Vishing (voice phishing) is phishing conducted over phone calls, where an attacker impersonates a trusted party, IT support, a bank, an executive, to extract credentials, codes or payments by voice.
Key facts
- It exploits the immediacy and authority of a live voice: pressure and improvisation the recipient cannot pause to inspect.
- AI voice cloning now lets attackers convincingly impersonate specific people from seconds of public audio (see deepfake).
- Vishing frequently pairs with email and SMS as the "confirmation" step of a multi-channel fraud.
How vishing works
The attacker builds a pretext (a "compromised" account, a "suspicious" transaction, an urgent executive request), spoofs a caller ID that matches the story, and applies time pressure so the target acts before verifying. The "IT department" resetting your MFA and the "bank fraud team" walking you through a "safety transfer" are the enduring classics; both work because the caller sounds official and the target does not want to be the one who blocked a legitimate request.
The deepfake escalation
Voice cloning turns "call the CEO to verify" into a weaker defense: a synthetic voice can confirm the fraudulent instruction with the CEO''s own timbre and cadence. This raises the bar on verification: it is no longer enough that the voice sounds right, or that the caller knows internal details, both are increasingly cheap to fake.
The multi-channel pattern
Modern fraud rarely lives in one channel. An email plants the story ("expect a call from Legal"), the call closes the transaction, and an SMS follows up with the payment link. Each channel lends credibility to the next. See social engineering and phishing for the wider pattern.
How to defend
Verify through numbers you initiate, not numbers a caller provides. Use code words or out-of-band confirmation for high-value approvals and payment changes. Train that no legitimate party ever needs an MFA code by phone. And never act on inbound-call instructions alone for anything sensitive: hang up, call back through a known channel, and confirm before acting.
How Sentaro helps
Sentaro does not inspect phone calls and does not claim to. What it does is stop the email that sets up or confirms the vishing chain: the "expect a call from us" pretext, the follow-up "as discussed on the call" payment instruction, the impersonated executive setting the scene. Sentaro catches those messages so the phone step never has the credibility it needs.