Threat 01 · Voice channel

Vishing: when a convincing voice is the attack

Vishing—voice phishing—is a phone scam targeting people, businesses and trusted professional relationships. The caller's story may sound informed and urgent. That is the technique, not proof of identity.

What vishing is

Unlike a generic robocall, targeted voice phishing is a social-engineering operation. The criminal uses conversation to turn incomplete information into access, disclosure or action. They may spoof a displayed number, imitate a familiar cadence or simply sound calm and competent.

A strong pretext blends truth with a gap. The caller may know a client's name and matter type but not the private detail needed to complete the fraud. A helpful correction—confirming an address, balance, staff member or process—can fill that gap. That is why information leakage matters before any money moves.

Vishing can stand alone or support another compromise. A spoofed invoice email becomes more persuasive when “the supplier” calls to confirm it. A password-reset request seems routine when “IT” is already on the line. The voice channel adds pressure and apparent human legitimacy.

A useful rule

Treat the call as a claim about identity. Verify that claim independently before confirming facts, sharing a code or following an instruction.

How the vishing kill chain works

The call is only the visible middle. Breaking the chain at the pretext stage denies the attacker the next fact or action they need.

  1. 01

    Reconnaissance

    The attacker collects names, roles, suppliers, client relationships and fragments of personal data from breaches, social media, public records or earlier calls.

  2. 02

    Pretext-building

    Those fragments become a believable role and reason to call: a client under deadline, a director travelling, a bank fraud analyst, an IT technician or a supplier chasing payment.

  3. 03

    The call

    The caller controls pace and emotion. Urgency, authority, helpfulness or fear discourages the employee from pausing and checking the story through another channel.

  4. 04

    Extraction or instruction

    The caller asks for one more fact, a security code, a changed payment, a document or an exception. Small disclosures can prepare a more damaging second attempt.

The Australian context

Vishing sits inside a much larger impersonation and payment-fraud problem. The National Anti-Scam Centre's Targeting Scams 2025 report says Australians made 481,523 reports across Scamwatch, ReportCyber, IDCARE, the Australian Financial Crimes Exchange and ASIC in 2025. Reported losses totalled $2.18 billion. Those combined figures cover many scam types; they are context, not a vishing-only count.

The report also records thousands of phone numbers and sender IDs referred to telecommunications partners for disruption. That reflects the continuing importance of calls and messages in scam delivery, while avoiding the false conclusion that every attempt is visible in official reports. Unreported losses and near misses remain difficult to measure.

For a business, the important lesson is not a national probability. It is that a phone call can carry the same compromised instruction as email, while making the recipient decide in real time. A sound control must therefore test identity rather than trust the incoming channel.

Who is targeted

Any employee who answers calls or can reveal information is useful to an attacker. Reception, accounts, conveyancing, settlements, payroll, IT support and executive assistants are frequent pressure points because they connect people to money, documents and decision-makers.

Professional services firms face a double exposure. They can be the victim when an employee follows a false instruction. They can also become the vector when a criminal borrows the firm's trusted relationship to approach a client. Matter details, transaction timing and a recognisable firm name make an invented request feel routine.

Seniority does not remove the risk. Executives are attractive impersonation subjects, while junior staff may be targeted because they are expected to be helpful. Controls work best when every role has permission to pause—even when the caller claims to be important.

The cost before a transfer

Loss is not limited to money sent. A caller can gather identity data, confidential matter information, internal approval paths or the names of people worth impersonating next. The first call may be reconnaissance for a later email compromise, account takeover or client-directed scam.

That changes the safest response. Staff should not coach a failed caller by explaining which answer was wrong. They should disclose nothing further, end the interaction, preserve the evidence and use a trusted record to contact the real person.

A firm also absorbs operational and reputational damage when clients receive fraudulent calls in its name. Documented verification gives the firm a repeatable way to protect the relationship rather than relying on individual instinct under pressure.

How verification interrupts the pretext

The pretext works by keeping the target inside an environment the attacker controls: the incoming call, the supplied callback number and the story explaining why normal rules should bend. Independent verification creates a break. Instead of asking the caller to prove themselves with more facts they may already possess, the firm challenges possession through a channel tied to the real person.

Vericode sends a code to the verified phone number held for that person. The caller must obtain that code from the real device. A persuasive voice, spoofed caller ID or knowledge of public details does not provide possession. If the person cannot complete the check, staff stop without revealing what failed.

This is especially valuable early in the kill chain. The attacker may know enough to sound credible but still need one missing address, reference, contact or workflow detail. Refusing disclosure until possession is established denies that next data point. Verification is not a judgement about whether the caller sounds suspicious; it is a consistent rule applied to convincing and unconvincing calls alike.

No control makes fraud impossible. Verification should sit alongside dual approval, trusted-record callbacks, payment-change procedures, staff training and incident response. Its role is precise: interrupt the identity claim before information or instructions pass across the trust boundary.

Vishing red flags

One flag is enough to pause. Several flags do not require an argument with the caller; they require an independent check.

  • The caller creates urgency, secrecy or a fear of consequences.
  • They know some accurate details but need you to supply or confirm the rest.
  • They resist a callback to the number already held in your records.
  • They ask for a one-time code, password, client detail or internal process explanation.
  • They want an exception to an ordinary approval or payment control.
  • Caller ID, a familiar voice or professional vocabulary is offered as proof.
  • A call unexpectedly confirms instructions first received by email or message.
General information only. This threat guide is not legal, financial or incident-response advice. Follow your firm's procedures and seek professional advice for your circumstances.

Vishing tactics recur across every vertical Vericode serves. Dedicated glossary and vertical guides are planned; this page remains the canonical voice-phishing reference.