Vishing is voice phishing. A criminal uses a phone call, voicemail, or another voice channel to deceive someone into providing money, credentials, security codes, or device access, often by impersonating a trusted organization or person. The caller may know personal details and may manipulate caller ID. Neither proves who is calling.
How does vishing work?
The caller creates a problem that seems to require immediate action. Common stories include an unauthorized bank charge, compromised Social Security number, unpaid tax, hacked computer, family emergency, or suspicious online order. The caller then offers a solution that benefits the scammer: reveal a code, transfer money, buy gift cards, install remote-access software, or move funds to a supposed safe account.
Some campaigns begin with a text or email and ask the target to call. Others use an automated menu to collect information before transferring the call to a person. Artificially generated voices may imitate relatives or employees, so voice familiarity alone is no longer a sufficient identity check.
Warning signs of a vishing call
- The contact was unexpected and the caller creates a deadline.
- The caller asks for a password, PIN, card number, or one-time code.
- You are told to transfer money to protect it.
- Payment must be made by gift card, cash, cryptocurrency, wire transfer, or payment app.
- The caller asks you to install remote-access software or share your screen.
- You are threatened with arrest, deportation, account suspension, or loss of benefits.
- The caller tells you to keep the matter secret or remain on the line while paying.
- The callback number comes only from the caller, voicemail, text, or search advertisement.
The FTC notes that scammers can make almost any name or number appear on caller ID. A local area code, a bank name, or a government agency label should be treated as display information, not authentication.
Can banks or government agencies call you?
Organizations can make legitimate calls, including about suspicious activity. The safe response is still to end an unexpected call and reconnect through a number you trust. Use the number on the back of a card, a statement, an official app, or a government website you typed yourself.
The Social Security Administration says it generally calls in limited circumstances, such as after a person applies for a benefit or requests a call. It does not threaten arrest, suspend an SSN, demand immediate payment, or require payment through gift cards, cryptocurrency, cash, or wire transfer.
What to do during a suspicious call
Hang up. Do not press a key, call a number supplied by the caller, or continue simply to gather evidence. Contact the organization through an independently verified channel. Tell its fraud or security team what the caller claimed so they can check the specific account event. If the caller claims to be a relative, call that person at a known number or contact another family member.
For sensitive family requests, agree on a verification phrase that is not posted online. For workplace payments or account changes, use the companyâs established approval process and confirm through a separate conversation.
What to do if you shared information or money
- If you shared a password or code, change the password, end unfamiliar sessions, secure recovery methods, and contact the provider.
- If you shared bank or card details, call the financial institution using an official number and review recent activity.
- If you granted remote access, disconnect the device, end the session, remove the software, run a trusted security scan, and change important credentials from another device you trust.
- If you sent money, contact the payment service, bank, card issuer, gift-card company, or wire-transfer provider immediately and ask whether the transaction can be stopped or recalled.
- If you shared identity information, create a recovery plan at IdentityTheft.gov.
Save the caller ID shown, callback number, voicemail, payment instructions, receipts, date, and time. Report the scam at ReportFraud.ftc.gov. Report unwanted calls without a financial loss at DoNotCall.gov.
PSafeâs analysis of vishing
A legitimate organization can handle a callback through its published number. If the caller resists independent verification or insists that you remain on the line, end the call and verify the claimed event yourself.
Security software can help detect malicious apps or links involved in a call. It cannot determine whether the person speaking is a bank employee, police officer, government agent, or relative.
Frequently asked questions about vishing
Is caller ID reliable?
No. Caller ID can be spoofed. Verify the event through an official app or a number obtained independently.
Is it safe to enter a code on the phone keypad?
Do not enter credentials or security codes during an unexpected call. A caller or automated system may capture keypad tones or use the code to approve an account action.
Is a âsafe accountâ real?
A stranger who tells you to move money to protect it is running a scam. Contact your bank directly without using the callerâs number or instructions.
Are remote-access apps malware?
Legitimate remote-support tools have valid uses. A scammer can abuse the same access to view information, change settings, or initiate transactions. Do not install one at the direction of an unexpected caller.
Can a familiar voice be fake?
Yes. A recording or generated voice can imitate someone you know. Confirm urgent requests by calling the person through a known number and asking something the caller would not learn from public information.
Does blocking the number stop the scammer?
It may stop that displayed number, but scammers can switch or spoof numbers. Blocking, call labeling, and carrier filters reduce nuisance calls but do not replace verification.