Hacked.com

Online Account Security

Vishing

Practical security guidance maintained by Hacked.com's recovery team.

Professional realistic concept image for Vishing
Jump to a section

Vishing is phishing by voice call or voicemail. A familiar voice or caller ID does not verify the caller; contact the organization through a known number.

Why it matters for account recovery

Vishing matters for recovery because attackers often target the control plane: email logins, phone numbers, and verification codes. A convincing voice script can bypass otherwise good security settings.

Common failure modes and misconceptions

  • Calling you on the number you trust: Caller ID can be spoofed. The display name does not prove who is calling.
  • Code and password extraction: Attackers ask for one-time codes, password reset links, or "verification" steps that hand them access.
  • Remote access tools: Support impersonation often aims to get you to install remote control software.

Safe best practices

  • Hang up, then call back using a known number from an official site, card, or app.
  • Do not share one-time codes or recovery links by phone.
  • Treat phone-based urgency as social engineering pressure and switch to a known verification path.

What to record if it happens

Record the displayed number, callback instructions, claimed institution, call time, and requested action. Keep original messages and note what you actually did, rather than treating every claim from the sender as an established fact.

Vishing is a verification failure. If you make call-back on known numbers normal for high leverage requests, most vishing scripts stop working.