Vishing — voice phishing — is social engineering conducted by phone call. The attacker impersonates someone with a plausible reason to ask: IT support needing a password reset, the payroll provider confirming details, an executive needing something handled urgently, a benefits administrator "verifying" enrollment data.
It deserves separate attention from email phishing because it defeats a different set of defenses. Email filters, link scanners, and banner warnings never see a phone call — the entire attack happens between two voices, in real time, with no artifact for technology to inspect.
A live call removes the pause that written messages allow. The target cannot reread, forward to a colleague, or hover over a link; they must respond now, to a person, with social pressure operating at full strength. Skilled callers use that: friendly authority, mild urgency, background office noise, and fluent use of names and details harvested from public sources or a previously compromised mailbox.
Caller ID makes it worse, because it can be spoofed trivially. A call displaying the payroll vendor's real number, or the CEO's cell, proves nothing — and most employees do not know that, which makes the display itself a tool of the fraud.
Voice cloning has raised the ceiling further: short samples of a person's voice — a conference talk, a voicemail greeting, social video — are enough to synthesize a convincing likeness. The practical consequence is blunt: a familiar voice is no longer verification.
The help desk reversal deserves emphasis, because it inverts the usual training. It is not employees being called by fake support — it is support being called by fake employees, and it succeeds wherever reset procedures verify with information the caller can look up.
Training people to "detect" vishing sets an unwinnable game — good callers are undetectable. The defense that works removes the judgment call entirely: nothing sensitive happens on an inbound call.
The standing rules, stated as procedure rather than advice:
The callback discipline works because it swaps the channel the attacker controls for one they do not. It defeats spoofed caller ID, cloned voices, and perfect scripts equally, and it requires no one to out-judge a professional manipulator.
Vishing resistance is culture as much as procedure. Employees follow the callback rule when leadership has said, explicitly and repeatedly, that verification applies to calls that sound like the CEO, and that no one will ever be penalized for hanging up and dialing back. Include a vishing scenario in training — hearing a recorded example does more than a paragraph of description — and publicize near misses internally, because the caller who targeted payroll on Tuesday is calling accounts payable on Thursday.
Reports belong in the same escalation channel as everything else: one number, no blame, fast action — since a vishing attempt against one employee is reconnaissance against the organization.
Employer's Guardian helps employers train staff on voice-channel fraud and build the callback procedures that neutralize it through workforce training.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.