Back to glossary

Vishing

1 min read

Vishing is social engineering carried out by voice call: the attacker phones a target and uses a pretext to obtain credentials, a one time code or an action such as an account reset. It is the channel where synthetic voice has changed the economics, because a convincing impersonation no longer needs a skilled caller.

July 29, 2026
Compartir:

The highest value target is rarely the individual employee. It is the service desk, because the service desk exists to help people who are locked out and is measured on how quickly it does so. A caller who can supply the details that identity verification asks for, which are often the details published on a professional network, can obtain a password reset or the re-enrolment of a second factor. That last one is how a multi-factor authentication deployment is defeated without touching a single technical control.

Voice cloning has removed the accent and confidence problems that used to limit this, and it pairs with pressure: a call that claims to come from a senior person, at a time when checking is inconvenient, asking for something the recipient has authority to do.

The control that works is procedural rather than technical. Identity verification for privileged actions has to use something the caller cannot look up, the reset of an authentication factor has to be a callback to a known number or an in person step, and staff need explicit permission to end a call and verify. When we test this channel, that permission is what we are measuring, and the report names the process rather than the person who answered. It is part of social engineering testing and of the social engineering testing that includes the phone as a channel.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.