Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


Vishing is voice phishing: a caller uses a false identity or story to get your money, sensitive information, or access to a device. The practical defense is to stop the requested action and verify the claim through a channel you choose, rather than the number or link the caller supplies. A convincing voice and familiar caller ID are not proof of identity.[1]
Key Takeaways
- Judge the requested action, not the caller's confidence or accent.
- Never relay login codes, approve unexpected sign-ins, or move money during an unsolicited call.
- Hang up and contact the organization through its official app, your card, or a known website.
- If you already disclosed something, respond to that specific exposure instead of changing everything at random.
Phone conversations are one part of a broader personal digital privacy plan. This guide focuses on requests made over the phone, including calls that follow a text message or email.
Vishing scams borrow an authority you already recognize. A caller may pretend to be your bank's fraud team, a government office, a delivery company, technical support, or someone at work. The story supplies a reason to act before you can ask another person: an account is frozen, a payment is pending, or a device supposedly needs urgent repair.[1][2]
Information about you can make the story feel credible. Knowing your name, employer, or a previous address does not establish that the caller works for the organization. Treat those details as part of the claim, not as a successful identity check.
The call may start with apparently harmless questions and escalate after you agree. A request to confirm a purchase can become a request for a code, then a demand to transfer savings. You can stop at any point; having answered one question does not oblige you to complete the conversation.
Some callers use recorded messages or synthetic voices. Others speak live and adapt to your answers. If the voice sounds like a relative, independent checks for cloned-voice calls are more useful than trying to hear a digital artifact. The identity problem remains the same even when no AI is involved.
The strongest vishing warning signs are requests that hand control to the caller. Do not wait for a spelling mistake, an unusual accent, or a dramatic threat. A calm, polite request can still be unsafe.
Use this decision table as a pause-and-verify aid. It is an editorial framework for comparing the request with the access it would grant, not a test that can certify a call as genuine.
| What the caller wants | What to stop | Where to verify independently |
|---|---|---|
| A one-time login or recovery code | Reading out the code or approving a prompt | The service's app or account-security page |
| A transfer to a supposedly safe account | Adding a payee or sending money | Your bank using the number on your card |
| A remote-support session | Installing tools or granting screen control | Support reached from the manufacturer's known website |
| Gift cards, cryptocurrency, or cash for an official fee | Buying or sending the requested payment | The agency's independently located contact channel |
| Secrecy or continuous conversation | Staying on the line while making decisions | A trusted person and the organization's own contact details |
The FTC identifies pressure and unusual payment demands as common features of phone scams. A threat of arrest, a promise of a prize, or an order to move funds should trigger independent verification, not compliance.[2]
Other risk signals include instructions to disable protection, ignore a bank employee, misdescribe the purpose of a transfer, or read a code that explicitly says not to share it. These instructions try to remove the safeguards between a persuasive conversation and an irreversible action.
A caller might offer an employee number or ask you to check an official-looking website. Neither is enough when the caller controls the evidence. Find the organization's contact details yourself; do not let the same person supply both the claim and the supposed proof.
Vishing prevention works best as a repeatable habit that does not depend on improvising under pressure. Prepare known contact channels before a crisis, especially for banking, work accounts, and relatives who may ask for help.
For a supposed family emergency, contact the relative using a number already saved, or reach another trusted person who can check their safety. A phrase agreed in advance can help, but it is not a substitute for an independent callback if that phrase may have been exposed.
If you need to reduce interruptions after the incident, device options for filtering nuisance calls are a separate task. Filtering can reduce contact opportunities; it cannot decide whether every remaining caller is trustworthy.
Respond to what the caller actually obtained. Write down the approximate time, the claimed organization, what you disclosed, and whether you approved anything. Separate facts you know from things you suspect; that distinction helps a bank or support team choose the right response.
If you only answered the call: end contact and monitor for follow-up attempts. Answering by itself does not prove that the phone or an account is compromised. Do not install a “cleanup” tool offered by a later caller.
If you shared a password or login code: use a trusted device to contact the affected service, change exposed credentials, and review signed-in sessions and recovery details. Change reused passwords on other accounts. If you cannot sign in, use the service's official recovery process.[3]
If you paid or exposed card information: contact the bank, card issuer, payment app, or transfer provider promptly. Explain that the transaction resulted from a scam and ask what cancellation, recall, dispute, or replacement options apply. Refund rights and deadlines vary; an immediate report does not guarantee recovery.[3]
If you granted remote access: stop using that device for sensitive accounts and get help from support you independently trust. Explain which tool was installed and what was visible. Do not reenter banking credentials while the other person may still control the session.
If you shared identity documents: record exactly which documents and numbers were exposed. Ask your local identity-theft or consumer-protection service about available measures. U.S. identity-recovery services described by the FTC are jurisdiction-specific, not a universal process.[3]
Once account access is secure, review network precautions for online banking when you resume routine banking. Network protection does not verify a caller, cancel a transfer, or recover stolen money; those tasks stay with the institution and relevant authorities.
Keep the call log, voicemail, messages, payment receipts, and any contact details the caller supplied. Preserve the original files where possible and note the sequence of events in your own words. A displayed number can be spoofed, so label it as the number shown rather than a proven identity.[1]
Report impersonation to the organization through a trusted channel. Use your local fraud-reporting or police service where appropriate. The FTC's reporting routes are for U.S. consumer complaints; readers elsewhere should use their own local authorities rather than assume a U.S. report starts a local investigation.
If another person in your household answered the call, share the request pattern without blame. Agree that anyone can stop a conversation and seek a second opinion. Similar pressure may also appear in relationship-based payment scams, where trust builds over a longer period.
Do not call back repeatedly to confront the caller or publish alleged identities based on caller ID. That can expose more information or implicate an unrelated person whose number was spoofed. Check local rules before recording future calls; a written incident log is useful without making a legal assumption about recording.
Vishing is phishing conducted through voice communication. Email phishing and text-based scams can lead into a phone call, so the categories may overlap. The important question is which information or action the attacker is trying to obtain.
No. A displayed number or organization name is not an identity guarantee. End the call and contact the bank through its official app or the number on your card before sharing information or making an account change.
Do not relay a login, recovery, or authorization code to an unsolicited caller. Read the code's accompanying message and open your institution's own channel. The caller's explanation does not override what the code actually authorizes.
No. Familiarity can come from imitation, a recording, or voice cloning. Verify a request for money through another channel, particularly when the caller demands secrecy or refuses to let you contact the person independently.
Contact the payment provider promptly and ask what recovery options exist for that transaction. Keep receipts and explain the circumstances accurately. Do not pay another person who guarantees recovery in exchange for an upfront fee.
Answering alone is not evidence of a compromised phone. Assess whether you installed something, granted access, disclosed credentials, or approved a request. Those actions determine the response; unsupported panic can make follow-up scams easier.
No. Blocking may stop calls from that displayed number, but attackers can use other numbers or spoof caller ID. Combine filtering with independent verification and never assume that an unblocked call has passed a security check.
Disclaimer: This is general safety information, not legal or financial advice. Canadian and U.S. sources support the scam patterns; reporting procedures, recording laws, and payment remedies depend on your country or region. If you face an immediate threat, contact local emergency services.
Sources:
Sources checked 5 October 2026.
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.





