SardineCon SF/2026

Learn More
Scams & social engineering4 分で読めます

Vishingとは?

SUBSCRIBE

Vishing is voice phishing over a phone call, using a fabricated story and often a spoofed caller ID to pose as a bank, agency, or company and extract codes, credentials, or payments. The live pressure of a call, now sharpened by AI voice cloning, makes it far harder to resist than a suspicious email.

What is vishing, in plain English?

Vishing is phishing done by voice. Instead of a link in an email, the attacker calls the victim and works them in real time. The caller adopts a pretext, a fraud investigator at the bank, an agent from the tax office, a support rep, and uses that role to extract what they need: a one-time code, login details, card information, or a payment made on the spot.

Two things make a call more dangerous than an email. First, it is live, so the attacker can adapt to hesitation, apply pressure, and keep the victim from stepping away to check. Second, the caller ID is usually spoofed to display a trusted number, so the call looks official before a word is spoken. Increasingly, AI voice cloning raises the stakes further, letting a caller sound like a specific bank's line or even a family member in distress.

In the fraud stack, vishing sits alongside smishing and email phishing as a delivery channel for social engineering. It is a frequent trigger for account takeover and authorized payments, because a code or approval given by phone can unlock everything else.

How a vishing call unfolds

  1. Spoof — Call from a trusted number. The attacker fakes the caller ID to show the victim's bank or a known agency.
  2. Pretext — Open with a crisis. They report fraud on the account or a problem that needs the victim to act right now.
  3. Extract — Ask for the code or payment. Under pressure, the victim reads out a one-time code, confirms credentials, or moves money to a "safe" account.
  4. Act — Use it immediately. The attacker enters the code or approval while the victim is still on the line, taking over or draining the account.

Who is involved?

Who

Their role

The caller

Runs the pretext live, adapting to the victim and applying pressure to get the code or payment.

The spoofed organization

A bank, agency, or company whose number and identity are faked to open the call with trust.

The victim

The account holder who shares a code, confirms details, or transfers money believing the call is real.

The bank or platform

Sees the login, code use, or payment that follows and is best placed to break the chain.

What it looks like in practice

In practice

A customer answers a call that shows their bank's real number. The caller says several fraudulent payments are being attempted and that, to block them, the customer needs to confirm the security code the bank is sending to their phone right now.

The code is genuine, but it is the code the fraudster triggered to authorize a new payee on the real account. The customer, alarmed and wanting to stop the "fraud," reads it out. Within seconds the payee is added and money is on its way. The urgency, the spoofed number, and the plausible story did all the work.

Why it matters to operators

Vishing produces the same hard-to-argue evidence as other authorized fraud: the customer entered or confirmed the code, the login came from a valid session, the payment was approved. The manipulation lives in a phone call you never see. That is why treating a one-time code as proof of presence is risky; the customer can be genuinely present and still be reading the code to an attacker.

The practical defenses are behavioral and procedural. Teach customers a single reflex: hang up and call back the number on the card. On your side, use callback verification for sensitive changes, watch for code use immediately followed by payee or contact changes, and never let inbound callers drive a step-up. As voice cloning spreads, "it sounded like them" is no longer evidence of anything.

What to watch for

  • Code then payee change. A one-time code confirmed, immediately followed by a new payee or a transfer to a "safe" account.
  • Safe-account transfers. Customers moving funds to an account they were told is secure by a caller claiming to be the bank.
  • Inbound-driven changes. Sensitive actions that trace back to an inbound call rather than a customer-initiated request.
  • Compressed timelines. Login, code, and payment happening within a few minutes suggests a live call in progress.
  • Cloned-voice claims. Reports of calls that sounded exactly like the bank or a relative, a sign of AI voice tools.

Quick questions

How is vishing different from phishing?

It uses a live phone call instead of a message. The live pressure and spoofed caller ID make it harder to resist, because the victim cannot easily pause to think or check the sender.

Why is a spoofed number so convincing?

The call displays the organization's real published number, so it looks official before the caller says anything. Caller ID can be faked, so the displayed number proves nothing.

How does AI voice cloning change things?

It lets attackers mimic a specific institution's line or a known person's voice, so "it sounded like them" no longer means the call is genuine. That erodes a signal people used to trust.

What is a safe-account scam?

A vishing variant where the caller convinces the victim their money is at risk and must be moved to a new "safe" account, which the fraudster controls. The transfer is authorized, so it looks legitimate.

What should customers be told to do?

Hang up and call the number on the back of their card. No genuine bank asks you to read out a one-time code or move money to a safe account over the phone.

Should a code count as proof the customer is present?

No. A customer can be present and still reading the code to a scammer on the phone. Sensitive actions need verification that a relayed code cannot satisfy.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

Vishingと併せて知っておきたい用語