Vishing (voice phishing)
In plain terms
Phishing by voice. Nothing is written, nothing can be reread, and the caller moves at their own pace while you have to respond at yours. That imbalance is what makes it work.
Definition
Vishing refers to phishing carried out by phone call: a caller presents themselves as a trusted organization and obtains, during the conversation, information or actions a written message wouldn't have obtained.
How it works
The phone strips the victim of everything they'd rely on elsewhere. There's no sender address to examine, no link to hover over, no text to reread with a clear head: the decision has to be made while the other person is talking. The caller controls the pace, and the silence they leave after a request weighs more than an argument. The number shown proves nothing, since it can be spoofed, but it's perceived as proof. The conversation itself builds trust: a polite caller who knows your name and two accurate details seems legitimate, though those details often come from an earlier data leak. Scenarios vary — bank, government agency, tech support, carrier — but the lever stays constant: get an action while the line is still open.
Warning signs
- Unsolicited call asking you to share, enter, or validate something immediately
- Insistence on staying on the line while the requested action happens
- Refusal or discouragement when you offer to call back yourself
- Number displayed matching a known organization, presented as proof of identity
- Caller who knows a few accurate details about you and uses them as credibility
- A pretext built to justify secrecy: an ongoing investigation, a confidential procedure
How to verify
Taking back the initiative of the call is the only verification that works on the phone, and it always works. Hang up, then dial a number you already had — on the back of a card, in an official app, on a letter you received. Wait a few minutes or use another line: a line can stay open if you don't hang up firmly.
What to do
Don't share any code, password, or banking information during an incoming call. Don't install anything and don't approve any notification at the request of someone calling you. No legitimate caller will hold it against you for calling back.
If it already happened
Depending on what was shared: contact your bank to block the card, immediately change the affected passwords from another device, revoke active sessions. Note the time of the call and the number displayed, then file a police report. Report the incident to the relevant authority.
Test yourself
A fraud-department representative calls you. They ask for no password.
Start the simulationFrequently asked questions
- What's the difference with the "fake bank advisor" fiche?
- This page describes the technique — why the phone is favorable ground for the attacker, whatever the pretext. The "fake bank advisor" fiche describes a specific scenario, the call from a supposed anti-fraud department, with its own signals and steps to follow.
- How can I tell if a call from my bank is genuine?
- You can't tell during the call, which is exactly why the question shouldn't be framed that way. Hang up and call the number on the back of your card: if the request was real, it will be confirmed; if it wasn't, you'll have lost nothing.
- The caller knew my name and my recent transactions.
- Accurate information can come from an earlier data leak, a compromised account, or intercepted mail. It makes the call credible without proving anything: knowing a detail is not proof of identity.
Related attacks
Official sources
This article is part of the Social engineering family. Last updated: 2026-09-02.