Skip to content

Fraud

What Is Vishing? Meaning, Types, Examples and How to Prevent It

Deepak Gusain

Marketing LeadOct 5, 2026Updated Oct 6, 202615 min read

Vishing Meaning

Vishing, also known as voice phishing, is a phone-based cybercrime in which scammers impersonate trusted entities such as banks, government agencies, law enforcement authorities, or customer support teams to manipulate individuals into sharing sensitive information or authorising transactions. Scammers often use voicemails or phone calls to trick people into giving OTPs, bank passwords, or credit card numbers. As digital banking, UPI payments, and mobile financial services continue to expand across India, vishing attacks have become increasingly sophisticated and difficult to detect.

This guide explains the vishing meaning, how these scams work, and the steps individuals and financial institutions can take to prevent them.

Vishing Meaning: Why Is It Called Voice Phishing?

Vishing is a form of phishing that uses voice calls to trick people into revealing sensitive information, sharing security codes, or authorising payments. The term combines “voice” and “phishing.”

While traditional phishing attacks use emails, text messages, or fake websites to trick individuals into revealing sensitive information, vishing uses phone calls as the primary attack channel.

In a typical vishing scam, fraudsters impersonate trusted organisations such as banks, payment providers, government agencies, or customer support teams to convince victims to share sensitive information, including OTPs, PINs, CVV numbers, online banking credentials, or UPI verification codes. In some cases, they may also pressure victims into approving fraudulent transactions or installing remote-access applications.

How Does a Vishing Attack Work?

vishing-attack-stages.webp

A vishing attack builds trust over a phone call and then manipulates the victim into sharing a code, handing over credentials, or approving a payment. Most scams of this kind usually follow a similar step/pattern as discussed below.

Step 1: Reconnaissance

The attacker starts by gathering data about the target victim, including names, job titles, phone numbers, banks used, and internal company procedures. Attackers often choose victims who are easy to pressure, such as seniors or people who have just applied for a loan or credit card.

Step 2: Pretexting and Caller ID Spoofing

The attacker builds a believable yet fake scenario, also known as a pretext, such as an urgent bank alert, a KYC update, or an IT support ticket. Caller ID spoofing software or Voice over Internet Protocol (VoIP) services make the phone number appear legitimate, such as a bank helpline, a government office, or a known company.

Step 3: Establishing Contact and Impersonation

The victim receives an unexpected call or voicemail. In some cases, the attacker first sends a text or email that prompts the victim to call a specific number. This is known as telephone-oriented attack delivery (TOAD). On the call, the attacker poses as a bank fraud officer, KYC executive, tax official, or IT support agent and asks for details like the victim's name, loan amount, or credit card type to seem legitimate.

Step 4: Generating Urgency or Fear (Social Engineering)

After gaining trust, the attacker creates urgency, fear, or excitement to manipulate the victim into taking a specific action. Typical claims include a blocked bank account, a suspicious transaction, expired KYC, unpaid taxes, a pending refund, or the threat of legal action. The goal is to trigger an emotional response that discourages the victim from verifying the request independently.

Step 5: Extract Credentials, Data or Access

When the victim is anxious and compliant, the attacker requests the credentials, information, or access they are after. This could be a password, card number, CVV, or one-time password (OTP). They may also ask the victim to approve a UPI collect request or a multi-factor authentication (MFA) push notification. In an MFA fatigue attack, the fraudster sends repeated prompts until the victim approves one.

Step 6: Fraud Implementation

With the information or access, the attacker either removes the money or gets into the company network. Funds are usually transferred through several accounts within minutes, making them hard to trace and recover. In corporate scenarios, the stolen access could be used for data theft or further attacks.

Why Are Vishing Attacks Increasing in India?

Vishing cases are rising in India because digital payments have widened the pool of targets, fraud calls run at massive volume, and AI tools make impersonation more convincing. According to the National Cyber Crime Reporting Portal (NCRP), fraud cases rose from 2.62 lakh in 2021 to 24.02 lakh in 2025. Below are five factors that explain most of the reasons behind this increase in vishing attacks.

  • New digital banking users are still learning how banks communicate and what they never ask, so a fake call seems believable.

  • Through UPI, users can move money in seconds, and authorised payments are hard to reverse. Once a victim approves, funds move on within minutes.

  • Leaked names, phone numbers and account details circulate through resale lists. A caller who knows your name and bank sounds authentic instantly.

  • Fraud centres use automation to dial thousands of numbers, run multilingual scripts and spot responsive victims, lowering the cost per victim.

  • A short social media audio clip can imitate a relative or bank official. A cloned voice makes urgent requests harder to doubt.

Earlier fraud focused on just stealing credentials and breaking into accounts. Vishing works differently. It convinces the account owners to share OTPs or approve requests, so transactions look legitimate to banks. Traditional authentication checks who acts on that step, not the intent behind it. That’s why technical security alone isn't enough to detect these threats.

What Are the Common Types of Vishing Attacks?

vishing-scams.webp

The most common types of vishing are fake KYC calls, account suspension calls, UPI fraud calls, reward point scams, loan approval scams, insurance maturity scams, tax refund scams and investment scam calls. Each entry below is an example of vishing that Indian customers meet regularly, and the table explains how the scam works, who it targets and how severe the risk level is.

Types of ScamHow the Scam WorksWho It TargetsRisk-level
Fake KYC Update CallsThe caller says your KYC has expired and the account will be blocked today. You are pushed to share an OTP or Aadhaar details, or to install a verification app.Salaried customers and senior citizensHigh
Bank Account Suspension CallsA fake fraud officer reports a suspicious transaction and threatens to freeze your account. To stop it, you must confirm card details or login credentials immediately.Debit and credit card holdersHigh
UPI Fraud CallsThe caller sends a UPI collect request and calls it a refund or prize. Approving it and entering your PIN sends money out, not in.UPI users and small merchantsCritical
Credit Card Reward Point ScamsThe caller offers to redeem reward points that supposedly expire tonight. Redemption requires your card number, CVV and an OTP, which the fraudster uses for online purchases.Credit card holders with reward programmesMedium
Loan Approval ScamsThe caller promises a pre-approved loan at a low rate, then demands a processing fee upfront. The loan never arrives, and the fee is gone for good.First-time borrowers and self-employed peopleMedium
Insurance Maturity ScamsThe caller claims your policy has matured and asks for a tax or clearance fee before releasing the full payout. A maturity payout sounds believable and welcome, which makes the story convincing.Policyholders and senior citizensHigh
Income Tax Refund ScamsThe caller says a refund is pending and asks you to confirm your bank account number and an OTP, or to pay a small processing charge.Salaried taxpayers who expect refunds every yearMedium
Investment Scam CallsThe caller promises assured returns from stocks, crypto or trading groups, then pushes you to transfer more money repeatedly. Losses grow with every payment.Retail investors and working professionals, often reached through private messaging groupsCritical

Swipe the table

Vishing vs Phishing vs Smishing: What Is the Difference?

Vishing, phishing and smishing are all different in the channel they use. Vishing is voice calls, phishing is email, and smishing is SMS. These are all social engineering attacks that get people to give up money or information. The table below compares the key aspects of each.

Key AspectsVishingPhishingSmishing
Full FormVoice vishingPhishing (Email-Based Fraud)SMS Phishing
ChannelPhone calls, voicemails, VoIP callsEmails, fake websites, online messagesSms and text messages
InteractionReal-time voice conversation with the victimOne-way communication through emailOne-way communication through text messages
Main TacticImpersonation, trust-building, urgency, and social engineeringFake links, spoofed emails, and credential harvestingFraudulent links, fake alerts, and urgent text messages
Victim ActionShares OTPs, PINs, credentials, or approves transactions during a callClicks a malicious link, downloads malware, or enters credentials on a fake websiteClicks a malicious link, calls a fake number, or shares personal information
Warning SignUnsolicited calls requesting sensitive information or immediate actionSuspicious sender addresses, unexpected attachments, or fake login pagesUnknown numbers, shortened URLs, urgent requests, or unexpected messages
Detection DifficultyHigh, because attackers use live conversations and psychological pressureMedium, as users can inspect email addresses, links, and contentMedium to High, as messages often appear legitimate and create urgency
Common scenarioFake KYC update call, bank account suspension call, credit card reward points callFake bank login email, Microsoft 365 password reset email, courier delivery phishing emailFake UPI refund SMS, package delivery text scam, income tax refund SMS

Swipe the table

While phishing, smishing, and vishing all rely on social engineering, vishing is often considered more persuasive because it uses a live voice conversation. The ability to build trust, answer questions in real time, and create urgency makes it particularly effective at bypassing human judgment and traditional security controls.

Why Does Traditional Banking Security Fail Against Vishing?

Vishing is often able to bypass traditional banking security, as it is designed to confirm identity, not intent. Most security controls focus on ensuring that the right customer is logging into an account. But they can't tell whether that customer is acting on their own or being directed by a fraudster. In a typical example of vishing, the customer passes every check because the customer is the one entering the details.

1. OTPs confirm ownership, not intent

The one-time password (OTP) gives the bank assurance that a registered device or phone number is being accessed. But it can't tell why the OTP is being used. The verification process still works if a victim is on the phone with a fraudster and gives them the code.

2. MFA is not sensitive to manipulation

Multi-factor authentication (MFA) adds extra identity-verification steps, like biometrics, authentication apps, or security prompts. However, when a real customer follows these steps under the instruction of a fraudster, the authentication system only sees a successful verification attempt.

3. KYC confirms identity, not behaviour

Know Your Customer (KYC) processes help financial institutions verify a customer's identity during onboarding. Although well suited for compliance and identity verification, KYC offers no insight into whether a customer is being manipulated at the time of the transaction, months or years later.

4. Authentication does not detect social engineering

Traditional authentication systems cannot detect social engineering. They can’t tell if a customer is under duress, responding to threats or following the directions of someone pretending to be a bank representative, government official or technical support agent.

Moreover, banks face a major problem: vishing often happens after the customer has passed authentication. The customer enters the correct credentials, approves the transaction and passes all security checks. Bridging this gap requires analysing behavioural, device, and risk signals that can detect suspicious activity, even when the authentication process seems legitimate.

How Sign3 Helps Financial Institutions Prevent Vishing-Driven Fraud

At Sign, we use device intelligence, behavioural analytics, digital footprint intelligence and real-time risk assessment to help financial institutions detect possible vishing-related fraud before funds are transferred.

Core features include:

  • Device Intelligence: Identifies high-risk signals such as SIM swaps, rooted devices, emulators, VPNs, app cloning and device anomalies related to fraud.

  • Behavioural Biometrics: Identifies anomalous customer behaviour, guided transactions, patterns of hesitation and anomalies in interaction that may indicate social engineering.

  • Digital Footprint Intelligence: Assesses the risk profile and trustworthiness of users via digital identity and behavioural signals across channels.

  • Real-Time Risk Scoring: Combines multiple fraud signals into a single risk score so you can instantly approve, challenge or block.

  • Account Takeover Detection: Identifies suspicious login and transaction activity that could indicate compromised accounts.

  • Mule Account Detection: Detects accounts that are used to receive or move fraudulent funds as part of larger money laundering networks.

  • Fraud Ring Intelligence: Uncovers hidden connections between devices, accounts, identities and transactions to identify organised fraud operations.

  • Continuous Lifecycle Monitoring: Monitors risk across onboarding, login, payments, and ongoing account activity, not just authentication events.

These capabilities allow financial institutions to go beyond identity verification and detect fraud patterns that arise during actual customer interactions.

How Is Vishing Linked to Account Takeover Fraud?

Vishing leads to account takeover when stolen credentials let fraudsters log in and move money out. It is often the first step in a chain that turns one phone call into an organised laundering operation.

Once fraudsters hold credentials, they log in, change contact details and move funds into mule accounts that split and forward the money. For banks and NBFCs, this means a single vishing call can trigger an account takeover, a mule account problem, and a money-laundering exposure at the same time. Stopping the chain early costs far less than unwinding it later. Each stage is a chance to intervene.

A flagged login from a new device, an unusual change of mobile number or a first-time transfer to an unfamiliar beneficiary can all break the chain if the system reads them together. To understand Account Takeover (ATO) Fraud in detail, read this guide.

Banks and fintechs detect vishing-related fraud by analysing device, behavioural, transactional, and network signals that traditional authentication systems cannot see. Because victims often complete transactions themselves, fraud detection must determine whether the activity is genuine or influenced by a fraudster.

1. Device Intelligence

Device intelligence helps identify suspicious environments before a transaction is completed. Banks monitor signals such as SIM swaps, rooted devices, emulators, VPN usage, app cloning, unfamiliar devices, and unusual login locations that may indicate account compromise or fraudulent activity.

2. Behavioural Analytics and Biometrics

Behavioural analytics examines how a customer interacts with an app or website. Unusual hesitation, guided navigation, active phone calls during transactions, changes in typing patterns, or behaviour that differs from historical activity can indicate that a fraudster is influencing the customer.

3. Real-Time Transaction Monitoring

Modern fraud systems continuously analyse transactions as they occur. Unusual transfer amounts, newly added beneficiaries, abnormal payment frequencies, or UPI requests that deviate from a customer's normal spending behaviour can trigger additional reviews before funds leave the account.

4. Remote Access and Screen-Sharing Detection

Many scams of this type involve persuading victims to install remote-access software or share their screens. Detecting active remote-control applications, screen-sharing sessions, or device-control activity during sensitive transactions can help identify fraud in progress before losses occur.

5. Mule Account and Network Intelligence

Fraud detection platforms analyse where money is being transferred and whether destination accounts are linked to known fraud networks. Identifying mule accounts, suspicious beneficiary relationships, or unusual fund movement patterns helps uncover organised fraud activity beyond a single transaction.

6. Risk Scoring and Adaptive Controls

No single indicator proves fraud. Risk-scoring models combine device, behavioural, transactional, location, and network signals into a single risk assessment, allowing banks and fintechs to apply additional verification, cooling-off periods, transaction challenges, or real-time blocks when necessary.

How Can Banks and Consumers Prevent Vishing Scams?

Stopping vishing requires both customer awareness and proactive fraud controls. Consumers may reduce their risk by validating requests and safeguarding sensitive information, but banks and fintechs need to deploy security controls that can detect fraud even if a customer has been coerced into taking action.

For Consumers

Some basic practices can reduce consumers’ vulnerability to vishing calls.

  • Never share OTPs, PINs, CVVs, passwords or banking credentials over a phone call, irrespective of who the caller claims to be.

  • If someone calls asking for sensitive information or to take immediate action, hang up and call the organisation using an official phone number from its website, app or bank card.

For Banks & Financial Institutions

Banks and fintechs need effective fraud-prevention controls that go beyond authentication.

  • Ongoing transaction monitoring, behavioural analytics, device intelligence, risk scoring and mule account detection can identify suspicious activity even when a legitimate customer initiates the transaction.

  • By combining these signals in real time, institutions can identify potential vishing-related fraud, perform additional verification when needed, and prevent high-risk transactions from resulting in fund losses.

Conclusion

Vishing is getting more sophisticated, with fraudsters employing AI voice cloning, caller ID spoofing and advanced social engineering to make scams more convincing. Customer awareness is still an important defence, but it can’t stop every call. Typical security controls such as OTP, MFA and KYC verify identity but miss the point when a legitimate customer is manipulated into authorising a fraudulent transaction. Addressing this threat requires an effective and multi-pronged approach that includes device intelligence, behavioural analytics and real-time risk assessment.

Book a demo and find out how Sign3 helps banks, NBFCs and fintechs detect and prevent vishing-driven fraud before the funds are lost.

Frequently Asked Questions

What is the meaning of vishing in cybersecurity?

In cybersecurity, vishing means voice phishing. It is a social engineering attack carried out through phone calls, IVR systems or voice messages. The attacker impersonates a trusted entity to steal credentials, OTPs or money.

What is an example of vishing?

A common example of vishing is a caller posing as a bank fraud officer who says your account has been flagged. They ask for an OTP or push you to approve a UPI collect request, and the money leaves your account.

How can vishing be prevented?

Never share OTPs, PINs or CVVs; verify callers through official numbers and avoid acting under pressure. Banks add device intelligence, behavioural analytics and risk scoring to detect manipulated transactions.

Can banks detect vishing in real time?

Yes, banks can detect vishing in real time. By adapting device signals, behavioural patterns, and risk scores during a live session, banks and fintechs can identify a customer being guided by a fake caller and prevent the transaction before funds move.

Share

Keep reading

All articles →

Browse by topic

Run your last week of traffic through Sign3.

We'll score it, surface the fraud patterns your current stack missed, and walk you through what we found. Your data, our scoring. No commitment, no integration, no decision required until you've seen the result.