Vishing

Vishing (voice phishing) is a social engineering attack conducted over the phone where callers impersonate trusted entities — IT support, bank representatives, government officials, or company executives — to trick victims into revealing sensitive information, transferring funds, or granting system access.

Vishing attacks have become increasingly sophisticated, sometimes using spoofed caller IDs to appear to come from legitimate numbers. Attackers may have done extensive research on the target, making the call seem genuine by referencing real names, projects, or organizational details.

Why It Matters

Security awareness training under CMMC should cover phone-based social engineering. Employees need to verify caller identity through callback procedures before sharing sensitive information or granting access requests received by phone.