AI-Powered Vishing Attacks Create New Evolution of Cyberthreats

by Zachary Barlow

August 27, 2026

To round out a week of cybersecurity-themed blogs, here’s something else to keep you up at night: AI-powered vishing attacks. Monday’s blog discussed fraudsters using a traditional playbook to run AI scams. Today’s topic shows how fraudsters are updating their playbooks with AI technology. Phishing attacks are nothing new. Hackers often resort to social engineering to obtain protected credentials. Vishing, however, uses AI to create convincing voice mimics, luring employees into trusting scammers on the other end of the line. A recent Willkie memo breaks down how these attacks work:

“These latest campaigns represent an escalation in both targeting precision and tactical sophistication. The threat actors employed effective social engineering strategies, relying primarily on voice phishing (“vishing”) to compromise targets. In vishing incidents, attackers contact employees on their personal cellphones, not just office lines, and impersonate an organization’s internal help desk, in some instances displaying the correct help desk phone number through caller ID spoofing. They claim urgent IT directives requiring employees to update passkeys or MFA credentials, then direct victims to convincingly spoofed websites.

When employees enter their credentials on these fraudulent sites, the attackers harvest passcodes live over the phone and hijack accounts within seconds. AI tools are enabling attackers to scale these campaigns more cheaply and broadly, using voice mimicry technology to impersonate trusted persons with increasing fidelity.”

Financial institutions are frequent targets for AI-powered vishing attacks as they hold large amounts of sensitive data, but any company can fall victim to this scam. The memo recommends updating your cybersecurity training to include modules on vishing. Establishing strong internal procedures and known practices can also help. IT should never request passwords over the phone. If passwords need to be shared, then organizations can use a trusted password manager application to do so. Employees should be trained to spot the red flags of a vishing attempt and err on the side of caution. Hanging up and calling IT back might be annoying, but it could save you from falling victim to vishing scams.