Vishing
Vishing is a type of social engineering attack that uses voice communication (phone calls) to trick individuals into revealing personal information, passwords, or financial details. The term is a combination of "voice" and "phishing."
Key Characteristics
- Voice-Based: Uses phone calls as the attack vector
- Social Engineering: Relies on psychological manipulation
- Caller ID Spoofing: Often displays fake or legitimate-looking caller IDs
- Authority Impersonation: Impersonates officials, banks, or service providers
Advantages (for attackers)
- Personal Interaction: More persuasive than written communication
- Immediate Response: Creates pressure for immediate action
- Trust Exploitation: Voice can create more trust than text
- Technology Exploitation: Uses VoIP and caller ID spoofing tools
Disadvantages
- Personal Information Theft: Can lead to identity theft and fraud
- Financial Loss: Direct access to banking and financial information
- Emotional Manipulation: Exploits fear, urgency, or trust
- Technology Vulnerability: Exploits weaknesses in phone systems
Best Practices
- Never provide personal information over unsolicited calls
- Verify caller identity through independent channels
- Be wary of urgent or threatening language
- Use call blocking and identification services
Use Cases
- Impersonation of bank representatives
- Government agency impersonation scams
- Technical support fraud
- Tax authority impersonation