What is vishing? Tips to spot and avoid voice phishing scams

Vishing is a phone-based phishing tactic, and scammers have made it even more convincing due to AI voice tricks. Get more details on what vishing is and how to spot these calls before you share any information. To help avoid getting on the phone with a scammer in the first place, Norton 360 Advanced can automatically block or label scam calls before they reach you.

SE labs logo

2025

Consumer

Security Innovator

av test award

2026

Top Rated Product

A woman talking confidently on the phone, knowing she's protected by the Norton Safe Call feature.

Voice phishing (vishing) scams are becoming more widespread and persuasive. According to a recent CrowdStrike report, vishing attacks surged by 442% in 2024, driven by scammers using polished scripts, real-time pressure, and even AI-generated voices to sound legitimate. And these sophisticated tactics are increasingly being deployed against everyday consumers.

Callers aim to sound believable enough to get you to share personal information, send money, or take action without double-checking. Learn about vishing so you can recognise these calls early and avoid getting caught up in the story.

What is vishing, and how does it work?

Vishing, short for “voice phishing,” is a phone-based cyberattack where cybercriminals exploit the phone as a tool for their schemes. During a vishing phone call, a scammer may try to get you to share personal information and financial details, such as bank account numbers and passwords.

Scammers usually pose as a trustworthy or authoritative source during a phone call. They may spoof the caller ID to appear legitimate or even use Voice over Internet Protocol (VoIP) technology to place hundreds of calls at a time for more widespread attacks.

Visual showing how vishing works in four steps, from the scammer posing as a trusted source to the victim giving the scammer their sensitive information.
Visual showing how vishing works in four steps, from the scammer posing as a trusted source to the victim giving the scammer their sensitive information.
Visual showing how vishing works in four steps, from the scammer posing as a trusted source to the victim giving the scammer their sensitive information.

What’s the difference between phishing, vishing, and smishing?

Vishing and smishing are types of phishing, but they use different communication channels. Smishing scams are delivered through SMS text messages, while vishing scams happen through phone calls or voice messages.

Here are the differences in detail:

  • Phishing: A cyberattack that uses fraudulent emails, texts, calls, or online messages to steal your data, gain access to account information (including logins), and monitor online activities. Attackers typically trick victims into clicking on malicious links or visiting fake websites.
  • Vishing (voice phishing): A type of phishing carried out through phone calls. These calls may come from a live person or a pre-recorded robocall, but the goal is the same: to pressure or deceive you into sharing sensitive information or taking actions that compromise your data.
  • Smishing (SMS phishing): A phishing attack delivered through text messages. While both smishing and vishing target phones, smishing relies on SMS or spam texts rather than voice calls to steal confidential information.
  • Quishing: A type of phishing that uses malicious QR codes. Scammers create fake QR codes that lead to malicious websites designed to steal your information.
A four-quadrant visual showing four different types of social engineering scams from phishing to quishing.
A four-quadrant visual showing four different types of social engineering scams from phishing to quishing.
A four-quadrant visual showing four different types of social engineering scams from phishing to quishing.

How to spot a vishing scam

Common signs of a vishing scam include urgency or fear-based pressure, unsolicited requests for sensitive information, and poor call quality. Understanding how vishing scams work can help you recognise these red flags quickly and stay in control during unexpected calls, making it easier to protect both your money and your personal information.

Here’s a closer look at warning signs to watch out for:

Unsolicited calls

Unsolicited calls you weren’t expecting are a classic vishing tactic. If something feels off, hang up, look up the official number, and call back directly. Most “urgent” calls claiming to come from organisations such as the Australian Taxation Office (ATO) and Medicare or large companies, turn out to be scams once you verify them.

Urgency and fear tactics

To pressure you into taking immediate action, scammers will use threats to create a sense of urgency. If you get one of these phone calls, remain calm and never give them any form of payment or personal information.

Requests for personal information

Anyone who calls out of the blue and asks you to confirm your Tax File Number (TFN), myGov details, bank account info, or other identifying details over the phone is likely a scammer. Never share confidential info on the phone unless you can confirm the source is who they say they are.

Background noise or poor audio quality

Pay attention to odd background noise or generally poor audio quality on phone calls. Subtle glitches, awkward pauses, or audio that doesn’t match the caller’s story can all be early signs that something’s wrong. Also, listen for unnatural or robotic-sounding voices, as it could be an automated or pre-recorded call.

How vishing scams bypass detection

Rather than relying on a single trick, scammers combine technical tactics with psychological pressure to slip past your defences.

Many vishing calls begin with caller ID spoofing, making the incoming call appear to come from your bank, local police, or a government agency. Automated dialling systems let scammers place thousands of calls at once, and because these interactions happen in real time, they often bypass the filters that catch suspicious emails or texts.

Once connected, vishers use natural-sounding scripts, casual small talk, or urgent warnings to put you off balance. These social engineering ploys closely mimic the tone and pacing of legitimate customer service teams, sounding credible just long enough to build trust.

By blending real company jargon with believable scenarios, vishers create calls that feel familiar and safe. Their goal is to extract enough personal information to commit identity theft or drain accounts before you realise what’s happening.

11 common examples of vishing scams

From bank impersonation to tech support fraud, vishing scams tend to take on a few common forms. Here are some vishing examples you're most likely to encounter.

1. Bank impersonation

A common vishing scam is when attackers pose as representatives from banks or financial institutions. Whether it’s a real person on the phone impersonating the bank or a prerecorded message, a scammer will often tell you there’s an issue with your account or a recent payment you made.

Using convincing scripts, they’ll trick you into sharing account details or PINs. They may even have you transfer funds to another account to fix the “problem.”

According to Scamwatch, in one bank scam, an Australian man was scammed out of $500,000 after receiving a call from someone impersonating a major bank’s security department and asking whether he had authorised a payment.

2. Tech support scams

This type of vishing scam frequently targets older adults aged 65+, as they are more likely to fall victim to tech support scams than younger people. According to the Australian Bureau of Statistics, although Australians aged 65 and over comprise approximately 17% of the population, they account for over 26% of total losses reported to Scamwatch. reported to Scamwatch.

Scammers may pose as tech support personnel from large companies like Amazon or Microsoft. In this vishing scam example, the scammer could call you claiming to have detected a harmful virus on your phone or computer, or to alert you of an important software update.

From there, they’ll convince you to share your personal information or login credentials and even request remote access to your devices to solve the issue or install the update. In one case, a caller posing as a Telstra employee told the victim that their internet connection had been compromised, manipulating them into sending money overseas in order to stop the “hackers,” resulting in a loss of $520. resulting in a loss of $520.

3. Medicare, Centrelink and myGov scams

Vishing scammers may pose as representatives from Medicare, Centrelink, or myGov and claim there is a problem with your account, payment, or records to try to glean sensitive, personal or financial info such as your Medicare number or bank account details.

By impersonating these trusted organisations, they can threaten you with fines, suspension of benefits, or other consequences to encourage you to act immediately. From there, they may use the information collected to steal money, access accounts, or commit identity fraud.

4. ATO impersonation scams

Vishing attackers may pose as Australian Taxation office (ATO) employees, issuing false warnings about unpaid taxes. The goal is to create panic, leading you to share sensitive information or make payments to resolve supposed problems.

There are many variations of this type of scam. Typically, you'll receive a prerecorded message about an issue with your tax return, and if you don't call back, they will issue a warrant for your arrest. Scammers may also pair this with a spoofed caller ID made to look like the call is coming from the ATO.

When in doubt, hang up and contact the ATO directly either through the official app or website, or by calling 1800 008 540 to check if the contact is real. or by calling 1800 008 540 to check if the contact is real.

5. Shipping or delivery scams

In shipping or delivery scams, callers pose as postal or courier service agents and claim there’s a “problem” with your parcel. They may cite a customs fee, an address issue, or the need to verify your identity before delivery can proceed. To sound routine, they often reference a well-known carrier such as Australia Post or FedEx.

Once the setup is in place, they try to collect personal information or direct you to a fake payment link. These calls can feel convincing because parcel deliveries are so common — but if you receive an unexpected request for payment or sensitive information, check the delivery independently through the carrier’s official website or app.

6. Investment or loan scams

In loan and investment scams, callers pitch low-interest loans, high-return investments, or “guaranteed” financial opportunities. They rely on polished scripts and high-pressure sales tactics to get you to commit quickly, often urging you to share banking details on the spot.

According to the National Anti-Scam Centre investment scams cause more financial loss in Australia than any other scam type. In 2025, Australians reported combined losses of $837.7 million to investment scams.

These numbers highlight just how widespread and convincing these schemes have become. The pressure is the giveaway. Legitimate lenders and financial advisers don’t rush decisions or demand immediate deposits. If an offer sounds like a shortcut to easy money, it’s usually a sign someone is trying to cash in on your trust.

7. Prize scams

With prize scams, the caller claims you’ve won something — a holiday, a gift card, or even a cash reward. However, to receive the prize, you’re told to verify your identity or pay a small processing or tax fee.

Scammers rely on excitement to cloud your judgement, hoping you’ll act before you think. But legitimate competitions don’t require upfront payment or sensitive details. If your lucky “win” comes with strings attached, it’s almost always a setup.

Scamwatch warns that scammers may pose as well-known businesses such as airlines or hotel chains in these travel prize scams to make the ruse more believable.

8. Romance vishing scams

Romance scams start with trust. The caller pretends to be someone from a dating app, social network, or even a long-lost acquaintance. Once a connection is established, they pivot to personal requests, such as asking for money for an emergency, access to an account, or private details they can misuse later.

Because these calls lean heavily on emotion, they can feel more believable than typical scams. A sudden request for financial help or sensitive information is the clearest sign that the relationship isn’t what it seems.

One Reddit user shared how a scammer not only manipulated them emotionally but also managed to deceive their father with the same fabricated story.

9. Family emergency impersonation scams

In family scams, callers pretend to be a child, grandchild or other relative claiming they’re in trouble and need help right away. They rely on urgency and fear to override scepticism. What makes this trick even harder to catch now is the use of AI-generated voices that can mimic real family members.

With just a short audio sample, attackers can create a voice clone that sounds close enough to spark panic. If a call leaves you rattled, take a breath, hang up, and check in with the family member via a different channel before taking action. 

In one recent operation, scammers stole $5 million from 400 older adults in the U.S. by impersonating distressed grandchildren and demanding immediate payment.

10. Executive impersonation

Executive impersonation scams target employees by mimicking the tone, authority, and urgency of company leaders. The caller may claim there’s an unexpected payment to process, a confidential project underway, or a sensitive document they need access to right away.

Because the request appears to come from someone in charge, you may jump to act without verification. But legitimate executives typically don’t bypass normal procedures or pressure staff into rushed decisions. A quick call or message through an official channel is all it takes to confirm whether the request is real.

One IT administrator reported that job applicants received calls and messages from scammers impersonating their company, offering fake roles, highlighting how attacker-scraped job-site data can lead to realistic leadership impersonations.

11. Voice cloning and deepfakes

Some of the most advanced vishing scams now use AI tools to recreate voices — or even faces — to make calls or videos sound and look authentic. Attackers blend social engineering with deepfake technology, creating messages that feel personal and urgent.

These tools can replicate speech patterns, accents, and emotional tone, making scams harder to spot. As the technology improves, awareness becomes your best defence. If a message feels scripted, unusually urgent, or “too perfect,” it’s worth slowing down and verifying it independently.

In one case, fraudsters impersonated the CEO of WPP using a fake WhatsApp account, a cloned voice, and a fabricated Teams meeting to try and trick an agency leader into setting up a new business venture.

Emerging tactics and technologies in vishing

Vishing continues to evolve, and attackers these days mix classic tricks with new tech to stay one step ahead. However, understanding what a vishing attack is means you can keep up and see how these tools work behind the curtain.

Emerging vishing tactics and technologies include:

  • Caller-ID spoofing: Lets scammers mimic trusted numbers to make their calls look legitimate.
  • VoIP services: Make it cheap and easy for scammers to launch calls from anywhere in the world.
  • Robocall automation: Allows attackers to send thousands of scripted calls in just minutes.

But the biggest shift comes from AI scams. Voice-cloning tools can replicate real speech patterns with unsettling accuracy, giving scammers the ability to sound like people you know and trust. Some operations even use AI to generate dynamic call scripts that adapt in real time to your responses, making conversations feel natural and unscripted.

These evolving tactics make staying informed more important than ever. The better you recognise the patterns, the easier it is to shut down even the most convincing scam.

Visual with person sitting in the centre showing all of the reasons why traditional security fails against vishing such as no digital trail or no email filters.
Visual with person sitting in the centre showing all of the reasons why traditional security fails against vishing such as no digital trail or no email filters.
Visual with person sitting in the centre showing all of the reasons why traditional security fails against vishing such as no digital trail or no email filters.

How to protect yourself from vishing

Staying prepared is your best defence against unpredictable or misleading calls. Use these tips to safeguard yourself and your data from a vishing scam:

  • Verify caller identities: Always confirm a caller’s identity, especially if they request sensitive information. If they provide a call-back number, it may be part of the scam — so don't use it. Instead, search for the company's official phone number and call them to confirm if the call was legitimate.
  • Ignore calls from unknown numbers: Although it may be tempting to answer every phone call, simply let them go to voicemail if you don’t recognise the number. Listen to your messages and decide whether to call the person back.
  • Trust your instincts and hang up: The moment you suspect a vishing phone call, don't feel obliged to converse politely. Simply hang up and block the number.
  • Join the Do Not Call Register Australia’s Do Not Call Register is a free service that can reduce unwanted telemarketing calls to personal home and mobile numbers. But it won't stop people from illegally calling your number, so it’s important to remain vigilant against suspicious calls. important to remain vigilant against suspicious calls.
  • Use call-blocking features: Enable call-blocking features on your phone to filter out potential vishing scams. Most smartphones offer this function to help you avoid fraudulent calls.
  • Use two-factor authentication: Add an extra layer of security to your mobile device and accounts by enabling two-factor authentication.

The tips above can help you identify and avoid vishing attempts while improving your overall cybersecurity.

Common vishing targets

Some people are targeted more often because scammers see an opening — access to money, weaker verification habits, or situations where pressure is likely to work. Knowing where you fit makes it easier to recognise vishing attempts and shut them down quickly.

Common vishing targets include:

  • Older adults: Phone scams targeting seniors often assume greater trust or less familiarity with rapidly evolving technology.
  • Young adults and students: Targeted with fake loans, scholarships, or job offers while juggling tight budgets and busy schedules.
  • Remote workers: Approached through fraudulent IT calls or “urgent” company updates, exploiting reliance on phone and digital communication.
  • New customers or recent account holders: Scammers take advantage of the confusion that can come with setting up new services, hoping details are confirmed without scrutiny.
  • Finance and HR staff: Targeted for access to payroll, invoices, and sensitive employee data.
  • Small business owners: Busy schedules and direct access to business accounts make them appealing targets for fake supplier or payment requests.
  • Healthcare workers: Pressured with fabricated patient issues or urgent access requests in fast-paced work environments.
  • Parents: Manipulated with false emergencies involving their children, often amplified by voice cloning or urgent narratives.
  • Hiring managers: Scammers pose as candidates or vendors to gain access to internal systems or collect sensitive information.

What to do if you’ve been vished

When a vishing call slips through, quick action makes all the difference. Here’s what to do when you realise something isn’t right:

  1. End the call: Hang up immediately and make a note of what they asked for, the number displayed, and anything that felt unusual. This helps you stay grounded and gives authorities helpful details. Don’t return calls to the number they provided. Instead, visit the organization’s official website and use the listed phone number to verify the call independently.
  2. Secure your accounts: Update your login details, create a secure password, and review recent activity. If you shared banking or payment information, contact your bank or financial institution so they can protect your accounts quickly.
  3. Report the incident: File a report with the National Anti-Scam Centre’s Scamwatch service. If you lost money through cybercrime or your identity or accounts have been compromised, you should also make a report through ReportCyber. Keep relevant evidence, such as the phone number displayed, messages, screenshots, and transaction records.

Keep you and your phone safe from scammers

Vishing attacks are designed to catch you off guard, but knowing the warning signs helps you stop scams before personal information slips out. Staying informed puts you one step ahead of cybercriminals who rely on urgency and deception over the phone.

For added protection, Norton 360 Advanced goes further, helping to block scam calls, and a full suite of advanced AI scam protection tools that can help detect scam texts, sites, and deepfake videos. Take the guesswork out of spotting scams — let Norton handle the heavy lifting.

Vishing FAQs

How can I tell if a call is vishing?

You can often spot a vishing call by signs like undue urgency, pressure to act quickly, unexpected requests for personal information, or a caller ID that doesn’t match the pretext. Any call that feels rushed, inconsistent, or off is worth treating with caution.

What should I do if I get a suspicious call?

If you get a suspicious call, hang up immediately. Ending the call prevents the scammer from cloning your voice, steering the conversation, or pressuring you into quick decisions. Then contact the company, organisation or public body directly using the phone number listed on its official website to confirm whether the call was legitimate.

What’s the best response to a vishing call?

The safest response to a vishing call is to disconnect right away, block the number, and avoid saying anything that could be recorded or reused later.

What is voice spoofing?

Voice spoofing is when scammers disguise their phone number or imitate someone’s voice to make a call appear trustworthy. The goal is to lower your guard so you’ll share information or follow instructions, making it a common tactic in vishing and other phishing attacks.

What is smishing and vishing?

​​Smishing (SMS phishing) uses text messages to trick you into sharing information, while vishing relies on phone calls. Both are phone-based scams designed to steal personal or financial details.

Oliver Buxton
Oliver Buxton, a staff editor for Norton, specializes in advanced persistent threats. His work on cyberterrorism has appeared in The Times, and his prior work includes writing digital safeguarding policies.

Editorial note: Our articles provide educational information for you. Our offerings may not cover or protect against every type of crime, fraud, or threat we write about. Our goal is to increase awareness about Cyber Safety. Please review complete Terms during enrollment or setup. Remember that no one can prevent all identity theft or cybercrime, and that LifeLock does not monitor all transactions at all businesses. The Norton and LifeLock brands are part of Gen Digital Inc. 


Want more?

Follow us for all the latest news, tips, and updates.

Protect against vishing

Get Norton 360 Advanced to help detect and block scam calls.

Protect against vishing

Get Norton 360 Advanced to help detect and block scam calls.

Norton 360 Advanced