TL;DR: Vishing has moved beyond simple phone scams: attackers now combine VoIP, caller ID spoofing, and AI voice cloning to impersonate executives and vendors, making legacy annual awareness training too slow to counter modern social engineering, according to Living Security Human Risk Management Platform. The real governance gap is verification discipline, not employee intelligence, because trust in voice and caller ID is no longer a reliable security control.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: How to Spot and Prevent a Vishing Social Engineering Attack
Questions worth separating out
Q: What breaks when organisations trust caller ID or voice as proof of identity?
A: Caller ID and voice are no longer reliable identity signals because both can be spoofed or cloned.
Q: Why do vishing attacks still work against trained employees?
A: Training helps, but vishing succeeds because it exploits real-time pressure, authority cues, and the human tendency to help.
Q: How do organisations know if vishing controls are actually working?
A: They know by measuring behaviour under pressure, not by counting training completions.
Practitioner guidance
- Implement mandatory callback verification Require employees to end any unexpected call involving access, money, or credentials and call back using an official number from a trusted source.
- Block sensitive requests over voice Prohibit password resets, MFA code sharing, payment approvals, and remote-access grants from being completed by phone alone.
- Add vishing scenarios to identity training Include executive impersonation, spoofed help desk calls, and AI voice cloning in phishing simulations and role-based awareness content.
What's in the full article
Living Security Human Risk Management Platform's full article covers the operational detail this post intentionally leaves for the source:
- Practical examples of the exact words attackers use in executive impersonation and urgent request scenarios
- Step-by-step guidance for building a callback verification rule into employee response procedures
- Expanded discussion of how AI voice cloning changes social engineering detection
- Additional advice on reporting, documentation, and recovery after a suspected vishing call
👉 Read Living Security Human Risk Management Platform's analysis of how to spot and prevent vishing →
AI voice cloning in vishing: what controls are missing?
Explore further
AI voice cloning has turned vishing into a human identity verification failure. The core problem is no longer whether employees know not to share passwords. It is that a believable voice, a familiar number, and urgent language now mimic the cues people use to decide whom to trust. IAM programmes that do not account for voice-channel impersonation are leaving a governance gap between authentication policy and real-world behaviour. Practitioners should treat voice trust as an unmanaged identity signal.
A question worth separating out:
Q: Who is accountable when a vishing attack leads to account takeover?
A: Accountability usually spans identity operations, service desk ownership, and security governance because the failure often sits in the recovery process, not the login prompt. Teams should review who approves resets, who audits enrolments, and who owns containment when a legitimate session is abused.
👉 Read our full editorial: Vishing now blends AI voice cloning, spoofing, and human risk