What is voice phishing (vishing)? - ITSAP.00.102

Vishing is a type of social engineering technique that leverages voice communication technology. In a vishing attack, threat actors or “vishers” use fraudulent phone numbers, voice altering software and other social engineering tactics to entice people to share personal and sensitive information over the phone. Advanced vishing attacks exploit Voice over Internet Protocol (VoIP) technology to create fake phone numbers and spoof the caller ID so that the call appears to be from legitimate companies or institutions. VoIP makes it easy for vishers to automate hundreds of scam calls over the internet and these numbers are hard to trace.

On this page

Vishing scams typically follow a predictable pattern. Attackers gather information, prepare a convincing impersonation and then contact the victim. Each stage is designed to make the call appear legitimate and to pressure the victim into acting quickly. Understanding these steps can help reduce the risk of being targeted.

Step 1: Information gathering

Vishers start by collecting phone numbers and background information. They often use a combination of automated tools and publicly available data. This information can support large-scale scam campaigns or more targeted attacks. In targeted vishing attempts, threat actors look for personal, work-related or role-specific details to make the call interaction more believable.

Common data collection methods include the following:

  • Dumpster diving involves retrieving discarded documents or lists of phone numbers that were not securely destroyed
  • War dialing uses automated systems to call a range of phone numbers within a specific area code to identify active lines
  • Internet searches gather information from publicly available online sources, such as social media, video platforms, professional networking sites and organizational websites
  • Data breaches expose phone numbers, contact lists and personal or organizational information that may later be sold or shared among scammers

Step 2: Impersonation and voice manipulation

Once enough information is collected, vishers prepare to impersonate a trusted source. This may involve posing as a coworker, supervisor, executive, service provider or government representative.

Threat actors often adjust their tone to match the situation to lower suspicion and encourage cooperation. They may sound:

  • calm and professional
  • urgent and authoritative
  • helpful and reassuring

Threat actors use artificial intelligence (AI) technology and short audio samples to create a simulation of a person’s voice. This technique, also known as voice cloning, allows threat actors to impersonate people the victim knows or trusts to appear more legitimate.

Step 3: Making the fraudulent call

Once vishers have manipulated a voice, they will place phone calls in a way that makes them appear legitimate and routine. The conversation is designed to move quickly and limit opportunities for verification.

Threat actors plan and execute the call in a deliberate way, using a combination of technical tricks and social pressure to steer the conversation toward a specific outcome. As part of this approach, they may:

  • spoof caller ID information so the call appears to come from a trusted phone number, internal extension, or voicemail system
  • select targets broadly or based on role and access, such as individuals who can approve payments or share sensitive information
  • rely on prepared scripts to guide the conversation and lead the victim toward a specific action
  • introduce urgency by claiming there is an immediate issue, such as a security problem, a payment concern, or a time sensitive request from leadership

This combination of legitimacy and urgency increases the likelihood that the victim will act before stopping to verify the request.

Scammers are after your:
identity, passwords and money

Vishing can be part of a larger phishing attack, another social engineering technique, to steal money or data from individuals or organizations.

To learn more about phishing, refer to Don't take the bait: Recognize and avoid phishing attacks - ITSAP.00.101 on our website.

Examples of vishing scams

Vishing aims to convince the victim to disclose confidential information, such as a personal identification number (PIN), Social Insurance Number (SIN), credit card information, or account passwords. This information can be used for identity fraud, to conduct unauthorized financial transactions, or to gain access to corporate or personal accounts. The list below provides some examples of common vishing scams:

  • Credential vishing
    • Vishers use this method to gain access to banking and credit card information. They will use these compromised credentials to login into your account, access funds, or make unauthorized purchases.
  • Government impersonation
    • Vishers pose as government employees, most frequently from departments dealing with taxes and personal finance. They will use scare tactics to convince you to pay for items like overdue or unpaid taxes or face legal consequences.
    • Vishers also pose as members of law enforcement organizations and request your personal information which they can use for identity fraud.
  • Corporate extortions
    • Posing as the boss or company CEO, vishers will convince you to comply with your boss’ request (e.g., releasing funds, authorizing approvals for access to sensitive systems).
  • Telemarketing scams
    • Posing as a telemarketer or representative of a company, vishers will congratulate you on winning a contest and then ask for you to pay a redemption fee or provide your credit card information to reserve your prize.
  • Technical support scams
    • Posing as technical support employees for various organizations, vishers will often ask for personal or employment information to verify your identity. Vishers may even ask for your permission to access your device remotely to help install software. While doing so, they can download malicious software on your device that can trigger pop-up warnings that encourage you to call a number to fix a technical or security issue.

Tips for spotting and avoiding vishing scams

The following tips outline practical steps you can take when handling suspicious phone calls.

  • Be suspicious of callers asking for sensitive information. Do not share personal or organizational information such as usernames, passwords, one-time codes or banking details over the phone, unless you are certain it is a legitimate institution.
  • Hang up and call back using a known, trusted number. If a caller claims to be from a bank, vendor, IT support or government agency, end the call and contact the organization using a publicly listed phone number or official website. Do not use numbers provided by the caller or your phone’s callback option.
  • Use verification methods like safe words or call-back codes. For workplace or families, establish a shared word, code or call-back procedure to confirm someone’s identity before discussing sensitive matters. If the caller cannot pass the verification, assume the call is not legitimate.
  • Be wary of calls from unknown numbers or automated calls. Let the call go to voicemail if you do not recognize the number. Avoid using your phone's callback function or phone numbers provided by the caller. Communicate with the site or service through a trusted contact method.
  • Watch for urgency or scare tactics. Vishers try to catch you off guard and make you feel you have no other options but to provide the requested information. Some may use threatening language to get you to act quickly. For example, they may say you must provide your information to avoid having your account deactivated.
  • Be cautious of poor audio quality or unnatural speech patterns. Calls with unusual delays, robotic voices or distorted audio may be scams. Hang up and wait to see if the caller calls back and leaves a voicemail, then verify independently.
  • Train staff and set clear phone-based verification processes. Educate employees on vishing tactics and how to respond. Put simple procedures in place for reporting suspicious calls and for verifying internal or partner requests made over the phone.
  • Use built-in phone protections. Most smartphones have spam-call filtering and call-blocking features. Enable these settings and report suspected scam calls to your phone provider when possible.
 

STIR/SHAKEN

STIR stands for Secure Telephone Identity Revisited. SHAKEN stands for Signature-based Handling of Asserted Information using toKENs. As of November 30, 2021, the Canadian Radio-television and Telecommunications Commission (CRTC) required all telecommunications providers in Canada to implement this new technology to authenticate and validate VoIP voice calls.

What does this mean?

Once your phone company implements STIR/SHAKEN they will be able to determine if a call is from a legitimate source and better inform customers of spam calls. This will enable you to make an informed decision about whether to respond to the unknown caller. As more phone companies implement STIR/SHAKEN, there should be a reduction in the volume of spam calls made over VoIP.

How to recover from a vishing scam

Vishing scams are designed to sound urgent and believable. Anyone can be affected, even people who are cautious and experienced. Acting quickly can help limit harm and protect your information.

  • Notify all your financial institutions related to the compromised accounts. Ask if the fraudulent transactions can be cancelled and block future charges.
  • Change your passwords immediately for all affected accounts as well as other accounts that used the same compromised passwords.
  • Monitor your financial accounts. Consider signing up with a credit monitoring service to alert you of potential fraudulent activity, especially if you have concerns that you've been a victim of identity theft.
  • Report the scam to the Canadian Anti-Fraud Centre (CAFC). Document the phone number of the scammer as well as any websites you were asked to visit and provide this info to CAFC.
  • Report the incident to your organization’s IT administrator if you think you might have revealed sensitive corporate information. Follow your organization's protocol for reporting cyber incidents.

Learn more

Date modified: