A Single Phone Call Cost One Company $25 Million

In early 2024, a finance worker at engineering firm Arup was tricked into wiring $25 million after a video call with what appeared to be the company's CFO — deepfake technology made the voice and face indistinguishable from the real executive. That incident made global headlines, but thousands of less dramatic vishing attacks succeed every single day without ever reaching the news.

Vishing scam awareness isn't optional anymore. It's a survival skill. If your employees answer phones — and they do — they're targets. Voice phishing, or vishing, is one of the fastest-growing attack vectors because it bypasses every email filter and spam blocker you've spent money on. The threat actor simply dials in.

I've spent years watching organizations pour resources into email security while leaving their phone lines completely undefended. This post breaks down exactly how vishing works, why it's exploding in 2026, and what you can do about it right now.

What Is Vishing and Why Is It So Effective?

Vishing is voice-based phishing — a social engineering attack delivered by phone call instead of email. The attacker impersonates someone the victim trusts: a bank, the IRS, a tech support agent, or even a colleague. The goal is credential theft, financial fraud, or gaining access to internal systems.

Here's what makes vishing devastatingly effective: urgency plus authority plus human instinct. When someone calls claiming to be your CEO and says the wire transfer needs to happen in the next fifteen minutes, your brain goes into compliance mode. Email gives you time to hover over links and think. A live voice call doesn't.

The FBI's Internet Crime Complaint Center (IC3) has tracked a consistent rise in vishing-related complaints over the past several years. Their annual reports show that business email compromise and its voice-based cousin, business voice compromise, collectively account for billions in losses annually.

The 2026 Vishing Landscape: AI Made It Worse

Generative AI changed the game entirely. In my experience, the vishing calls of 2020 were clumsy — broken English, obvious scripts, background call-center noise. The vishing calls of 2026 are polished, personalized, and sometimes powered by real-time voice cloning.

Threat actors now use AI to clone a voice from as little as three seconds of audio scraped from a conference talk, podcast, or LinkedIn video. They combine this with data from breached databases to reference real account numbers, recent transactions, or internal project names. The result is a call so convincing that even security-savvy employees get caught.

Common Vishing Scenarios Your Team Will Face

  • IT Help Desk Impersonation: "We detected suspicious activity on your account. I need you to verify your credentials so I can reset your password."
  • Executive Impersonation: "This is [CEO name]. I need you to process an urgent payment. I'm in a meeting so don't email me — just handle it."
  • Bank Fraud Alert: "This is your bank's fraud department. We've frozen a suspicious transaction. Please confirm your account details to release it."
  • Vendor Payment Update: "We've changed our banking information. Please update your records before processing next month's invoice."
  • Government Agency Threat: "This is the IRS. You owe back taxes and a warrant will be issued if you don't pay immediately."

Every one of these scenarios exploits the same psychological levers: fear, authority, and urgency. That's why technical controls alone won't save you.

The $4.88M Lesson About Human-Layer Defense

IBM's Cost of a Data Breach Report has consistently shown that breaches involving social engineering carry some of the highest costs. The 2024 report pegged the global average cost of a data breach at $4.88 million. Many of those breaches started with a phone call or a phishing email — not a sophisticated zero-day exploit.

I've investigated incidents where the entire compromise chain began with a 90-second vishing call to a receptionist. The attacker got a direct dial number, called the target, and harvested VPN credentials. No malware needed. No firewall bypassed. Just a conversation.

This is exactly why security awareness training must include vishing scenarios alongside traditional email phishing. If you're only running phishing simulations via email, you're training your team for half the battle. Consider expanding your program with phishing awareness training for organizations that covers voice-based attacks as well.

How Do You Recognize a Vishing Call?

This is the question I get asked most, so here's a direct answer. You recognize a vishing call by these red flags:

  • Unsolicited urgency: The caller pressures you to act immediately and warns of dire consequences if you don't.
  • Request for sensitive data: Legitimate organizations will never ask for passwords, full SSNs, or multi-factor authentication codes over the phone.
  • Caller ID spoofing: The number looks legitimate, but caller ID can be faked in seconds with widely available tools.
  • Resistance to verification: When you say "Let me call you back on the official number," the scammer pushes back or gets aggressive.
  • Too much personal detail: The caller knows your name, role, and recent activity — this data likely came from a previous data breach or OSINT.

The single best defense: hang up and call back on a verified number. Every time. No exceptions. If it's really your bank, they'll still be there when you dial their official line.

Building Vishing Scam Awareness Into Your Security Culture

Awareness isn't a one-time training slide. It's a culture shift. Here's what actually works based on programs I've helped build:

1. Run Voice-Based Social Engineering Tests

Most organizations test their employees with email phishing simulations but never test the phones. Start running controlled vishing exercises. Track who gives up information and use those results — without blame — to target additional training. CISA's cybersecurity best practices recommend testing across all communication channels, not just email.

2. Create a Verification Protocol

Establish a clear, documented process for verifying any phone request that involves credentials, payments, or sensitive data. This should include a mandatory callback to a known number and a second-person approval for any financial transaction above a set threshold.

3. Train on Real Scenarios, Not Abstract Concepts

Generic "be careful on the phone" advice doesn't stick. Use real vishing recordings (with permission or from public sources) in your training. Let employees hear what a sophisticated social engineering call actually sounds like. Programs like the cybersecurity awareness training at computersecurity.us incorporate scenario-based learning that covers voice phishing alongside email-based threats.

4. Layer Technical Controls Where You Can

While vishing is fundamentally a human-targeting attack, technology still helps. Deploy multi-factor authentication on every system so that stolen credentials alone aren't enough. Implement a zero trust architecture that requires continuous verification. Use call-filtering solutions that flag known scam numbers. None of these are silver bullets, but they reduce the blast radius when a vishing call succeeds.

5. Report and Share Internally

Create a simple way for employees to report suspicious calls — a Slack channel, a shared inbox, a quick form. When someone reports a vishing attempt, share the details (anonymized) with the entire organization. This turns one person's close call into everyone's learning moment.

Why Ransomware Gangs Love Vishing

Here's something that doesn't get enough attention: ransomware operators increasingly use vishing as their initial access vector. Groups have been observed calling IT help desks to reset passwords, calling employees to install remote access tools, and even calling victims post-encryption to pressure ransom payment.

The NIST Cybersecurity Framework emphasizes that organizations must address social engineering as a critical component of their Identify and Protect functions. You can review their guidance at nist.gov/cyberframework. Vishing is no longer a nuisance — it's a gateway to enterprise-wide compromise.

Your Phone Is Now an Attack Surface

Every phone in your organization is an unmonitored entry point. Your email gateway logs every inbound message, scans attachments, and flags suspicious links. Your phone system does almost none of that. Threat actors know this, and they exploit it daily.

Vishing scam awareness is the countermeasure. It doesn't require a massive budget. It requires intentional, repeated training that treats voice calls as the serious attack vector they are. It requires verification protocols that become muscle memory. And it requires leadership that takes social engineering as seriously as they take ransomware — because increasingly, they're the same thing.

Start today. Brief your team this week. Run a vishing simulation this quarter. And build the kind of security culture where "let me call you back on the official number" is the default response, not the exception.