Why the phone call is quietly becoming attackers’ favorite way into your business, and what a healthy call-verification culture looks like.
Executive Summary
Voice phishing, or “vishing,” has gone from a minor nuisance to one of the fastest-growing ways attackers break into organizations. Industry trackers recorded a 442% jump in vishing volume in the back half of 2024 alone, and that momentum has carried into 2026, with Mandiant now ranking voice-based social engineering as the second most common way attackers get their first foothold in a network.
The shift makes sense from an attacker’s perspective. Email filters have gotten better. Employees have been trained for years to hover over links and check sender addresses. But a phone call still carries a strange kind of trust — a human voice on the other end feels real, urgent, and hard to say no to. Attackers know this, and they’re leaning on it harder than ever, now with AI voice-cloning tools that can mimic a real colleague’s voice from just a few seconds of audio.
This piece walks through how vishing works, why it’s succeeding right now, and the concrete steps a small or mid-sized business can take to make itself a much harder target — without needing a big security budget.
Quick Facts
| Threat Type | Voice phishing (vishing) / voice-based social engineering |
| Recent Surge | +442% in attack volume, H1 to H2 2024 (CrowdStrike) |
| 2025 Ranking | #2 most common initial infection vector in Mandiant’s M-Trends 2026 (11% of investigated breaches) |
| Top Targets | Customer support teams, executives/finance staff, remote workers, IT help desks |
| Primary Enabler | AI voice cloning — a convincing clone can be made from roughly 3 seconds of audio |
| Business Impact | Average recovery cost from a major vishing incident: $1.5 million |

A Short History: From Prank Calls to Boardroom Fraud
Voice-based social engineering isn’t new. The term “phreaking” dates back to the 1970s, when early hackers manipulated telephone systems to make free long-distance calls. By the 1990s and 2000s, social engineers like Kevin Mitnick had turned phone calls into a primary tool for talking their way past corporate security — impersonating IT staff, vendors, or executives to extract passwords and access.
For a long time, vishing stayed a relatively low-volume, high-skill tactic because it required a real human to make a convincing, live call. That changed with two developments: cheap, scalable robocall infrastructure that let scammers blast thousands of calls a day, and, more recently, generative AI that can clone a specific person’s voice or hold a natural, adaptive conversation without a human operator on the line at all.
The result is a threat that has quietly scaled from opportunistic gift-card scams targeting retirees to sophisticated, targeted operations aimed at finance departments, IT help desks, and corporate executives — the same infrastructure now supports both.
How Today’s Vishing Attacks Actually Work
Modern vishing rarely looks like the crude “your car’s extended warranty” robocall most people picture. Attackers now use a handful of well-tested patterns:
• Caller ID spoofing — used in the large majority of vishing attempts — makes the call appear to come from a trusted internal extension, a known vendor, or even the company’s own IT help desk.
• Callback phishing sends an email or text asking the recipient to call a number to resolve a fake invoice, subscription, or security alert — sidestepping email link-scanning entirely, since the malicious step happens over the phone.
• Help desk impersonation, in either direction: attackers call pretending to be IT asking an employee to “verify” credentials, or call a company’s actual help desk pretending to be an employee locked out of an account, pressuring staff to reset a password or MFA device on the spot.
• AI voice cloning and deepfake calls now let attackers impersonate a specific executive’s voice — or even join a video call with a synthetic face and voice — to authorize a wire transfer or urgent request. One widely reported case involved a $25 million fraudulent transfer after a finance employee joined a video call where every participant’s face and voice had been artificially generated.
Why It’s Working So Well Right Now
Three trends are converging to make vishing unusually effective in 2026:
1. Voice still “feels” trustworthy. Employees have been trained for years to distrust suspicious emails and texts, but a live phone call, especially one that sounds like a familiar voice, doesn’t trigger the same skepticism.
2. AI has collapsed the cost and skill needed to run a convincing attack. Voice-cloning services and AI phone agents are now sold as commercial and criminal tooling, meaning an attacker no longer needs to be a native speaker, sound convincing, or even be awake — automated voice agents can run vishing calls and one-time-passcode theft at scale.
3. Support and recovery workflows are the soft target. Many of today’s most effective vishing attacks don’t try to steal a password directly; they manipulate a help desk or support agent into resetting one, bypassing multi-factor authentication altogether by exploiting the human process behind it.
| WHY THIS MATTERS FOR SMALL BUSINESS You don’t need to be a Fortune 500 company to be a target. Customer support teams and remote workers show some of the highest susceptibility to vishing of any employee group — and small businesses often have thinner call-verification procedures than large enterprises, making them an efficient target rather than an unlikely one. |
MITRE ATT&CK Mapping
For technical teams tracking this threat against a standard framework, vishing activity most commonly maps to the following techniques:
| Tactic | Technique | ID |
| Initial Access | Phishing: Voice Phishing | T1566.004 |
| Initial Access / Persistence | Trusted Relationship (impersonating IT/vendor) | T1199 |
| Credential Access | Multi-Factor Authentication Request Generation / Social Engineering of Support Staff | T1621 (related) |
| Defense Evasion | Impersonation | T1656 |
Resolution: Building a Call-Verification Culture
The good news is that vishing is one of the more defensible threats out there, because the fix is largely procedural rather than purely technical. Recommended steps for any small or mid-sized business:
• Establish a callback verification rule: any request involving credentials, payments, or account changes made by phone must be verified by calling the person back on a known, previously stored number — never a number given during the call.
• Create a shared “code word” or verification question for high-risk requests (wire transfers, password resets, executive requests) that isn’t posted anywhere public.
• Harden your help desk’s identity-verification process for password and MFA resets so that a convincing voice or urgent tone alone can never authorize a reset.
• Train staff — especially customer-facing, finance, and IT support roles — to expect urgency and authority as red flags, not reasons to comply faster.
• Register company numbers with caller ID authentication where possible, and treat caller ID as unverified information, not proof of identity.
• Run periodic vishing simulations, the same way you’d run phishing email tests, so staff experience the pressure tactics in a safe setting first.
The Bottom Line for Small Business Owners
Vishing succeeds because it exploits trust, urgency, and the assumption that a real voice means a real person with legitimate authority. Neither is guaranteed anymore. The businesses best protected against this trend aren’t necessarily the ones with the biggest security budgets — they’re the ones with a simple, well-practiced rule: if a phone call asks for credentials, payment, or account changes, verify it independently before acting, every single time.
• Put a callback-verification policy in writing and share it company-wide this month.
• Brief your help desk or IT support team specifically — they are the highest-value target for this tactic.
• If something feels off during a call, it’s always acceptable to hang up and call back on a known number.



