What is vishing?¶
Vishing is phishing carried out through a voice call or voice-message service.
The caller usually tries to persuade the victim to disclose information, approve something, install remote-access software, make a payment or help the caller gain account access.
Reconstruct what the caller actually asked for¶
The victim's account is important, especially where no recording exists.
Record:
- incoming number/display;
- time and duration;
- claimed identity;
- what the caller already appeared to know;
- what they asked the victim to do;
- what the victim actually did;
- any follow-up texts, emails or calls.
A contemporaneous note may be more reliable than a later reconstructed memory.
Caller ID and voice are not enough for identity¶
Numbers may be spoofed or internet-routed.
A familiar voice can be imitated.
Recordings or synthetic voice may be used.
So treat caller ID, accent or voice familiarity as lines of enquiry rather than identity proof.
Follow the pressure sequence¶
A common sequence might look like:
Join the call to other evidence¶
Useful sources may include:
- phone call logs;
- voicemail;
- recordings;
- telecoms/provider records;
- contact-centre records;
- remote-access logs;
- authentication events;
- payment records;
- follow-up messages.
The practical point is: vishing is a persuasion sequence delivered by voice. Reconstruct what the caller asked for and what happened afterwards, then prove caller identity from technical and wider evidence rather than the voice alone.