What Is Vishing? How Voice Phishing Calls Work and How to Stop Them

Vishing, or voice phishing, is a scam carried out over a phone call or voice message. The caller pretends to be your […]

Madhurendra SachanBy Madhurendra Sachan
November 16, 2017
7 min read
Updated October 6, 2026
A person holding a phone, a phishing hook extending from the earpiece, ensnaring a dollar sign

Vishing, or voice phishing, is a scam carried out over a phone call or voice message. The caller pretends to be your bank, a telecom company, tech support, the police or a government agency, and uses fear or urgency to get an OTP, a PIN, remote access to your device or a payment. Hanging up and calling back on a number you trust stops most of it.

A phone call feels more personal than an email, and that is exactly why it works. There is no link to inspect and no sender address to check, only a confident voice and a deadline. Vishing is one of several channels a phishing campaign can use, and we cover the others in 10 types of phishing attacks.

How common vishing is

Call based fraud is large and still growing. In its 2025 Internet Crime Report, the FBI’s Internet Crime Complaint Center (IC3) counted more than 80,000 complaints about illegal call centres posing as tech support or government agencies, with losses above $2.9 billion. Tech support scams alone produced 47,794 complaints and about $2.13 billion in losses, and government impersonation added 32,424 complaints and about $798 million.

Some of those call centres operate from India. The same report describes Operation Chakra, in which India’s Central Bureau of Investigation, working with the FBI, dismantled a Noida based network in December 2025 and arrested six people. The group had cheated more than 600 Americans by posing as tech support and US agencies, and IC3 reports linked more than $48.7 million in losses to it.

The trend is still upward. The Anti-Phishing Working Group’s Phishing Activity Trends Report for Q2 2026 quotes Crane Authentication, which saw vishing rise 20% from the first to the second quarter of 2026.

How a vishing call works

Most vishing calls follow the same five steps:

  1. Research. The caller starts with your name, number and sometimes your bank or employer, often taken from a data leak or social media.
  2. A believable caller ID. The number on screen is spoofed or looks local, so the call seems to come from a bank, a courier or a government office.
  3. The script. You hear about a blocked account, a suspicious transaction, a parcel with illegal items or a pending arrest. The story is built to make you scared or rushed.
  4. The ask. The caller wants an OTP, card details, a UPI PIN, a screen sharing app installed, or money moved to a “safe” account.
  5. The cash-out. Money moves within minutes through mule accounts, so the victim’s bank has little time to stop it.

Common vishing scripts in India

The bank or KYC call

The caller claims your KYC has expired or a suspicious transaction is pending and asks you to confirm an OTP to “reverse” it. The Reserve Bank of India warned again in February 2024 about frauds in the name of KYC updates, which rely on threats to block the account.

Digital arrest

Callers pose as police, CBI, customs or narcotics officers, claim your Aadhaar or a parcel is linked to a crime, and keep you on a video call for hours until you transfer money to “clear your name”. In a Lok Sabha reply published by PIB, the Ministry of Home Affairs said I4C had blocked more than 1,700 Skype IDs and 59,000 WhatsApp accounts used for digital arrest. No Indian agency arrests anyone over a video call.

Courier and telecom calls

A recorded voice says a parcel is held or your SIM will be disconnected in two hours, then passes you to an “agent” who asks for personal details or a payment.

Tech support and the IT help desk

Some callers say your computer is infected and ask you to install a remote access app. Others target companies. The US Cybersecurity and Infrastructure Security Agency (CISA) describes how the Scattered Spider group calls IT help desks while posing as employees, to get passwords reset and MFA moved to a device the attackers control.

Why caller ID can’t be trusted

Caller ID shows whatever number the caller’s system sends, and that can be faked. The PIB release notes that the government and telecom operators now identify and block incoming international calls that display Indian mobile numbers, which criminals used in digital arrest and courier scams. That helps, but local numbers and fresh SIM cards still get through, so treat the number on screen as a claim, not proof.

How to protect yourself from vishing

  • Hang up and call back on the number printed on your card, statement or the official app. Never use a number the caller gives you.
  • Never share an OTP, PIN, CVV or password on a call. Banks and government offices don’t ask for them.
  • Don’t install screen sharing or remote access apps because a caller asked.
  • Be suspicious of any call that demands secrecy or tells you not to hang up.
  • Report suspected fraud calls on Chakshu on Sanchar Saathi, which takes reports of fraud calls, SMS and WhatsApp messages.
  • If money has left your account, call 1930 or report at cybercrime.gov.in immediately.

Speed also decides who carries the loss. Under the RBI’s 2017 circular on limiting customer liability, a customer who shared payment credentials bears the loss until the transaction is reported to the bank. Losses after that point fall on the bank.

How organisations can reduce vishing

  • Set a callback rule: payment changes and password resets are confirmed by calling a number already on file.
  • Give the help desk a verification process that a caller can’t talk around, and log every MFA reset.
  • Run vishing drills alongside email and SMS simulations, so staff practise saying no.
  • Watch for fake customer care numbers. Scammers publish them on lookalike websites, search ads and social media pages, and customers call them believing they are you. A takedown service removes those pages at the source.

Vishing often arrives together with a text message that asks you to call a number, so read our guide to smishing and the types of scam texts as well.

FAQ

Can someone steal money from me just through a phone call?

Not by the call alone. The caller needs you to do something: read out an OTP, approve a UPI request, install a remote access app or transfer money yourself. That is why the call is built to rush you. If you hang up, verify through the official number and share nothing, a vishing call can’t move your money.

Do police or the CBI ever arrest people over a video call?

No. There is no such thing as a digital arrest under Indian law. Real investigators send written notices and don’t demand payment to close a case. A caller who keeps you on video, forbids you to tell family and asks for a transfer is running a scam. End the call and report it on 1930 or cybercrime.gov.in.

What should I do if I shared an OTP during a call?

Call your bank’s official helpline at once and ask them to block the card, account or UPI access. Then report the fraud on 1930 or at cybercrime.gov.in so the receiving account can be flagged. Change any passwords you mentioned on the call and check your recent transactions. Reporting within minutes gives the best chance of stopping the money.

Want to learn more about protecting your organization?

Talk to a TIKAJ security expert and discover how our platform can help secure your digital ecosystem.

Get in Touch