Voice and deepfake

How do you prevent vishing?

Vishing is prevented by removing the help desk’s ability to reset credentials on the strength of a phone call alone. Every large vishing breach in this library ran through a support function that could restore access to a caller it could not actually identify.

The caller is usually plausible, informed and patient. They know the org chart, the ticketing language and often the target’s employee number. What defeats them is a process that requires proof they cannot obtain by talking.

Documented cases

  • MGM Resorts fell to a ten-minute call to the help desk that reset MFA and handed over identity systems.
  • Caesars Entertainment lost a loyalty database the same year after its IT help desk was talked into a password reset.
  • Jaguar Land Rover shows the operational cost when the same technique lands in 2025.

The control that breaks it

  • Require identity proof the caller cannot talk their way around, such as a manager approval in a separate system or a verified device prompt.
  • Never reset MFA on a voice call alone, however senior or urgent the caller sounds.
  • Give help-desk staff an explicit, no-penalty right to refuse and escalate.
  • Log and review resets. Repeat attempts against one identity are the pattern worth alerting on.

Related: vishing vs voice cloning · vishing vs phishing · Vishing