Keepnet – AI-powered human risk management platform logo
Menu
HOME > blog > what is vishing

What Is Vishing? Voice Phishing Meaning, Stats & Protection (2026)

Vishing (voice phishing) uses phone calls to steal credentials and authorize fraud. DBIR 2026: pretexting 6% of initial access; phone sim median ~2% vs email ~1.4%. Detection and exec verification playbook.

Ozan Ucar, Founder and CEO of Keepnet

What is Vishing: Definition, Detection and Protection

Vishing (voice phishing) is social engineering by phone: spoofed caller ID, cloned voices, or callback lures that push people to share credentials, approve wires, or reset accounts without a second-channel check.

The Verizon 2026 DBIR attributes pretexting (live voice, chat, or callback manipulation) to 6% of initial access in the breach sample. Median simulation failure rates run ~1.4% on email and ~2% on phone-centric scenarios (~40% higher, DBIR 2026, p. 50). If you only train email, you grade the easier test.

Gartner's 2025 Secure Behavior Strategies Survey (n=65) found 73% of leaders prioritize phishing reporting metrics, but only 10% prioritize deepfake recognition training (G00840741). The 2025 AI Risk Management Survey (n=302) reports 35% of organizations affected by deepfake incidents.

Source: Gartner, "6 Ways to Transform Your Cybersecurity Awareness Program" (G00840741, March 2026), based on the 2025 Secure Behavior Strategies Survey (n=65).

Keepnet's Extended Human Risk Management Platform (xHRM) pairs multi-channel simulations with Secure Behavior Management (SBM) outcomes. Identity is what you verify on a separate channel, not what caller ID displays.

For channel-wide numbers, see our 2026 phishing statistics hub and dedicated vishing statistics guide.

The honest read

Vishing wins when verification is vague. Help desks and executives are the highest-risk roles because attackers target workflow shortcuts, not ignorance of definitions.

What I'd do this quarter

Publish one rule: no payment, credential reset, or wire transfer on voice alone. Model callback verification in town halls. Run voice phishing simulations mapped to real approval workflows.

Voice phishing speed in the wild (CrowdStrike 2026)

CHATTY SPIDER targeted law firms with vishing and remote tooling in 2025. In one U.S. law firm intrusion, the adversary moved from Quick Assist access to an attempted WinSCP exfiltration within four minutes; when blocked, they pivoted to Google Drive (CrowdStrike 2026 Global Threat Report, p. 11). Average eCrime breakout time across CrowdStrike telemetry was 29 minutes in 2025.

Practical next step

Callback and live-voice playbooks need sub-hour escalation, not next-day ticket queues. DBIR pretexting at 6% of initial access is the breach benchmark; CrowdStrike timelines show why phone failures compress response windows.

Deepfake voice and vishing in 2026 (Gartner G00847786)

Vishing is no longer only a robocall problem. Gartner reports 41% of organizations faced deepfake plus social engineering on an audio call in its 2026 CISO survey (n=297, Gartner G00847786).

Employee playbook: before you act on a live call

  • Pause if the caller pushes urgency for a wire transfer, MFA approval, or password reset.
  • Verify identity on a second channel you initiate (known number, ticket system, in-person).
  • Never share one-time codes or approve MFA prompts the caller triggered.
  • Report suspicious voice calls through your phishing reporter workflow, not only email abuse.
  • Run vishing and deepfake simulations so teams rehearse verification under pressure.

Operational stats: vishing statistics 2026.

Sources

  • CrowdStrike, 2026 Global Threat Report (Year of the Evasive Adversary), p. cited in body.
  • Gartner G00847786: Cybersecurity Threat: Deepfake Identity Impersonation (Akif Khan, 28 May 2026).

For audio context on phone scams and verification habits, see the Keepnet podcast episode embedded below.

Vishing definition and purpose

FTC and CISA frame vishing the same way: phone-based impersonation to steal information or money. The attacker sounds legitimate; the pressure is live. Full regulator wording is in Sources below. This page focuses on what security teams should measure and drill.

ObjectiveWhat attackers want
Credential harvestPasswords, MFA codes, account recovery details
Payment fraudWire transfers, gift cards, invoice changes
Account takeoverHelp-desk resets, vendor portal access
Urgency leverageFake fraud alerts, executive requests, IT lockouts

Purpose of vishing attempts

Phishing vs vishing vs smishing

DBIR 2026 treats asynchronous messaging phishing (16% initial access) separately from pretexting (6%). Same human target, different channel mechanics.

ChannelDeliveryTypical ask
Phishing (email)Async message + linkClick, login, download
Vishing (voice)Live or callback callVerify identity, approve payment, reset MFA
Smishing (SMS)Text + link or replyTrack package, bank alert, MFA code

Phishing vs vishing vs smishing

Phishing simulations, vishing, and smishing exercises should cover all three, not email alone.

Why attackers use voice over email

Attackers optimize for speed and authority. A live voice creates social pressure that email cannot. Finance, IT help desk, and executive assistants see the highest-volume targeted scenarios.

"I ask who's on the other end of every unexpected call. Vishing wins when urgency beats verification. Train people to challenge the caller and confirm on a separate channel before they act."

Ozan Ucar
Founder and CEO of Keepnet

How to detect vishing calls

  • Caller refuses a callback to a published number on the company website
  • Urgent payment or credential request with no ticket reference
  • Caller ID looks internal but the script asks for secrets (passwords, MFA codes)
  • Background noise or hold music designed to sound like a call center
  • Executive or vendor voice that will not verify on a second channel

Where teams get this wrong

Detection is not about spotting robots anymore. Lisbon University research (2024) found more than half of test subjects believed they were speaking with a human during AI voice interactions. Label that as academic research, not a global rate.

Practical next step

Train a pause-and-verify reflex: get a name, ticket ID, and call back on a known number. Measure time-to-report, not quiz scores.

Three shifts matter for program design:

  • AI voice cloning: Deepfake and voice-synthesis tools lower the cost of credible executive impersonation (see deepfake statistics).
  • Callback chains: Email lures that push victims to call an attacker-controlled number (callback phishing).
  • Help-desk targeting: MFA reset and password recovery workflows remain the fastest path to enterprise access.

Keepnet's labeled 2024 Vishing Response Report found 70% of organizations exposed to simulated vishing and 6.5% of employees disclosed sensitive information in voice drills. Use alongside DBIR medians, not as a breach-rate substitute (full report).

Real-world vishing cases

MGM Resorts (September 2023): Industry reporting describes vishing to the IT help desk to reset MFA; SEC filings cite ~$100M impact. Control gap: help-desk verification before privilege changes.

Arup deepfake CFO (January 2024): Multi-person video call with synthetic executives; ~$25.6M loss (HK Police briefing). Control gap: out-of-band executive approval for wires.

Sony partner lure (Keepnet customer drill): See Ibrahim Ucar's field note below: a help-desk agent who had just completed a vishing drill demanded a ticket number and the call ended.

“That last lure almost worked on one of our fastest-growing tech customers. A caller claiming to be a Sony partner offered free game keys and asked employees to ‘verify’ their corporate email and ID, really a ploy to harvest credentials and pivot into the dev cloud. A help-desk agent who had just completed our vishing drill paused, demanded a ticket number, and the line went dead. The lesson is clear: vishing succeeds when curiosity or urgency overrides routine verification, so train people to slow the call, challenge, and confirm on a separate channel.”

Ibrahim Ucar
Product Manager, Keepnet

Common vishing methods

MethodHow it worksWho is targeted
CEO / executive fraudUrgent wire or purchase approvalFinance, assistants
IT help-desk impersonationFake lockout, MFA resetAll staff; help desk
Bank / fraud alertAccount compromise verificationGeneral workforce
Vendor / supplierInvoice or banking detail changeAP, procurement
Callback phishingEmail sends victim to attacker phone lineMixed; often finance
Deepfake voice / videoCloned executive on call or meetingFinance, legal, C-suite

Common vishing methods

How to prevent vishing attacks

  • No secrets on inbound calls: passwords, MFA codes, and recovery links go through approved portals only
  • Callback rule: hang up and dial the published number for IT, bank, or vendor
  • Executive wire policy: second approver plus out-of-band confirmation for any voice-initiated payment
  • Help-desk playbook: ticket required before MFA reset; vishing drills for privileged roles
  • Report rate KPI: track suspicious call reports and time-to-report, not training completion alone

Run vishing simulations tied to the workflows above. Pair with 2026 phishing statistics for board-ready channel comparison (email ~1.4% vs phone ~2% DBIR medians).

Why vishing still works in 2026

Vishing succeeds because it shortcuts verification. A live voice adds urgency and false legitimacy faster than most email lures. The gap is usually operational: no calm path for help-desk staff under pressure.

We see failure rates drop when simulations mirror real workflows (payment approval, login recovery, vendor changes), not generic bank-fraud scripts. Completion rate is a comforting metric; reporting speed and repeat-failure cohorts are security outcomes.

Keepnet recommendation

  • Require callback verification for payment, credential, and account recovery requests
  • Train front-line teams on the vishing scenarios that match your business model
  • Measure reporting speed and repeat failures, not LMS exports alone
  • Pair awareness content with incident-response steps people can follow on a live call

Sources

SHARE ON

twitter
linkedin
facebook

See how your team handles voice phishing

You'll learn how to:
tickBuild AI voice lures mapped to your approval workflows.
tickMeasure reporting speed and repeat failures, not completion alone.
tickCompare channel risk using DBIR-aligned simulation metrics.

Frequently Asked Questions

How is AI deepfake voice different from traditional vishing?

arrow down

Traditional vishing often uses generic scripts or spoofed caller ID. Deepfake voice can mimic a known executive or vendor in real time, which raises success rates on finance and help-desk workflows. G00847786 treats audio deepfake plus social engineering as a distinct incident class (41% of orgs in the 2026 CISO survey, n=297).

What is vishing in cybersecurity?

arrow down

Vishing (voice phishing) is a social engineering attack that uses phone calls to impersonate trusted parties and steal credentials, authorize fraud, or reset accounts. DBIR 2026 tracks pretexting (voice/chat/callback) as 6% of initial access in the breach sample.

What is the difference between phishing and vishing?

arrow down

Phishing usually uses asynchronous messages (email, links). Vishing uses live or callback voice calls. DBIR 2026 reports phishing at 16% and pretexting at 6% of initial access; phone-centric simulations fail at ~2% median click vs ~1.4% for email.

What are common vishing attack examples?

arrow down

Fake bank fraud departments, IT help-desk lockout calls, executive wire requests, vendor invoice changes, and callback scams that start with email. Help-desk MFA reset attacks (MGM-class incidents) remain a top enterprise pattern.

How do you detect a vishing call?

arrow down

Red flags: refusal to use a published callback number, urgency for payment or secrets, spoofed caller ID with a script that asks for passwords or MFA codes, and executives who will not verify on a second channel. Train pause-and-verify, not keyword spotting alone.

How can organizations prevent vishing?

arrow down

Publish callback rules, run voice phishing simulations on real workflows, require ticket IDs before help-desk resets, enforce out-of-band approval for wires, and measure reporting rate and time-to-report.

What vishing statistics matter in 2026?

arrow down

Lead with DBIR 2026: pretexting 6% initial access, phone sim median ~2% vs email ~1.4%. Add Gartner deepfake gap (35% affected vs 10% training priority) and labeled Keepnet voice simulation data where applicable.