Vishing Explained: Voice Phishing and MFA Bypass for Security+
Vishing — voice phishing — is social engineering conducted over the phone. An attacker calls, establishes a plausible identity, manufactures urgency, and talks the victim into handing over credentials, approving an MFA prompt, or making a payment. A phishing email gives the target time to think. A phone call does not, and that is the entire point. Email phishing can be reread, forwarded to IT, and checked against the sender's real address. A live call moves at the attacker's pace, exploits politeness, and leaves no artifact to examine. That is why vishing succeeds against people who would never click a suspicious link — and why it has become the preferred route past MFA. The Techniques Caller ID spoofing. Trivially easy, and it underpins nearly every campaign. The display can read your bank's real number, your own company's help desk, or a government agency. Caller ID is not authentication and never was — worth saying plainly, because most people treat it as ...