Keepnet – AI-powered human risk management platform logo
Menu
HOME > blog > vishing statistics unmasking the voice phishing threat

Vishing Statistics 2026: Unmasking the Voice Phishing Trends

2026 vishing statistics grounded in Verizon DBIR pretexting and phone-centric simulation metrics. Separate from our smishing statistics guide on SMS/text channels.

Ozan Ucar, Founder and CEO of Keepnet

Vishing Statistics 2026: Unmasking the Voice Phishing Trends

Vishing (voice phishing) uses live calls, callbacks, and help-desk manipulation to bypass email filters. The Verizon 2026 DBIR tracks pretexting , synchronous voice or chat , at 6% of initial access (p. 10-12). Phone-centric phishing simulations median near ~2% click versus ~1.4% for email (~40% higher, p. 50).

Keepnet's Extended Human Risk Management Platform (xHRM) pairs multi-channel simulations with Secure Behavior Management (SBM) outcomes: reporting speed and repeat-failure cohorts, not completion exports alone.

Source: Gartner, "6 Ways to Transform Your Cybersecurity Awareness Program" (G00840741, March 2026), based on the 2025 Secure Behavior Strategies Survey (n=65).

Executive summary: vishing statistics 2026

  • Pretexting (voice/chat): 6% of initial access (DBIR 2026)
  • Phone sim median click: ~2% vs email ~1.4% (DBIR 2026, p. 50)
  • Only 10% of leaders prioritize deepfake recognition vs 73% prioritizing phishing reporting (Gartner 2025, n=65)
  • 35% of organizations affected by deepfake incidents (Gartner 2025, n=302)

Vishing statistics at a glance

MetricValueSource
Pretexting as initial access6%Verizon DBIR 2026
Phishing (async) initial access16%Verizon DBIR 2026
Phone sim median click~2%Verizon DBIR 2026, p. 50
Email sim median click~1.4%Verizon DBIR 2026, p. 50
Phone vs email sim gap~40% higher on phoneVerizon DBIR 2026
Deepfake incidents (orgs)35%Gartner G00840678, n=302

Vishing statistics at a glance (2026)

Why this matters

Legacy vishing pages cite consumer scam-call surveys without breach context. DBIR separates pretexting from inbox phishing for a reason.

What security leaders should do

Use DBIR pretexting % in board decks, not undated robocall stats. baseline vishing simulations against the ~2% median.

Vishing vs email phishing statistics

Asynchronous phishing (email, SMS links) accounts for 16% of initial access; pretexting adds 6%. Combined identity manipulation (phishing + credentials + pretexting) totals 35% , comparable to vulnerability exploitation at 31% (DBIR 2026). Email-only security awareness grades the easier test.

Why this matters

Gartner reports 73% of leaders prioritize phishing reporting (n=65) while phone channels show higher sim failure rates.

What security leaders should do

Run voice and callback scenarios alongside email. See phishing statistics 2026 for the full multi-channel matrix.

Deepfake and AI voice phishing statistics

Gartner's 2025 AI Risk Management Survey (n=302) found 35% of organizations experienced a deepfake incident. Only 10% of security leaders prioritize deepfake recognition training (G00840741, n=65). The Arup deepfake CFO case (Hong Kong, 2024) cost approximately $25.6M USD (HK Police briefing).

Why this matters

Synthetic voice closes the loop after an email lure. Programs without executive verification workflows remain exposed.

What security leaders should do

Require second-channel approval for wires and credential resets triggered by voice or video.

Real-world vishing cases

MGM Resorts (September 2023): ~$100M impact estimate (SEC Form 8-K). Industry reporting describes vishing to IT help desk for MFA reset.

DBIR 2026 contributor data: Keepnet contributed anonymized voice and SMS simulation data (p. 118). Enterprise phone sim medians validate help-desk and callback playbooks.

What security leaders should measure

Weak metricBetter metric
Email click rate onlyPhone sim click rate vs ~2% DBIR median
Training completionReporting rate on callback scenarios
Generic awareness scoreRepeat failures on help-desk vishing templates

Vishing program metrics

eCrime breakout time trend (CrowdStrike 2026)

CrowdStrike average eCrime breakout time by year (Figure 3): 98 min (2021), 84 min (2022), 62 min (2023), 48 min (2024), 29 min (2025), roughly a 70% reduction from 2021 to 2025 (CrowdStrike 2026 Global Threat Report, p. 11).

Deepfake voice on live calls (Gartner G00847786)

Voice phishing now overlaps with real-time deepfake audio. Gartner's 2026 CISO role-based survey (n=297) found 41% of organizations experienced a deepfake combined with social engineering on an audio call, and 35% on a video call (Gartner G00847786). Pair those rates with DBIR phone-centric simulation medians (~2% click vs ~1.4% email) when you justify vishing program budget.

Contact center controls Gartner recommends

Beyond voice biometrics, G00847786 lists caller metadata checks, phone number intelligence, and SIM-swap detection. Programs that only simulate inbox links miss the channel where deepfake audio is scaling fastest.

Vishing extortion campaigns in 2026 (Google Threat Intelligence)

Google Threat Intelligence Group published reporting in August 2026 on a cluster it tracks as UNC6671, which runs its intrusions under several extortion brands. The detail that matters for anyone measuring vishing risk is the entry point. Almost every intrusion in that reporting starts with a phone call.

The pretext has changed. Callers pose as internal IT help desk staff and tell the employee that a FIDO2 passkey enrolment or an MFA update must be completed now. Calls go to personal mobile numbers, outside corporate call controls, and some campaigns spoof the real help desk number on the display. The employee is then sent to a lookalike enrolment page that captures the credential and the MFA response in real time.

Two things follow for anyone tracking these numbers. Targeting moved through sectors during the year, from manufacturing, real estate, healthcare and insurance early on to financial services, legal firms and private equity by mid-year, so a sector risk picture built in January was already stale by July. And the entry point was a voice call while the loss event was data theft from Microsoft 365 and Okta, which is one reason vishing rarely appears in incident records as vishing.

Why this matters

Phishing-resistant MFA is the correct control, and it is now also the story attackers tell to get in. The enrolment process itself became the social engineering surface.

What security leaders should do

Give the help desk one rule that survives a convincing call: passkey enrolment, MFA resets and other identity changes are never completed on an inbound call. Verify on a channel the caller does not control, and simulate that exact scenario instead of a generic bank fraud script.

The extortion economics behind the calls

Google Threat Intelligence Group tracked 18 Bitcoin addresses tied to the BlackFile brand between 7 January and 12 May 2026. Those addresses received 141.65 BTC, roughly 10.69 million US dollars at the time of the transactions. Initial demands ran between 1 and 3 million dollars, and operators typically agreed to reductions of 50 to 75 percent, with a final payment averaging about 750,000 dollars across 53 percent of the tracked cases.

The operational tempo is the other figure worth carrying into a board conversation. The group registered 28 root domains between 1 April and 31 May 2026, one every 2.2 days, then accelerated to one every 1.6 days through June and July, including seven domains inside a single 72 hour window between 20 and 22 July. Those are the economics of an industrialised voice phishing operation, not a scattering of opportunistic scam calls.

Source: Google Threat Intelligence Group, UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments, August 2026.

Sources

What teams should do next

Pair these statistics with operational controls: help-desk callback verification, executive corroboration rules, and voice phishing simulations baselined against DBIR medians. For the full cross-channel stat pack, read phishing statistics 2026.

SHARE ON

twitter
linkedin
facebook

Frequently Asked Questions

What is vishing?

arrow down

Vishing is voice phishing: an attacker uses a live call, a callback number or help desk manipulation to obtain credentials, codes or approvals. Because there is no message to scan, email filtering never sees it.

How common is vishing compared with email phishing?

arrow down

Pretexting, which covers synchronous voice and chat manipulation, accounted for 6% of initial access in the 2026 Data Breach Investigations Report, while phishing accounted for 16% (Verizon, 2026 Data Breach Investigations Report, 2026, p. 10 to 12). Vishing is smaller in volume and considerably more effective per attempt.

Do people fail voice attacks more often than email?

arrow down

Yes. The 2026 Data Breach Investigations Report puts the median click rate for email based simulations at roughly 1.4%, while phone centric simulations fail at roughly 40% higher (Verizon, 2026 Data Breach Investigations Report, 2026, p. 50).

How has AI changed vishing?

arrow down

Voice cloning removed the accent and hesitation that used to give attackers away. Gartner reports that 35% of organisations have experienced a deepfake incident, while only 10% of security leaders prioritise deepfake training (Gartner, "6 Ways to Transform Your Cybersecurity Awareness Program", G00840741, March 2026, n=65).

Why do email controls not stop vishing?

arrow down

Because there is nothing for them to inspect. No sender domain, no link, no attachment. The controls that work here are procedural: verification through a separate channel and a help desk process that does not reset credentials on voice alone.

How should organisations test for vishing?

arrow down

By running voice simulations alongside email, and by measuring reporting speed and repeat failure rather than a single pass rate. A programme that tests only email leaves the channel with the higher failure rate unmeasured.

Which sectors are vishing extortion groups targeting in 2026?

arrow down

Google Threat Intelligence Group reported in August 2026 that the UNC6671 cluster shifted focus during the year, from manufacturing, real estate, healthcare and insurance to financial services, legal firms, private equity and rating agencies. The pattern is less about sector than workflow. These are organisations where a single help desk call can lead to an identity change.

How much money do vishing extortion groups make?

arrow down

Google Threat Intelligence Group tracked 18 Bitcoin addresses linked to the BlackFile brand between 7 January and 12 May 2026 and recorded 141.65 BTC received, about 10.69 million US dollars at the time of the transactions. Initial demands ran from 1 to 3 million dollars and were typically settled 50 to 75 percent lower, averaging near 750,000 dollars in the cases the report tracked.

Where does Keepnet vishing data come from?

arrow down

From voice simulations Keepnet runs across its customer base. That data was contributed to the 2026 Verizon Data Breach Investigations Report, where Keepnet appears among the contributing organizations on page 118.