What is Vishing?
The latest social engineering scam explained and what you can do about it
Finn Jensen | Founder, FastPasscorp
Vishing, a shortened term for Voice Phishing, has emerged as a prevalent form of social engineering scam in recent years. This deceptive tactic involves impersonating a victim to extract sensitive details like personal information, banking credentials, financial data, credit card information, and other confidential data. Such fraudulent activities can lead to identity theft and data breaches, posing significant risks to individuals and organizations alike.
How Vishing Differs from Other Social Engineering Scams
Unlike other forms of social engineering scams that rely on emails or text messages, vishing takes advantage of the human voice to deceive individuals. It creates a sense of urgency or preys on people's trust by impersonating reputable organizations or individuals. This personal touch makes vishing attacks more convincing and difficult to identify.
In addition, vishing attacks often exploit human emotions and rely on psychological manipulation to trick victims into divulging sensitive information. Scammers may use fear tactics to make individuals believe that their personal or financial security is at risk, thus tricking them into taking immediate action.
In just a simple phone call, an attack can happen when it creates an illusion filled with emotions to avoid facts. The criminal has prepared prior to the call on what situation to create so he or she sounds like the actual victim.
Feelings are displayed to exploit by vishing hackers through a vishing scam:
- Empathy
- Pride
- Fear
- Greed
3 different types of Vishing and where it happens:
- Vishing victims through commercial channels pretending to be a consumer and tricks a customer support representative through a phone call to give away personal details like a bank account, social security, credit card, and all other financial numbers. Usually, they have a sense of urgency in their voice causing the privileged attendant to give out sensitive information.
- Corporate Vishing Scams are where victims are tricked to give away company values like a password for the victimβs accounts or do transactions for the criminalβs interest like transferring money. This often happens in some employees and mostly in top management (CEO scams).
- Another situation is where a voice phishing takes place when an important corporate user is being impersonated and calls a privileged user from the service desk to get the password for the target person = victim. See video: How to Hack the Service Desk: Reconstruction of a Real Story as Recounted by a Client
The weakest point in the defense is someone who has access privileges to the target personβs information and passwords. The help desk is the place. IT service supporters are trained to give service and do it fast β itβs an ideal profile for a common vishing victim!
Vishing is a social engineering attack. The core strategy is to elicit emotions that will make the victim give you what you ask for. It is done most of the time through a phone call.
The emotions will now dictate the victimβs actions; as a result, any critical methods-based instructions are forgotten!
Mitigation against vishing attacks must involve solutions where decisions are based on facts and not on emotions. FastPass Identity Verification Manager (IVM) is a secure workflow that takes control of the verification process.
Vishing vs Phishing
While vishing and phishing share a similar goal of stealing sensitive information, they differ in the method used to carry out the scam. Phishing typically involves sending fraudulent emails or messages that appear to be from legitimate sources, while vishing relies on phone calls to deceive victims.
Staying Vigilant: Keeping Up with Evolving Vishing Tactics
As technology advances, so do the tactics used by scammers. To stay ahead and protect yourself from vishing attacks, it is important to stay informed and follow these best practices:
- Be skeptical of unsolicited calls: If you receive a call from an unknown number or a caller claiming to be from a reputable organization, exercise caution. Do not feel pressured to provide any personal or financial information.
- Verify the source: If you receive a voice message or call that seems suspicious, independently verify the source by contacting the organization directly using a verified phone number.
- Avoid sharing personal information over the phone: Legitimate organizations will never ask for sensitive information, such as social security numbers or passwords, over the phone. Be wary of any request for such information.
- Keep software and security measures up to date: Regularly update your devices and install security updates to protect against potential vulnerabilities that scammers may exploit.
- Report suspected scams: If you believe you have been a victim of a vishing attack or have received a suspicious call, report it to your local authorities and the appropriate organizations.
By being aware of these evolving vishing tactics, you can better protect yourself from falling victim to scams. Remember, scammers are constantly adapting their strategies, so it is crucial to stay informed and remain vigilant. By following the best practices and staying educated, you can significantly reduce the risk of becoming a victim of vishing attacks.
Prevent Vishing Attacks through Identity Verification
Hackersβ tools now include voice changers for phone calls to fake target peopleβs voices, as well as telephone number spoofing and SMS copying. But hackers wonβt succeed even with these techniques if helpdesk workers follow a strict workflow with multiple verification(end user verification) tests.
The FastPass Identity Verification solution controls the entire verification process. Collecting a lot of data automatically and instructs the service desk supporter what questions to ask. Based on algorithms for the different user groups, IVM will decide when the verification is complete. The hackers canβt win by using emotional tricks against the company service desk supporter on the other end!
Know more about FastPass Identity Verification Manager (IVM) here.