What is vishing?¶
Vishing is social engineering carried out through a voice call or voice-message service.
Avoid the dangerous assumption¶
The dangerous assumption is that a familiar caller ID, accent, organisation name or detailed knowledge proves the caller’s identity.
Telephone numbers can be spoofed. Calls can be routed through internet services. Offenders may use leaked, public or previously obtained information to sound credible.
The caller may impersonate:
- a bank
- the police
- a government department
- technical support
- a senior colleague
- a supplier
- a family member
- a service provider.
The aim may be to obtain credentials, authentication codes, payment details, remote access, account changes or a direct transfer of funds.
Investigators should preserve more than the victim’s recollection where possible.
Relevant evidence may include:
- call logs
- recordings
- voicemail
- telephone-provider records
- contact-centre recordings
- notes made during the call
- follow-up texts or emails
- account and payment activity
- remote-access software installed during the call.
Ask what the caller knew, what they asked the victim to do and which steps were completed.
Do not assume that a convincing voice proves a known person was involved. Voice imitation, recorded audio and synthetic voice technology may be relevant, but ordinary impersonation remains common.
The victim’s account is important because social engineering often depends on sequence and pressure. Record exact wording where remembered, but distinguish memory from recorded content.
The call may show a coordinated method when combined with phishing messages, account changes or payment instructions.
It will not automatically identify the caller or the location from which they operated.
Operational takeaway¶
Preserve call and follow-up records, reconstruct the sequence of requests and do not treat caller ID, voice or claimed identity as proof of who made the call.