Vishing swaps email for a phone call — as used against MGM Resorts, Carnival, and Retool — where an attacker posing as IT support or a bank representative talks a target into resetting a password, approving an MFA push, or moving money. It's harder to filter than email and easier to make convincing under time pressure, which is why help-desk vishing has become one of the costliest attack paths for large enterprises.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from customer Alice Fries.
VIThe CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019 after a phone call using AI-cloned audio.
VIA caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438.
VIA Singaporean finance professional in her 50s lost S$1.2 million.
VIA Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew him into a deepfake.
VIA Snap Inc. payroll employee emailed the W-2 and payroll data of roughly 700 current and former employees to an attacker who spoofed CEO Evan.
VISABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South.
VITwo Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.
VITwo Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors.
VIA smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA codes.
VIA Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
VIA scammer spoofed a New Zealand bank's real phone number, posed as its fraud team.
VIFraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display photo of former Rajya Sabha MP.
VIAn Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
VINTS IT Care used fake Microsoft/Apple security pop-ups to scare consumers, mostly older Americans.
VIA 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
VIScattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
VIA retired 60-year-old Malaysian bank manager in Johor Baru lost RM936,000 (life savings) after a Macau-scam vishing syndicate posing successively.
VIA retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him.
VIPosing as NatWest bank security, vishing criminals convinced Surrey solicitor Karen Mackie to wire £734,000 of client money to fraudulent accounts.
VIFraudsters impersonating Leoni AG executives tricked its Romanian subsidiary into wiring roughly EUR 40 million ($44.6M) to attackers.
VIFraudsters posing as RBS fraud-team staff talked Hamilton Academical FC's banking employee into moving nearly £1 million to fake accounts.
VIJLR's five-week production halt and record £1.9bn UK economic hit were first blamed on helpdesk-vishing by a criminal collective calling itself.
VIDOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
VIDOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.
VIA single vishing call impersonating Carnival's own IT security team convinced an employee to hand over credentials.
VIA long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened tens.
VIDOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
VIA finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and colleagues were all AI-generated.
VIAttackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a fully SPF/DKIM/DMARC-authenticated.
VIFraudsters spoofed Barclays' real phone number and hold music, posed as the bank's fraud team in a two-caller vishing script.
VIAttackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.
The MGM Resorts help-desk vishing breach (Scattered Spider, 2023), the Retool smishing-plus-vishing breach, and the Carnival Corporation employee vishing breach all used a phone call posing as internal IT or support staff to get past identity verification.
Wells Fargo's "Alice Fries" case, the NatWest callback fraud that cost a Surrey solicitor £734,000, the Barclays-impersonation vishing of a UK jeweller, and the bank-impersonation vishing network dismantled in Colombia all posed as a bank's own fraud team to move money out of a target's account.
Arup's Hong Kong deepfake CFO video call (US$25.6M), the S$4.9 million Singapore deepfake Zoom call impersonating Prime Minister Lawrence Wong, and a UK energy firm's AI voice-clone CEO fraud show synthetic voice and video now built into the vishing call itself.
Singapore's Anti-Scam Centre police-impersonation case, Canada's CRA/RCMP Project OCTAVIA tax-scam network, and the India-based IRS/USCIS impersonation call-center takedown (61 defendants) all used a spoofed government caller ID to extract payment under threat of arrest or penalty.