Voice Phishing

cainxinth1 pts0 comments

Voice phishing - Wikipedia

Jump to content

Search

Search

Donate

Create account

Log in

Personal tools

Donate

Create account

Log in

Voice phishing

18 languages

Azərbaycanca<br>Čeština<br>Deutsch<br>Español<br>فارسی<br>Français<br>Bahasa Indonesia<br>Italiano<br>日本語<br>한국어<br>Norsk nynorsk<br>ਪੰਜਾਬੀ<br>Polski<br>Português<br>Русский<br>Simple English<br>Svenska<br>Українська

Edit links

From Wikipedia, the free encyclopedia

Phishing attack via telephony

Voice phishing , or vishing ,[1] is the use of telephony (often Voice over IP telephony) to conduct phishing attacks.

Landline telephone services have traditionally been trustworthy: terminated in physical locations known to the telephone company and associated with a bill-payer. Now, however, vishing fraudsters often use modern Voice over IP (VoIP) features such as caller ID spoofing and interactive voice response systems to impede detection by law enforcement agencies. Voice phishing is typically used to steal credit card numbers or other information used in identity theft schemes from individuals.

Usually, voice phishing attacks are conducted using automated text-to-speech systems that direct a victim to call a number controlled by the attacker. However, some use live callers.[1] Posing as an employee of a legitimate body such as the bank, police, telephone or internet provider, the fraudster attempts to obtain personal details and financial information regarding credit cards, bank accounts (e.g. the PIN), as well as personal information of the victim. With the received information, the fraudster might be able to access and empty the account or commit identity fraud. Some fraudsters may also try to persuade the victim to transfer money to another bank account or withdraw cash to be given to them directly.[2] Callers also often pose as law enforcement or as an Internal Revenue Service employee.[3][4] Scammers often target immigrants and the elderly,[5] who are coerced to wire hundreds to thousands of dollars in response to threats of arrest or deportation.[3]

Bank account data is not the only sensitive information being targeted. Fraudsters sometimes also try to obtain security credentials from consumers who use Microsoft or Apple products by spoofing the caller ID of Microsoft or Apple Inc.

Audio deepfakes have been used to commit fraud, by fooling people into thinking they are receiving instructions from a trusted individual.[6]

Terminology<br>[edit]

Social engineering - The usage of psychological manipulation, as opposed to conventional hacking methods, to gain access to confidential information.[7]

Caller ID spoofing - A method by which callers are able to modify their caller IDs so that the name or number displayed to the call recipient is different than that of the caller.[8] Phishers will often modify their numbers so that they appear familiar or trustworthy to the call recipient.[9] Common methods include spoofing a number in the call recipient's area code or spoofing a government number so that the call appears more trustworthy or familiar and the potential victim is more likely to answer the call.[9]

Voice over Internet Protocol (VoIP) - Also known as IP telephony,[10] VoIP is a technology that allows voice calls to be made over the internet.[11] VoIP is frequently used in vishing attacks because it allows callers to spoof their caller ID.[12] They can also reduce telephony cost by having VoIP servers in target countries instead of doing international calls, if doing international fraud.

Motives<br>[edit]

Common motives include financial reward, anonymity, and fame.[13] Confidential banking information can be utilized to access the victims' assets. Individual credentials can be sold to individuals who would like to hide their identity to conduct certain activities, such as acquiring weapons.[13] This anonymity is perilous and may be difficult to track by law enforcement. Another rationale is that phishers may seek fame among the cyber attack community.[13]

Operation<br>[edit]

Voice phishing comes in various forms. There are various methods and various operation structures for the different types of phishing. Usually, scammers will employ social engineering to convince victims of a role they are playing and to create a sense of urgency to leverage against the victims.

Voice phishing has unique attributes that separate the attack method from similar alternatives such as email phishing. With the increased reach of mobile phones, phishing allows for the targeting of individuals without working knowledge of email but who possess a phone, such as the elderly. The historical prevalence of call centers that ask for personal and confidential information additionally allows for easier extraction of sensitive information from victims due to the trust many users have while speaking to someone on the phone. Through voice communication, vishing attacks can be personable and therefore more impactful than similar alternatives such as email. The faster response time to an attack attempt due to...

voice phishing information call from caller

Related Articles