← Glossary

Vishing

Vishing is phishing over phone calls, now supercharged by AI voice cloning. It exploits the immediacy and authority of a live voice, and increasingly pairs with email fraud.

Updated

Vishing (voice phishing) is phishing conducted over phone calls, where an attacker impersonates a trusted party, IT support, a bank, an executive, to extract credentials, codes or payments by voice.

Key facts

  • It exploits the immediacy and authority of a live voice: pressure and improvisation the recipient cannot pause to inspect.
  • AI voice cloning now lets attackers convincingly impersonate specific people from seconds of public audio (see deepfake).
  • Vishing frequently pairs with email and SMS as the "confirmation" step of a multi-channel fraud.

How vishing works

The attacker builds a pretext (a "compromised" account, a "suspicious" transaction, an urgent executive request), spoofs a caller ID that matches the story, and applies time pressure so the target acts before verifying. The "IT department" resetting your MFA and the "bank fraud team" walking you through a "safety transfer" are the enduring classics; both work because the caller sounds official and the target does not want to be the one who blocked a legitimate request.

The deepfake escalation

Voice cloning turns "call the CEO to verify" into a weaker defense: a synthetic voice can confirm the fraudulent instruction with the CEO''s own timbre and cadence. This raises the bar on verification: it is no longer enough that the voice sounds right, or that the caller knows internal details, both are increasingly cheap to fake.

The multi-channel pattern

Modern fraud rarely lives in one channel. An email plants the story ("expect a call from Legal"), the call closes the transaction, and an SMS follows up with the payment link. Each channel lends credibility to the next. See social engineering and phishing for the wider pattern.

How to defend

Verify through numbers you initiate, not numbers a caller provides. Use code words or out-of-band confirmation for high-value approvals and payment changes. Train that no legitimate party ever needs an MFA code by phone. And never act on inbound-call instructions alone for anything sensitive: hang up, call back through a known channel, and confirm before acting.

How Sentaro helps

Sentaro does not inspect phone calls and does not claim to. What it does is stop the email that sets up or confirms the vishing chain: the "expect a call from us" pretext, the follow-up "as discussed on the call" payment instruction, the impersonated executive setting the scene. Sentaro catches those messages so the phone step never has the credibility it needs.

Questions we get asked.

What is vishing in simple terms?

Phishing by phone: someone calls pretending to be a trusted party (IT, a bank, an executive) and manipulates you into handing over codes, credentials or money.

How does AI change vishing?

AI voice cloning lets attackers impersonate specific people from short audio samples, so a "call the boss to verify" step no longer proves the caller is who they sound like.

How is vishing different from phishing and smishing?

Only the channel differs: phishing is email, smishing is SMS, vishing is voice. The manipulation and goals are the same, and modern attacks combine all three.

How do we defend against vishing?

Initiate verification yourself through known numbers, use code words for high-value approvals, and enforce procedures that never rely on an inbound call as sole authorization for payments or credential changes.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.