some campaigns use several channels. A text announces a payment, a caller offers to reverse it, and a fake page collects the victim's credentials. Treat the entire chain as one incident and preserve each message, number, time and URL.
Vishing vs phishing vs smishing
| Technique | Main channel | Typical request | Best first response |
|---|---|---|---|
| Phishing | Email or web | Open a link, sign in, pay or download | Do not interact; verify independently |
| Vishing | Phone or voice call | Reveal codes, transfer funds or install access software | Hang up and call a known official number |
| Smishing | SMS or messenger | Tap a short link, call a number or reply | Do not reply; report and delete after preserving evidence |
Smishing vs phishing: smishing is phishing delivered by text or messenger rather than email. Both rely on impersonation and may lead to the same credential-capture page.
Common vishing scripts
- Bank: “We detected a transfer. Read the code we just sent so we can cancel it.” A genuine one-time code normally approves an action; sharing it can help the attacker complete the transfer.
- Technical support: “Your device is infected. Install this remote-support application.” The software gives the caller control of the screen and accounts.
- Government agency: “A warrant, tax debt or identity case requires immediate payment.” Real agencies do not demand secrecy or payment by gift card or cryptocurrency.
- Parcel service: “Your delivery is held. Confirm the address and small fee.” The call or follow-up text leads to a card-harvesting site.
How to protect yourself
Never disclose a password, full payment-card number or one-time authentication code during an incoming call. Do not install software because an unsolicited caller instructs you to. Refuse pressure to stay on the line while making a transfer.
End the call, wait briefly and contact the organization through a channel you already trust. For a workplace request, use the company directory or speak in person. Set a family verification phrase for urgent money requests. Ask financial institutions about transaction alerts and account protections.
If you acted on the call, contact the relevant bank or account provider immediately, change compromised credentials from a clean device, remove unauthorized remote-access tools and report the number to the phone provider or national fraud-reporting service.
Reporting a vishing campaign
Record the time, displayed number, organization impersonated, exact request and any follow-up URL. Do not publish a private person's number without verification because caller ID may be spoofed. Report the call to your telecom provider and the impersonated organization.
If the campaign uses a website, submit the defanged URL through Fraudpol's reporting form. Fraudpol can investigate the web infrastructure; it does not trace telephone callers or replace a report to local law enforcement when money or identity documents were lost.
For the wider topic, read what phishing is.
Phishing cases we have neutralized
These records come from Fraudpol's public case data. Domains are defanged so they cannot be opened by accident, and retrospectively entered cases are excluded from elapsed-time figures.
No matching public case records are available right now.
View all confirmed casesHave a URL to report right now?
Fraudpol triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.
Report a website to FraudpolRelated guides
Frequently asked questions
What is vishing?
Vishing is voice phishing: a deceptive phone or internet call used to obtain information, money or access by impersonating a trusted person or organization.
This is a phishing technique in which cybercriminals misrepresent themselves and solicit information over the phone. What is it?
This is vishing, also called voice phishing.
What is the difference between vishing and phishing?
Phishing is the broader category. Vishing uses voice calls, while smishing uses texts and conventional phishing commonly uses email or websites.
