The Phone Call That Cost MGM Resorts $100 Million
In September 2023, a threat actor called MGM Resorts' IT help desk, impersonated an employee found on LinkedIn, and convinced a technician to reset credentials. That single vishing call — a voice phishing attack — triggered a ransomware event that shut down slot machines, hotel key systems, and reservation platforms across Las Vegas. MGM disclosed over $100 million in losses. One phone call.
Vishing scam awareness isn't a nice-to-have anymore. It's a survival skill for every employee who picks up a phone or answers a Teams call. This post breaks down exactly how vishing attacks work in 2026, the psychological tricks attackers exploit, and the concrete steps your organization needs to take right now.
What Is Vishing and Why Is It Exploding?
Vishing — short for voice phishing — is a social engineering attack conducted over the phone. The attacker poses as someone trustworthy: a bank representative, an IT support technician, a government agent, or even your CEO. The goal is always the same: extract sensitive information, steal credentials, or trick someone into authorizing a fraudulent transaction.
The FBI's Internet Crime Complaint Center (IC3) has tracked a sharp rise in phone-based social engineering. Their 2023 report documented over $10 billion in total cybercrime losses, with impersonation and tech support scams among the fastest-growing categories. And those numbers only reflect what gets reported.
Why the explosion? Three factors converge in 2026. AI voice cloning makes impersonation frighteningly convincing. Caller ID spoofing is trivially easy. And most organizations still train employees exclusively against email phishing while ignoring the phone entirely.
How a Vishing Attack Actually Works
Step 1: Reconnaissance
Attackers don't call blindly. They scrape LinkedIn for employee names, titles, and reporting structures. They harvest phone numbers from company websites, data broker sites, and previous data breach dumps. By the time they dial, they already know your name, your manager's name, and probably your role.
Step 2: Pretext Construction
The attacker builds a believable story — the pretext. Common ones I've seen in incident response engagements include:
- "This is IT support. We detected unusual login activity on your account and need to verify your credentials."
- "This is [CEO's name]'s office. We need an urgent wire transfer approved before end of business."
- "This is your bank's fraud department. We're seeing suspicious charges and need your account number to freeze the card."
- "This is the IRS. You have an outstanding tax liability and a warrant will be issued unless you resolve it now."
Step 3: Pressure and Extraction
Every vishing call weaponizes urgency, authority, or fear. The caller creates time pressure — "We need this resolved in the next 10 minutes or your account will be locked." They invoke authority figures. They threaten consequences. Under that pressure, even trained employees hand over passwords, multi-factor authentication codes, or financial details.
Step 4: Exploitation
Once the attacker has what they need, they move fast. Stolen credentials get used within minutes for account takeover. Wire transfers disappear into mule accounts. MFA codes unlock corporate email. In many cases, the vishing call is just the entry point for a broader ransomware deployment or data breach.
AI Voice Cloning: The 2026 Vishing Multiplier
Here's what keeps me up at night. In 2024 and beyond, threat actors started using AI-generated voice clones in vishing attacks. With as little as three seconds of audio — pulled from an earnings call, a podcast appearance, or a social media video — attackers can generate a convincing replica of someone's voice.
I've reviewed cases where a CFO received a call from what sounded exactly like the CEO, instructing an emergency funds transfer. The voice was synthetic. The money was real. CISA has issued guidance on this evolving threat, emphasizing the need for out-of-band verification for any sensitive request, regardless of how legitimate the caller sounds. Their cybersecurity best practices page is a solid starting point.
The $4.88M Lesson Most Organizations Learn Too Late
According to IBM's 2024 Cost of a Data Breach Report, the global average cost of a data breach hit $4.88 million. Social engineering — including vishing — was a leading initial attack vector. And breaches involving social engineering took an average of 257 days to identify and contain.
The math is brutal. One untrained employee. One convincing phone call. Months of undetected access. Millions in damages. That's the cost of ignoring vishing scam awareness.
How to Build Real Vishing Scam Awareness
Train Beyond Email
Most security awareness programs focus almost exclusively on email phishing. That's necessary but insufficient. Your employees need to recognize social engineering across every channel — phone, text, video call, and in-person. A comprehensive cybersecurity awareness training program should cover vishing scenarios specifically, not just email-based threats.
Run Vishing Simulations
Phishing simulation campaigns are standard practice. Vishing simulations should be too. Call your own employees using realistic pretexts and measure how they respond. Do they verify the caller? Do they refuse to share credentials over the phone? Do they report the call? You'll learn more from one simulation than from a hundred slide decks. Pair this with structured phishing awareness training for your organization to cover both email and voice attack vectors.
Establish Verification Protocols
Every organization needs a clear, enforced policy: no sensitive action based on a phone call alone. Period. If someone calls requesting a password reset, a wire transfer, or access to a system, the employee must verify through a separate channel. Call back on a known number. Confirm via internal chat. Walk to the person's desk. This single control stops the majority of vishing attacks cold.
Implement Multi-Factor Authentication Everywhere
MFA won't stop every vishing attack — attackers increasingly talk victims into reading MFA codes aloud. But phishing-resistant MFA methods like FIDO2 hardware keys eliminate this risk entirely. If you're still relying on SMS codes, you're exposed. The NIST Cybersecurity Framework recommends phishing-resistant authentication as a baseline control.
Adopt Zero Trust Principles
Zero trust means never trusting a request based solely on who the caller claims to be. Verify identity. Validate authorization. Confirm through independent channels. This mindset applies to every interaction — digital or voice. When your culture defaults to "trust but verify," vishing attackers lose their primary weapon: assumed trust.
What Should You Do If You Receive a Suspicious Call?
This is the question most people search for, so here's a direct answer:
- Don't provide any information. Never share passwords, MFA codes, account numbers, Social Security numbers, or financial details over the phone — even if the caller seems legitimate.
- Hang up. It's not rude. It's security. A legitimate caller will understand.
- Verify independently. Look up the organization's real phone number and call back directly. Never use a number the caller provides.
- Report it. Tell your IT or security team immediately. If it's a personal call, report it to the FTC at ftc.gov or the FBI's IC3.
- Document everything. Note the caller's number, what they said, and what they asked for. This helps your security team and law enforcement investigate.
Red Flags That Scream Vishing
Train your people to recognize these patterns:
- Unexpected calls claiming urgency — "Your account will be closed in one hour."
- Requests for passwords, PINs, or MFA codes. No legitimate organization asks for these by phone.
- Caller ID showing a familiar name but the conversation feels off.
- Threats of arrest, lawsuits, or account suspension.
- Pressure to stay on the line and not hang up to verify.
- Requests to install remote access software.
Any one of these should trigger an immediate hang-up and report.
Vishing Is Social Engineering's Oldest Trick — Updated
Phone scams aren't new. What's new is the sophistication. AI voice cloning, VoIP spoofing, and publicly available personal data make 2026's vishing attacks harder to detect than ever. Your email filters can't catch them. Your firewall can't block them. Your endpoint protection won't flag them.
The only defense is a trained human who recognizes the attack and responds correctly. That's why vishing scam awareness deserves the same investment and attention you give to credential theft prevention, ransomware readiness, and every other security priority.
Start with your people. Train them on voice-based social engineering. Run simulations. Enforce verification protocols. Build a culture where questioning a caller's identity isn't paranoia — it's policy.
Because the next vishing call targeting your organization isn't a matter of if. It's a matter of when.