Vishing: voice phishing and callback scams explained
Not all phishing has a link. Vishing — voice phishing — uses a phone call and a human voice to do what an email cannot: apply real-time pressure, improvise around your hesitation, and sound reassuringly normal. It is low-tech and highly effective.
How vishing works
- The pretext — the caller claims to be your bank, a tax authority, tech support or a service provider.
- The hook — fraud on your account, an overdue payment, a security alert; something that demands action now.
- The ask — a one-time code, card details, remote access to your device, or a "safe account" transfer.
Callback scams and spoofed numbers
A powerful variant plants a phone number rather than a link — in an email, text or voicemail. When you dial it yourself, you arrive already trusting the call. Attackers reinforce this with caller ID spoofing, forging the number on your screen so it matches a real brand. The lesson: a familiar number is not proof of a genuine caller.
Vishing bypasses most technical filters because the payload is a conversation. The strongest defence is a simple rule: hang up and call back on a number you looked up yourself.
Where brand protection fits
Vishing often works alongside fake websites — a spoofed "support" page listing a scam phone number, or a clone that follows up the call. Removing those pages, and publishing your real contact channels clearly, cuts off the infrastructure that makes a vishing pretext believable.
Phish Plug removes the fake support pages and lookalike sites that give vishing campaigns a believable backdrop — so a scammer's story has nothing to stand on.
The takeaway
Vishing turns trust in a voice into a weapon, and caller ID into a disguise. Technical filters struggle with a conversation, so the defences are human — verify independently, never share codes — backed by removing the fake pages that prop up the pretext.
Keep reading
Related articles
Business Email Compromise (BEC), explained
BEC skips malware and targets trust: fake invoices, wire fraud and impersonated executives. How it works, why it is so costly, and how to defend against it.
Read article Threats · 7 minSpear phishing vs. mass phishing: what's the difference?
One is a net, the other a spear. How targeted spear phishing differs from mass campaigns, why it works, and what defences actually apply to each.
Read article Threats · 6 minWhaling: phishing that targets the executives
Whaling aims at leadership, where one approval moves money. How executive-targeted phishing works and the controls that stop a convincing impersonation.
Read articleProtect your brand from impersonation
Run a free clone check on one domain — Phish Plug proves the cloaking and builds the takedown case for you.