---
title: "Voice Phishing Is Rising: Why “Just a Phone Call” Is Now a Real Threat"
description: Voice phishing (vishing) is rising fast. Learn the telltale signs, why it works, and practical steps to prevent and respond, without panic.
image: //www.jerichosecurity.com/hubfs/Voice%20Phishing%20Jericho%20Blog.png
---

[![Jericho Security logo](https://www.jerichosecurity.com/hubfs/assets/images/Jericho-Security.svg)](https://www.jerichosecurity.com/)

[![Jericho Security logo](https://www.jerichosecurity.com/hubfs/assets/images/Jericho-Security.svg)](https://www.jerichosecurity.com/)

- Why Jericho
  
  Why choose Jericho Security?
  
  See what sets Jericho Security apart from the rest.
  
  
  
  [About Us Our Mission](https://www.jerichosecurity.com/about) [Customers What customers say](https://www.jerichosecurity.com/customers)
- Plans 
    - Plans
    - [Lite](https://www.jerichosecurity.com/lite)
    - [Plus](https://www.jerichosecurity.com/plus)
    - [Premium](https://www.jerichosecurity.com/premium)
    - [Free Trial](https://www.jerichosecurity.com/7-day-free-trial)
- Solutions
  
  See how Jericho Security can help keep your team safe.
  
  We equip individuals with the knowledge and skills needed to identify, prevent, and respond to cyber threats.
  
  
  
  
  
  Platform
  
  
  
  [Cybersecurity Dashboard Manage Your Security](https://www.jerichosecurity.com/platform/cybersecurity-dashboard) [Phishing Simulator Train Your Employees](https://www.jerichosecurity.com/platform/phishing-simulator) [Performance Analytics Gain Key Insights](https://www.jerichosecurity.com/platform/employee-performance-analytics) [Customized Training Tailored to Your Organization](https://www.jerichosecurity.com/platform/training-content)
  
  
  
  
  
  Solutions
  
  
  
  [Cybersecurity Awareness Training Train Your Team](https://www.jerichosecurity.com/solutions/cybersecurity-awareness-training) [Anti-Phishing Training Protect Your Business](https://www.jerichosecurity.com/solutions/anti-phishing-training) [Enterprise Cybersecurity Training Defend Against Threats](https://www.jerichosecurity.com/solutions/enterprise-cybersecurity-training) [SMB Cybersecurity Training Empower Your Team](https://www.jerichosecurity.com/solutions/smb-cybersecurity-training)
  
  
  
  
  
  Industries
  
  
  
  [Retail Keep retail threats away](https://www.jerichosecurity.com/industries/retail) [E-Commerce Protect your E-Com Business](https://www.jerichosecurity.com/industries/e-commerce) [Technology Prevent sensitive breaches](https://www.jerichosecurity.com/industries/technology) [Financial Services Safeguard your assets](https://www.jerichosecurity.com/industries/financial-services) [Healthcare Secure sensitive information](https://www.jerichosecurity.com/industries/healthcare)
  
  [Manufacturing Keep your operation running](https://www.jerichosecurity.com/industries/manufacturing) [Energy Prevent the next breach](https://www.jerichosecurity.com/industries/energy) [Federal Government Prevent largescale attacks](https://www.jerichosecurity.com/industries/federal-government) [State & Local Government Protect local officials](https://www.jerichosecurity.com/industries/state-local-government) [Higher Education Keep staff & students safe](https://www.jerichosecurity.com/industries/higher-education)
- Resources
  
  Jericho Security resources hub.
  
  Find everything you need to defend against emerging Generative AI threats.
  
  
  
  
  
  [News Latest news headlines](https://www.jerichosecurity.com/resources/tag/news) [Literature White papers & solution briefs](https://www.jerichosecurity.com/resources/tag/white-papers-solution-briefs) [Case Studies Jericho success stories](https://www.jerichosecurity.com/resources/tag/case-study)
  
  
  
  
  
  [Events Upcoming security events](https://www.jerichosecurity.com/resources/tag/events) [Webinars Upcoming & On-Demand](https://www.jerichosecurity.com/resources/tag/webinars) [Podcast Leading CISO Discussions](https://www.jerichosecurity.com/ciso-diaries)
  
  
  
  
  
  [Community Spotlight To recognize and appreciate](https://www.jerichosecurity.com/resources/tag/community-spotlight) [Cybersecurity Glossary Cyber-Related Definitions](https://www.jerichosecurity.com/glossary) [Support Advice and Answers](https://support.jerichosecurity.com/)
  
  [View All Resources](https://www.jerichosecurity.com/resources)
- [Blog](https://www.jerichosecurity.com/blog)
- [Partners](https://www.jerichosecurity.com/partner)

- [Sign In](https://app.jerichosecurity.com/users/sign_in)
- [Free Trial](https://www.jerichosecurity.com/7-day-free-trial)

# Voice Phishing Is Rising: Why “Just a Phone Call” Is Now a Real Threat

Written by

![Iyan Danial](https://app.hubspot.com/settings/avatar/1406b7238d788c82f579059870625809)

Iyan Danial

Published on

February 2, 2026

![Concerned employee takes a phone call while a laptop displays a blurred login screen and an MFA prompt, in a purple-to-yellow lit office](https://www.jerichosecurity.com/hubfs/Voice%20Phishing%20Jericho%20Blog.png)

Your team finally tightened email security. Then the “IT helpdesk” calls start. Someone sounds calm, competent, and in a hurry. They “just need” an MFA code, a password reset, or a quick screen-share to fix an urgent access issue.

That’s [voice phishing](https://www.jerichosecurity.com/glossary/voice-phishing), and it’s becoming one of the most effective ways to bypass modern defenses because it targets the human layer, not the firewall.

In early 2026, [security reporting highlighted waves of vishing attacks](https://www.computerweekly.com/news/366637762/Wave-of-ShinyHunters-vishing-attacks-spreading-fast) tied to credential theft and SSO account compromise, including campaigns attributed to ShinyHunters that revolve around calling employees and manipulating authentication flows. 

## **Quick Take: Voice Phishing in 60 Seconds**

Voice phishing (aka vishing) is phishing conducted over phone/VoIP/voice channels -  often impersonating IT support, a vendor, or an executive to pressure someone into handing over access.

**Why it’s rising:**

- Cloud identity is a single choke point (SSO + MFA)
- Collaboration tools make “calls from strangers” feel normal

Attackers can synchronize calls with fake login pages and MFA prompts

**Best defenses:**

- Strong identity verification + call-back procedures
- [Phishing-resistant MFA](https://www.jerichosecurity.com/platform/phishing-simulator) (passkeys/FIDO2)
- Training + simulations that include voice scenarios

## **What Is Voice Phishing (and What Does Vishing Stand For)?**

If you’re searching “what is voice phishing” or “what is vishing in cyber security”, here’s the simplest definition:

- [Voice phishing](https://www.jerichosecurity.com/resources/solution-brief/voice-phishing-simulator) is a social engineering attack where a scammer uses voice (phone calls, VoIP, voice messages) to trick someone into revealing sensitive information or taking an action that gives the attacker access.
- Vishing therefore stands for **“voice phishing.” **

Unlike email phishing, the weapon is *conversation*: urgency, authority, empathy, intimidation - whatever gets a person to comply.

## **Why Companies Have to Take Voice Phishing Seriously Now**

Voice phishing isn’t really “new,” but the environment has changed in recent years.

### **1) Identity is the new perimeter**

SSO platforms and cloud suites mean one compromised login can open a lot of doors. Recent reporting describes attackers using voice calls to steal SSO credentials and coerce MFA approvals to access SaaS environments.

### **2) Real-time “guided phishing” is making vishing more successful**

Some campaigns combine a phone call with a fake login page that updates in real time based on what the victim sees so the attacker can coach them through each step (including [MFA](https://www.jerichosecurity.com/glossary/multi-factor-authentication) prompts) in sync with the call.

### **3) Anti-phishing investments skew toward email**

Many organizations have excellent email filtering, banners, and playbooks—but fewer have:

- a helpdesk **call verification** process,
- policies for **unsolicited security calls**, or
- training that prepares staff for voice pressure tactics.

CISA’s broader phishing guidance emphasizes breaking the attack cycle early and strengthening user + organizational defenses; not just technical filtering.

## **What Are the Common Attributes of a Voice Phishing Attack?**

If you want a quick “spot the pattern” list, these are the most common attributes:

- **Authority:** “This is IT / Microsoft / your bank / your vendor.”
- **Urgency:** “We need this in the next 2 minutes.” (Attackers want speed.)
- **A reason to bypass process:** “I can’t use the normal ticket system right now.”
- **A request that escalates access:** MFA code, password reset, device enrollment, new phone number, remote tool install.
- **Channel switching:** call → Teams/Slack message → email → fake login page.
- **“Verification” traps:**“Read me the code you just received,” “Approve the push,” “Confirm your identity.”

If it feels like a script designed to keep you moving, it probably is!

## **Where Voice Phishing Fits Into Cybersecurity and Why It Works**

A quick aside for the broader keyword “what is cyber security”: cybersecurity is the practice of protecting systems, networks, and data from attacks and unauthorized access.

Voice phishing is a threat because it targets the [*decision-making layer*](https://www.jerichosecurity.com/blog/revolutionizing-phishing-simulations-with-jericho-securitys-ai-generated-pretexts)—the human who can override controls, share secrets, or grant access. That’s why even strong tools can fail if a policy or habit says “be helpful quickly.”

The goal of the call is almost never “conversation.” It’s usually one of these outcomes:

- **Credential capture**(username/password)
- **MFA bypass** (approval or code)
- **Account recovery takeover** (reset flows)
- **Remote access** (screen share tools)
- **Sensitive data disclosure** (payroll, invoices, customer data)

## **Anatomy of a Modern Vishing Attack (Step-by-Step)**

Here’s how a typical voice phishing chain looks in the real world:

1. **Recon:** attacker finds employee info (role, org chart hints, tools used).
2. **Pretext:** “Hi. This is IT security. We detected suspicious login attempts.”
3. **Pressure:**“If we don’t fix this now, your access will be locked.”
4. **Action request:** “Go to this link,” “Read the code,” “Approve the MFA prompt.”
5. **Pivot:** attacker uses captured credentials to access SSO/SaaS, often escalating quickly.

The key is that it feels like solving a problem because the attacker is actively coaching the victim through “fixing” it.

## **Mini Scenario: What It Looks Like and the Best Response**

**![Laptop showing risky breach sign in detected as a social engineering attack](https://www.jerichosecurity.com/hs-fs/hubfs/1-Feb-02-2026-06-06-34-8609-PM.png?width=723&height=407&name=1-Feb-02-2026-06-06-34-8609-PM.png)**

**The call:** “Hey, this is Mike from IT. We’re seeing a risky sign-in to your account and I need to verify you so I can revoke the session. You’ll get an MFA code—read it to me.”

**What the employee does (bad path):**

- reads the code,
- approves the push,
- the attacker logs in and enrolls a new authenticator.

**What the employee does (good path):**

1. Says: “I can’t do MFA verification over the phone.”
2. Hangs up and uses a **call-back procedure****:** looks up the official IT number (not the number that called), opens a ticket, and calls IT directly.
3. Reports the attempt immediately.

That “slow down and verify” move is exactly what vishing guidance recommends since attackers rely on speed and emotion.

## **How to Prevent Voice Phishing: Practical Controls That Work**

If you’re a CISO/IT leader building a TOFU-friendly checklist, prevention should be layered:

### **People: Train for voice pressure (not just email)**

- Run awareness training that includes **phone/VoIP/Teams call** scenarios.
- Teach a single rule: **No codes, no approvals, no installs during unsolicited calls.**
- Make reporting frictionless (“Report suspected vishing” button or quick workflow).

### **Process: Add verification muscle memory**

- **Call-back policy:** Employees must initiate the return call using a trusted directory.
- **Helpdesk identity checks:** require ticket numbers, known internal identifiers, or verified callbacks.

Limit who can approve sensitive requests (new MFA device enrollment, payroll changes, wire approvals).

### **Technology: Make the “right choice” the easy choice**

- Deploy **phishing-resistant MFA** (passkeys/FIDO2/WebAuthn), especially for admins and high-risk roles.
- Harden MFA reset/account recovery flows (verification, approvals, logging).
- Use conditional access / device compliance where possible.
- Alert on suspicious identity events (new device, impossible travel, abnormal token use).

Microsoft and CISA both emphasize strengthening authentication and phishing resistance as part of modern identity defense.

## **What Malware Is Always Used During Voice Phishing Attacks?**

**![Woman employee is left confused as data breach alert shows on laptop](https://www.jerichosecurity.com/hs-fs/hubfs/2-Feb-02-2026-06-07-29-9194-PM.png?width=723&height=407&name=2-Feb-02-2026-06-07-29-9194-PM.png)**

This is a common search and the answer is: none**.**

Voice phishing is primarily [social engineering](https://www.jerichosecurity.com/glossary/social-engineering), so many attacks succeed without malware at all. When malware *does* show up, it’s usually because the caller convinces a victim to:

- install a **remote access tool;**
- run a “security update,”;
- or open a link that delivers a payload.

So instead of hunting for “the one vishing malware,” focus on the control points:

- block unauthorized installs;
- restrict remote support tooling;
- require verification for helpdesk requests;
- and improve MFA resilience.

## **If You Suspect a Voice Phishing Attempt: What to Do Immediately**

1. **Stop the interaction**(don’t argue; end the call).
2. **Verify through a trusted channel**(call-back using official numbers).
3. **Report internally** (SOC/IT/security mailbox or workflow).
4. **Check identity logs** (SSO sign-ins, new MFA enrollments, password resets).
5. **Reset and revoke** as needed (password reset, session/token revocation, MFA reset *with verification*).
6. **Document the pretext**(caller claim, phone number, requested action, link/domain).

[CISA’s phishing guidance](https://www.cisa.gov/secure-our-world/recognize-and-report-phishing) is a useful reference for improving organizational response and breaking the cycle early.

## **Voice Phishing Prevention Checklist **

Use this as a starting point for your internal playbook:

- Document a **call-back** policy for IT/security requests
- Train staff: **no MFA codes / no push approvals** on unsolicited calls
- Require tickets + identity checks for resets, MFA enrollments, and access changes
- Roll out **phishing-resistant MFA** for privileged users (then expand)
- Monitor for suspicious sign-ins and MFA changes (alerts + review)
- Restrict remote support tools and software installs (least privilege)
- Review collaboration tool settings for external calls/messages where relevant
- Run vishing simulations (phone + “follow-the-link” coaching scenarios)
- Make reporting easy and reward early reporting
- Post a 1-page “What to do if someone calls you from IT” guide

## **Next Steps**

Jericho Security focuses on [AI-powered cybersecurity awareness training](https://www.jerichosecurity.com/resources/solution-brief/cybersecurity-training), including phishing simulations and an infinitely customizable, comprehensive training library to help teams recognize and respond to modern threats.

If you want to see how vishing-ready training and reporting can look in practice, explore Jericho’s next-gen security awareness training and simulation approach - especially for high-risk roles like IT, finance, and exec assistants.

# **FAQ **

**Q1: What is voice phishing?** Voice phishing is a social engineering attack where scammers use phone/VoIP/voice channels to trick someone into revealing sensitive info or granting access.

**Q2: What is vishing in cyber security?** In cybersecurity, vishing is voice phishing - phishing conducted through calls or voice messages to steal credentials, bypass MFA, or trigger harmful actions.

**Q3: What does vishing stand for?** Vishing stands for “voice phishing.”

**Q4: What are the common attributes of a voice phishing attack?** Authority impersonation, urgency, requests for MFA codes/approvals, channel switching, and pressure to bypass standard helpdesk or verification steps.

**Q5: How to prevent voice phishing?** Use call-back procedures, train employees to refuse code/approval requests, harden helpdesk resets, and deploy phishing-resistant MFA for key accounts.

**Q6: What malware is always used during voice phishing attacks?** None. Many vishing attacks involve no malware at all. When malware appears, it’s typically installed after the caller persuades the victim to run a tool or click a link.

**Q7: Why is voice phishing increasing?** Attackers are targeting identity systems (SSO + MFA) and using real-time coaching with fake login flows to increase success rates.

**Q8: Is voice phishing only phone calls?** No. Vishing can include VoIP calls, voice messages, and voice-based approaches inside collaboration tools, depending on what’s normal for your organization.

##### Categories

- [News (45)](https://www.jerichosecurity.com/blog/tag/news)
- [Thought Leadership (15)](https://www.jerichosecurity.com/blog/tag/thought-leadership)
- [Phishing (14)](https://www.jerichosecurity.com/blog/tag/phishing)
- [Product Updates (10)](https://www.jerichosecurity.com/blog/tag/product-updates)
- [Announcements (8)](https://www.jerichosecurity.com/blog/tag/announcements)
- [Reports (5)](https://www.jerichosecurity.com/blog/tag/reports)
- [Case Study (4)](https://www.jerichosecurity.com/blog/tag/case-study)
- [Community Spotlight (3)](https://www.jerichosecurity.com/blog/tag/community-spotlight)
- [Events (3)](https://www.jerichosecurity.com/blog/tag/events)
- [White Papers & Solution Briefs (1)](https://www.jerichosecurity.com/blog/tag/white-papers-solution-briefs)

#### Subscribe to our newsletter

Get the latest updates on phishing trends and generative AI.

Subscribe

##### Popular Posts

Platform <https://www.jerichosecurity.com/blog/voice-phishing-vishing-prevention#collapseLanding>

- [Cybersecurity Dashboard](https://www.jerichosecurity.com/platform/cybersecurity-dashboard)
- [Phishing Simulator](https://www.jerichosecurity.com/platform/phishing-simulator)
- [Performance Analytics](https://www.jerichosecurity.com/platform/employee-performance-analytics)
- [Customized Training](https://www.jerichosecurity.com/platform/training-content)

Solutions <https://www.jerichosecurity.com/blog/voice-phishing-vishing-prevention#collapseLanding>

- [Anti-Phishing Training](https://www.jerichosecurity.com/solutions/anti-phishing-training)
- [SMB Cybersecurity Training](https://www.jerichosecurity.com/solutions/smb-cybersecurity-training)
- [Enterprise Cybersecurity Training](https://www.jerichosecurity.com/solutions/enterprise-cybersecurity-training)
- [Cybersecurity Awareness Training](https://www.jerichosecurity.com/solutions/cybersecurity-awareness-training)

Industries <https://www.jerichosecurity.com/blog/voice-phishing-vishing-prevention#collapseLanding>

- [Retail](https://www.jerichosecurity.com/industries/retail)
- [E-Commerce](https://www.jerichosecurity.com/industries/e-commerce)
- [Technology](https://www.jerichosecurity.com/industries/technology)
- [Financial Services](https://www.jerichosecurity.com/industries/financial-services)
- [Healthcare](https://www.jerichosecurity.com/industries/healthcare)
- [Manufacturing](https://www.jerichosecurity.com/industries/manufacturing)
- [Energy](https://www.jerichosecurity.com/industries/energy)
- [Federal Government](https://www.jerichosecurity.com/industries/federal-government)
- [State & Local Government](https://www.jerichosecurity.com/industries/state-local-government)
- [Higher Education](https://www.jerichosecurity.com/industries/higher-education)

Resources <https://www.jerichosecurity.com/blog/voice-phishing-vishing-prevention#collapseLanding>

- [Cybersecurity Glossary](https://www.jerichosecurity.com/glossary)
- [Support](https://support.jerichosecurity.com/)
- [Blog](https://www.jerichosecurity.com/blog)
- [News](https://www.jerichosecurity.com/resources/tag/news)
- [Literature](https://www.jerichosecurity.com/resources/tag/white-papers-solution-briefs)
- [Case Studies](https://www.jerichosecurity.com/resources/tag/case-study)
- [Events](https://www.jerichosecurity.com/resources/tag/events)
- [Webinars](https://www.jerichosecurity.com/resources/tag/webinars)
- [Community Spotlight](https://www.jerichosecurity.com/resources/tag/community-spotlight)

Company <https://www.jerichosecurity.com/blog/voice-phishing-vishing-prevention#collapseLanding>

- [About Us](https://www.jerichosecurity.com/about)
- [Customers](https://www.jerichosecurity.com/customers)
- [Partners](https://www.jerichosecurity.com/partner)
- [Careers](https://jericho-security.breezy.hr/)
- [Sign In](https://app.jerichosecurity.com/users/sign_in)
- [Get a Demo](https://www.jerichosecurity.com/demo)
- [Privacy Policy](https://www.jerichosecurity.com/privacy-policy)
- [Terms of Service](https://www.jerichosecurity.com/terms-of-service)

[![Jericho Security footer logo](https://www.jerichosecurity.com/hubfs/assets/images/bootstrap/jericho-logo.svg)](https://www.jerichosecurity.com/) 

AI-Powered Cyber Security Training for Employees.

![AICPA SOC](https://www.jerichosecurity.com/hs-fs/hubfs/assets/images/bootstrap/AICPA-SOC-Logo.png?width=54&height=54&name=AICPA-SOC-Logo.png) ![SOC 2 TYPE 1](https://www.jerichosecurity.com/hs-fs/hubfs/assets/images/bootstrap/SOC-2-TYPE-1.png?width=54&height=54&name=SOC-2-TYPE-1.png) ![SOC 2 TYPE 2](https://www.jerichosecurity.com/hs-fs/hubfs/assets/images/bootstrap/SOC-2-TYPE-2.png?width=54&height=54&name=SOC-2-TYPE-2.png)

Toggle theme

- Light
- Dark
- Auto

 Copyright ©  Jericho Security, Inc.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Iyan Danial",
    "url" : "http://www.jerichosecurity.com/blog/author/iyan-danial"
  },
  "dateModified" : "2026-02-02T18:07:59.657Z",
  "datePublished" : "2026-02-02T17:05:56.000Z",
  "headline" : "Voice Phishing Is Rising: Why “Just a Phone Call” Is Now a Real Threat",
  "image" : [ "//www.jerichosecurity.com/hubfs/Voice%20Phishing%20Jericho%20Blog.png" ],
  "mainEntityOfPage" : {
    "@id" : "http://www.jerichosecurity.com/blog/voice-phishing-vishing-prevention",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "//www.jerichosecurity.com/hubfs/assets/images/Jericho-Security.svg"
    },
    "name" : "Jericho Security"
  }
}
```

```json
{
  "@context" : "https://schema.org/",
  "@type" : "Article",
  "author" : {
    "@type" : "Organization",
    "name" : "Jericho Security"
  },
  "datePublished" : "",
  "description" : "Safeguard your data with these 10 phishing prevention tips and learn how to prevent phishing attacks with Jericho Security's advanced AI-powered strategies",
  "headline" : "10 Email Phishing Prevention Tips on How to Prevent Phishing Attacks in Your Organization",
  "image" : {
    "@type" : "ImageObject",
    "height" : "",
    "url" : "",
    "width" : ""
  },
  "mainEntityOfPage" : {
    "@id" : "https://www.jerichosecurity.com/blog/10-phishing-prevention-tips-and-helpful-solutions",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : "",
      "url" : "",
      "width" : ""
    },
    "name" : ""
  }
}
```