Vishing, or voice phishing, is a type of phishing attack carried out by phone or voice message – it can be a voice message, a video call, or a phone call. It’s used against businesses and individuals to steal data and money, or launch further scams.
A person’s voice is no longer trustworthy. And with AI voice cloning, attackers can impersonate a family member or a close friend with ease, sounding familiar enough to not raise any suspicion.
AI voice cloning makes it more important than ever for businesses to strengthen their defenses against vishing scams. A convincing fake voice can be used to impersonate executives, employees, suppliers, or customers, increasing the risk of fraudulent payments, credential theft, account takeover, data breaches, and disruption to internal operations.
Because these attacks can exploit normal business processes and trusted relationships, organizations need verification procedures that do not rely on whether a caller sounds familiar or convincing.
- What is vishing?
- How does vishing work?
- AI makes vishing harder to detect
- Common vishing examples targeting businesses
- The credential connection
- Exposed data makes vishing more convincing
- How to verify a suspicious call
- Build vishing awareness around tactics, not scripts
- What to do after a suspected vishing call
- How Proton Pass for Business helps reduce credential risk
What is vishing?
Vishing is a type of phishing carried out over the phone or through voice messages. Scammers impersonate trusted people or organizations, such as banks, employers, government agencies, or family members, to trick victims into sharing sensitive information, sending money, or taking some other action.
The name comes from “voice” + “phishing.” It is closely related to smishing, which uses SMS or text messages instead of voice calls to carry out similar scams.
Today, vishing can also involve AI voice cloning, which lets scammers imitate a real person’s voice and make the call sound more convincing.
How does vishing work?
Vishing usually works by combining impersonation, social engineering, and urgency. It relies on the pressure of a live conversation to push someone into acting before they have time to verify a request. A caller might pretend to be from IT and ask to confirm a login, pose as a bank employee checking a suspicious transaction, or impersonate a senior executive who urgently needs a payment approved.
Unlike phishing emails, there may be no suspicious link, attachment, or unfamiliar sender address to inspect. The caller may sound calm, convincing, or even familiar, especially if AI voice cloning is involved.
The goal is usually to persuade the victim to reveal credentials or one-time codes, approve a transfer, reset account access, or bypass a normal security process. In a business setting, that could mean tricking finance staff into authorizing a payment, impersonating IT support to collect login details, or convincing an employee to give an attacker access to a company account.
AI makes vishing harder to detect
Traditional vishing scams often gave themselves away through poor scripts, obvious threats, noisy call centers, or callers who simply did not sound convincing. Some still do. But businesses can no longer treat voice quality, confidence, or familiarity as reliable signs that a call is genuine.
AI voice cloning makes it possible to imitate real people closely enough to create believable requests. Attackers can combine a cloned voice with caller ID spoofing and personal details gathered from LinkedIn, company websites, public interviews, social media, or previous data breaches.
That makes familiar voices especially risky as a trust signal. People naturally judge callers by tone, confidence, hesitation, or whether the voice sounds like someone they know. AI can reproduce many of those cues, making an impersonated executive, colleague, vendor, or IT employee sound calm, rushed, authoritative, or concerned.
In 2025, the FBI warned(nowe okno) that malicious actors were using smishing and AI-generated voice messages to impersonate senior US officials, build trust, and try to gain access to personal accounts.
For businesses, attackers do not need a perfect imitation. They only need a call convincing enough to trigger an action, such as approving a payment, sharing a verification code, resetting a password, or changing account access.
That is why sensitive requests should be verified through another trusted channel, even when the caller sounds exactly like someone the employee knows.
Common vishing examples targeting businesses
Vishing works best when the request feels plausible. Attackers often choose scenarios that fit normal business routines, then add urgency. Here are common vishing examples:
IT support impersonation
One common scenario is IT support impersonation. An employee receives a call from someone claiming to be from the company’s helpdesk, software provider, or security team. The caller may say there is a login issue, an urgent update, suspicious activity, or a migration that requires the employee to confirm credentials or read out a one-time code.
Finance impersonation
Finance impersonation is another high-risk pattern. A caller pretends to be the CEO, CFO, a senior manager, or a trusted supplier that asks for a payment to be processed quickly. The pressure may be framed as confidential, time sensitive, or linked to a deal, invoice, tax issue, or vendor problem.
Bank fraud calls
Bank fraud calls are also common. The caller claims to be from the company’s bank and warns about suspicious transactions. The employee is asked to confirm details, approve a security step, move money, or provide information that allows the attacker to access the account later.
Government impersonation
Government impersonation can affect businesses too. Calls involving His Majesty’s Revenue and Customs (HMRC), the UK’s tax authority, are common enough that HMRC provides a dedicated route to report suspicious phone calls(nowe okno). A caller may mention tax deadlines, VAT, payroll, penalties, refunds, or investigations to create urgency.
Supplier and customer impersonation
There are also supplier and customer impersonation calls. A criminal may pretend to be a vendor changing payment details, a client requesting access to a portal, or a partner asking for a document link. The call may not ask for money immediately. It may only aim to collect information for a later attack.
The credential connection
Vishing often ends at credentials, even when it starts as a conversation. An attacker may ask directly for a password, but many vishing attempts are more subtle. The caller may ask an employee to confirm a username, read out a verification code, approve a two-factor authentication (2FA) prompt, or log in to a fake portal while the caller stays on the line.
Once credentials are exposed, the damage depends on what those credentials can unlock. A reused password can give the attacker access to more than one service, for example. A shared login can make it harder to know who used the account, and a missing 2FA requirement can leave a password as the only barrier. An over-permissioned account can turn one successful call into broader access.
Credential hygiene is an essential part of vishing attack prevention. Unique passwords for every service limit how far a stolen password can travel. A business password manager reduces the need for employees to remember or reuse passwords, and a built-in password generator makes it much easier to create strong, unique passwords for every account. Secure sharing keeps credentials out of calls, chats, and documents. 2FA adds another barrier when a password is compromised.
Why exposed data makes vishing more convincing
A vishing call is more persuasive when the attacker already knows something about the business. That information may come from public sources: job titles, suppliers, executives, company structure, press releases, social media posts, conference videos, podcasts, or employee profiles.
It may also come from leaked or stolen data, including email addresses, phone numbers, account details, exposed credentials, or internal documents.
Our Data Breach Observatory shows how exposed data can create risk beyond the original breach. A criminal only needs a phone number, a job title, a vendor name, and an old password to seem credible.
Employees may have reused details elsewhere, suppliers may have been compromised, or attackers may combine multiple public and leaked sources to build a believable story. In practice, businesses should treat exposed data as fuel for future scams. The more an attacker knows, the less the call sounds random.
How to verify a suspicious call
If you’re suspicious, end the call and verify for yourself whether the request was genuine. Vishing depends on keeping you on the line, encouraging you to answer now and act now. Verification only works when the employee can pause, leave that pressure, and return through a channel the business already trusts.
For any request involving credentials, payments, 2FA codes, remote access, bank details, account recovery, or permission changes, end the call and check the request separately. That may mean calling the person back using the company directory, contacting the bank through the number on its official website, opening an internal IT ticket, or checking supplier details already stored in the company’s records.
The callback number should never come from the caller. Caller ID is not enough either, because numbers can be spoofed. The point is to return to a trusted source, rather than continuing a conversation the attacker may be controlling.
Legitimate executives, suppliers, banks, and IT teams should expect verification for sensitive requests. A caller who becomes aggressive, demands secrecy, or refuses a callback is giving the employee a reason to stop, not a reason to move faster.
Build vishing awareness around tactics, not scripts
Awareness training for vishing should not only teach people to recognize a list of scam phrases. Scripts change quickly. The manipulation patterns are more stable.
Employees should learn to recognize the tactics behind the call, not just the script. They also need tactics of their own to fall back on when they’re unsure:
- If a caller makes them feel rushed, anxious, or responsible for fixing something immediately, that is a tactic, not proof of urgency. A caller may claim to be a senior executive, a bank fraud investigator, a tax authority, a supplier, or a security team member. The story can change, but the pressure often looks similar: act now, keep this confidential, trust my authority, and bypass the usual checks.
- Training also needs to include AI voice cloning. The message should be clear without creating panic: a familiar voice is not enough to authorize a risky action. Employees should be taught that they have the right to pause. If a caller asks for a payment, credential, code, access change, or urgent workaround, the safe response is to stop the conversation, ask for a few minutes, and verify the request through a known number or another trusted channel.
- A safe phrase, callback rule, or written approval workflow is more reliable than trying to judge whether someone sounds “off.” No legitimate urgent request should fail because of a short delay used for verification.
What to do after a suspected vishing call
A suspected phone phishing scam should be reported quickly, even when no money was sent and no password was shared. Near misses are useful because they show which employees, suppliers, or processes attackers may be targeting.
The first step is to record the details:
- Time of the call
- Number displayed
- Caller claim
- Requested action
- Names mentioned
- Systems involved
- Whether any information was shared.
Make sure that the number provided by the caller is not contacted again.
If credentials, one-time codes, payment details, or remote access were shared, treat it as urgent:
- Reset affected passwords
- Revoke sessions where possible
- Review account activity
- Enforce 2FA
- Check whether the same password was used anywhere else.
How Proton Pass for Business helps reduce credential risk
Vishing is a human attack, but the damage often depends on credential controls such as passwords, shared access, and account protection. A business password manager like Proton Pass for Business helps teams reduce the risk that one successful call turns into broader access.
Employees can generate strong, unique passwords for every service through Proton Pass’s built-in password generator, store them in encrypted vaults, use autofill, share credentials securely, manage passkeys, and use built-in two-factor authentication.
This is valuable for vishing protection, because even if an attacker gets your password during a call, they still can’t get into the account without the second factor. Proton Pass also includes Pass Monitor with dark web monitoring, which alerts you if your email appears in a known data breach, so you know when credentials may already be compromised.
Proton Pass also gives businesses a safer default for day-to-day access. When employees have an approved way to store and share credentials, a caller asking them to read out a password or send access through chat should immediately feel unusual.
Make voice requests verifiable by default
Vishing works because the voice feels immediate and personal. A caller can sound confident, familiar, helpful, or authoritative. AI voice cloning makes that trust even less reliable. Businesses need a verification habit that does not depend on how convincing the caller sounds.
The most important rules are simple: do not share credentials on a call, do not approve unusual payments from a phone request alone, and do not trust caller ID as proof of identity. Hang up, verify through a known channel, and document anything suspicious.
For SMBs, the process can stay simple. Sensitive requests should have a callback rule, payments and access changes should require confirmation through another channel, and employees should know the authority and urgency tactics that make vishing convincing. Credentials also need to stay inside a business password manager, where passwords are unique, shared securely, and easier to rotate if a call leads to exposure.
Voice phishing will keep evolving, especially as AI makes impersonation cheaper and more convincing. The defense is to make every sensitive request verifiable before anyone acts.
Protect your business credentials from voice phishing with a business password manager.






