A Single Phone Call Cost MGM Resorts $100 Million

In September 2023, a threat actor called MGM Resorts' IT help desk, impersonated an employee found on LinkedIn, and convinced a technician to reset credentials. That one vishing call triggered a ransomware attack that shut down slot machines, hotel key cards, and reservation systems across Las Vegas for ten days. The estimated cost exceeded $100 million.

That's why vishing scam awareness isn't optional anymore — it's a survival skill for every organization with a phone line. And if you think your team wouldn't fall for it, I'd ask you to reconsider. I've watched seasoned IT professionals hand over MFA codes to a convincing caller. It happens more than anyone wants to admit.

This post breaks down exactly how vishing attacks work in 2026, why they're surging, and what concrete steps you can take to harden your people against them.

What Is Vishing and Why Is It Exploding?

Vishing — short for "voice phishing" — is a social engineering attack delivered by phone call. The attacker impersonates a trusted entity: your bank, the IRS, a vendor, your own IT department. The goal is credential theft, financial fraud, or gaining a foothold into your network.

According to the FBI's 2023 Internet Crime Complaint Center (IC3) report, Americans reported over $10 billion in cybercrime losses, with call center fraud and tech support scams among the fastest-growing categories. The Verizon 2024 Data Breach Investigations Report found that 68% of all breaches involved a human element — and voice-based social engineering is a major contributor to that number.

Why the surge? Three reasons. First, AI-powered voice cloning now lets attackers mimic specific people with just a few seconds of sample audio. Second, caller ID spoofing is trivially easy. Third, most security awareness programs still focus almost exclusively on email phishing and ignore the phone entirely.

How a Vishing Attack Actually Works

Step 1: Reconnaissance

Threat actors start by mining LinkedIn, company websites, and data breach dumps. They identify targets — usually help desk staff, finance teams, or executives — and gather enough personal details to sound legitimate. A name, a department, an employee ID number. That's often all it takes.

Step 2: The Pretext Call

The attacker calls with urgency. Common pretexts I've seen in incident response work include:

  • "This is IT. We're seeing suspicious activity on your account and need to verify your identity."
  • "This is your bank's fraud department. We need to confirm a transaction before we lock your account."
  • "This is [CEO's name]'s assistant. We need a wire transfer processed immediately for a deal that's closing today."

The caller creates time pressure. They discourage the target from hanging up or verifying through another channel. They already know enough about the organization to sound credible.

Step 3: The Extraction

The attacker extracts what they need: a password reset, an MFA code, a wire transfer, or remote access to a workstation. In many cases, the victim never realizes anything happened until the damage is done.

The $4.88M Lesson Your Organization Can't Afford

IBM's 2024 Cost of a Data Breach Report pegged the global average cost of a data breach at $4.88 million — an all-time high. Social engineering attacks, including vishing, consistently rank among the most expensive breach vectors because they bypass technical controls entirely.

I've investigated breaches where the organization had best-in-class firewalls, endpoint detection, and zero trust architecture — and still got compromised because someone answered a phone call and trusted the voice on the other end. Technology alone doesn't solve this. Your people are your perimeter, and vishing scam awareness is how you fortify it.

Who Gets Targeted Most?

If you think vishing only targets grandparents, think again. In my experience, the most common corporate targets are:

  • IT help desk staff — trained to be helpful, often lacking verification protocols for inbound calls.
  • Finance and accounts payable teams — high-value targets for wire fraud and business email compromise (BEC) variants conducted over the phone.
  • C-suite executives — targeted in "whale vishing" attacks where AI-cloned voices impersonate board members or partners.
  • New employees — unfamiliar with internal processes and eager to comply with authority figures.

How Do You Protect Against Vishing Scams?

This is the section that matters most. Here's what actually works based on real-world deployments I've been involved in:

1. Build Vishing into Your Security Awareness Program

Most organizations run email phishing simulation exercises but completely ignore voice-based attacks. That's a massive blind spot. Your training program should include vishing scenarios — recorded examples, live simulations, and tabletop exercises where employees practice verifying callers.

2. Establish a Verbal Verification Protocol

Create a policy: no sensitive action (password resets, wire transfers, access grants) based solely on an inbound phone call. Every request must be verified through a separate, pre-established channel. Call back using the number on file, not the number the caller provides. This single control would have prevented the MGM breach.

3. Deploy Multi-Factor Authentication That Resists Vishing

SMS-based MFA codes are the exact thing vishing attackers ask for. Move to phishing-resistant MFA — FIDO2 security keys or passkeys — wherever possible. CISA's MFA guidance explicitly recommends hardware-based authentication over SMS or voice-based one-time codes.

4. Train Specifically on AI Voice Cloning

Your employees need to understand that a familiar voice on the phone no longer guarantees identity. AI voice cloning tools are publicly available and improving rapidly. Establish code words or challenge-response phrases for high-risk communications within your leadership team.

5. Report and Analyze Every Attempt

Create a simple, no-blame reporting mechanism for suspected vishing calls. Every reported attempt is intelligence. Track patterns — are attackers targeting a specific department? Using a specific pretext? This data shapes your next round of training.

Vishing Scam Awareness Starts with Continuous Training

A once-a-year compliance video won't cut it. Threat actors evolve their tactics constantly, and your training has to keep pace. The most effective programs I've seen combine regular phishing and vishing simulations with short, scenario-based modules delivered monthly.

If you're building or upgrading your program, our cybersecurity awareness training platform covers social engineering across all channels — email, voice, SMS, and in-person pretexting. It's designed for the threats your team actually faces, not the ones they faced five years ago.

What Should You Do If You Get a Suspicious Call?

Keep this checklist handy and share it with your teams:

  • Don't comply under pressure. Legitimate callers won't penalize you for verifying their identity.
  • Hang up and call back. Use the official number from the organization's website, never a number provided by the caller.
  • Never share MFA codes, passwords, or PINs over the phone. No legitimate organization will ask for these.
  • Verify unusual requests through a second channel. If your "CEO" calls requesting a wire transfer, confirm via email, Slack, or in person.
  • Report every suspicious call to your security team, even if you didn't fall for it.

The Zero Trust Mindset Applies to Phone Calls Too

Zero trust isn't just a network architecture concept. It's a philosophy: never trust, always verify. That applies to every inbound phone call, every voicemail, every text message. The voice on the other end of the line is not proof of identity.

The NIST Zero Trust Architecture framework (SP 800-207) establishes the principle that no actor should be implicitly trusted. Your employees need to internalize this — not as paranoia, but as professional discipline.

Your Phone Is Now an Attack Surface

Email security has gotten significantly better over the past decade. Spam filters catch most phishing emails. URL scanning blocks many malicious links. So threat actors adapted. They picked up the phone.

Vishing scam awareness is the gap in most organizations' defenses right now. The attacks are getting more sophisticated with AI voice cloning, more targeted with open-source intelligence, and more damaging as they bypass technical controls entirely.

The fix isn't complicated, but it requires commitment: train your people on voice-based threats, establish verification protocols, deploy phishing-resistant MFA, and build a culture where questioning a caller's identity is encouraged, not punished.

Your firewall can't hang up the phone for your employees. But the right training can teach them to do it themselves.