When the Phone Rings: Why Vishing Is Becoming a Serious Business Risk
For years, organisations have invested heavily in securing email with spam filters, attachment scanning, and phishing awareness training. Yet one communication channel has often been overlooked: the telephone.
Cybercriminals know this, and they are increasingly exploiting it through voice phishing, or vishing.
According to CrowdStrike’s 2025 Global Threat Report, vishing attacks increased by 442% between the first and second halves of 2024. Cisco Talos also reported that voice phishing accounted for more than 60% of phishing-related incidents it investigated in early 2025.
Unlike traditional phishing emails, these attacks rely on convincing phone conversations. Attackers impersonate IT support, executives, banks, or trusted suppliers to persuade employees to reset passwords, approve multi-factor authentication requests, install remote access software, or authorise financial transactions.
Even major organisations are vulnerable. The widely reported MGM Resorts cyberattack began with a call to the IT help desk, demonstrating how a single successful phone conversation can have significant business consequences.

Why Caller ID Can’t Always Be Trusted
Many people assume that if a familiar number appears on their phone, the caller must be genuine. Unfortunately, that’s no longer the case.
Modern Voice over IP (VoIP) technology makes it relatively easy for attackers to spoof caller ID information, allowing them to display the number of a colleague, supplier, bank, or even your own organisation.
Although the telecommunications industry has introduced authentication frameworks such as STIR/SHAKEN to reduce caller ID spoofing, these protections are not yet universal. Calls that pass through older telephone networks or overseas carriers may lose their authentication, allowing spoofed calls to reach employees without any obvious warning.
Four Practical Ways to Reduce the Risk
While organisations cannot control the public telephone network, they can strengthen their own internal processes.
- Verify sensitive requests independently. If someone requests a password reset, payment, or account change over the phone, hang up and call back using a trusted number already on file.
- Restrict remote access tools. Limit who can install software such as AnyDesk, TeamViewer, or Quick Assist to prevent attackers from gaining remote access.
- Use stronger multi-factor authentication. Consider phishing-resistant authentication methods, such as FIDO2 security keys, for administrators and finance personnel.
- Encourage immediate reporting. Employees should feel comfortable reporting suspicious calls without fear of blame. Early reporting can help prevent a small incident from becoming a major breach.
Good Processes Beat Good Scammers
Vishing attacks rely on persuading someone to take a specific action. If your organisation requires independent verification before approving payments, resetting passwords, or granting system access, even the most convincing scammer will struggle to succeed.
Strong security isn’t just about technology, it’s about building processes that make fraudulent requests easy to identify and difficult to complete.
Protect Your Business with ADVANTUM Network Managed Services
Cyber threats continue to evolve, and businesses need more than reactive IT support. ADVANTUM’s Network Managed Services help organisations strengthen their security posture through proactive network monitoring, endpoint management, vulnerability management, security best practices, patch management, and expert technical support.
Whether you’re looking to improve your cybersecurity defences, increase network reliability, or reduce the burden on your internal IT team, ADVANTUM provides the expertise and ongoing support to help keep your business secure and operating efficiently.
Contact ADVANTUM today to learn how our Network Managed Services can help protect your organisation against today’s evolving cyber threats.
