Security Awareness

Voice Phishing: When the caller sounds exactly like your CEO

voice phishing

Voice phishing, sometimes called vishing, just picked up a hard data point most security teams haven’t seen yet. The FBI’s 2025 Internet Crime Report broke out AI related fraud as its own category for the first time. In that first year of tracking, it counted 22,364 complaints and just under $900 million in losses tied specifically to AI, with voice cloning called out by name as a technique used to back up fake executive requests.

What makes vishing different from the phishing your team already knows how to spot is how little it takes to build. A few seconds of audio form a LinkedIn video, a webinar recording, or a short clip on your company website is enough to train a model on someone’s voice. Most leadership teams have that much audio sitting in public view without ever thinking of it as a security asset, because until recently, it wasn’t one.

How a Voice Phishing Call Actually Plays Out

An attacker pulls a short public clip of someone’s voice, usually an executive or someone in IT, and runs it through a voice model. Then the call comes in, and it sounds like that person exactly. Same tone, same pacing, same way they say your name.

They already know who you are and what you do because that information is public too. The story is simple and urgent. An IT lead locked out of a system and needing a password reset before a deadline. A vendor confirming an account number before payment goes out. A CEO traveling, asking for something to be handled quietly and quickly, no time to explain. 

“I’m locked out. I need you to reset my credentials” Said in a voice you’d recognize anywhere, by someone who was never on that call.

Why Voice Phishing Beats Every Technical Control You Have

Firewalls, endpoint detection, spam filters and multifactor authentication are all built to catch something abnormal happening on a system. A phone call isn’t a system event. There is no malicious file to flag, no suspicious login to block, no unusual traffic to notice. The entire attack takes place in a conversation, and conversation are not something your security stack was built to inspect. 

That is what makes vishing different from the email phishing your team has learned to spot. There is no message to hover over, no sender address to check, no link to scan. The only thing standing between a normal request and a costly mistake is whether the person on the receiving end knows to stop and verify before acting, every time without exception.

Watch For These Together

  1. The request involves codes, passwords, or moving money
  2. There’s urgency or pressure to act before you can think it through
  3. You’re asked for remote access or to open a link or page

The One Process That Actually Works

The fix isn’t a better filter. It’s a habit. If you didn’t initiate the call and it touches anything sensitive, treat it as unverified until proven otherwise. Hang up, and don’t feel awkward about it. Nobody legitimate will penalize you for confirming who you’re talking to. 

Then don’t use anything the caller gave you to verify them. Not the number they called from, not an email address they read out, not a link they sent. All of it can be faked in minutes. Instead, go find the contact information your team already has on file, the one nobody read to you over the phone, and call that number directly.

voice phishing

The caller ID, the phone number, the email address. All of it is easy to spoof. The only thing that can’t be faked is the contact you already had before the call came in.

If it turns out the call wasn’t legitimate, report it to your IT team right away, even if nothing was handed over. Knowing an attempt was made matters just as much as stopping one, because it tells your team someone is actively targeting your organization and probably won’t stop after one try. 

None of this requires new software or a bigger budget. It requires everyone on your team to know the process and use it consistently, including the people who feel too senior or too busy to double check. Those are usually the calls attackers are counting on going through without question.

Do you have the right checks in place?

Want to know how prepared your team actually is for a voice phishing call like this? We help our clients build a verification process everyone will actually follow.

Have questions about your setup?

We start every partnership the same way: a conversation about where you are, where you’re headed, and what you actually need.