Social engineering of a person
Vishing
Also called: help-desk social engineering, MFA reset fraud, callback phishing
Vishing is voice phishing: using phone calls or voice messages to trick someone into handing over access. Callers pose as IT support, a bank or an employee who is locked out. Aimed at a help desk, the goal is often a password reset or a new MFA device enrolled on the attacker's phone.
How it works
The attacker gathers names, job titles and personal details from public sources, then calls with an urgent, plausible story. Some send an email first that asks the target to call back. A successful call may end with the target reading out a code, installing remote access software or a help desk resetting credentials for the caller.
A real example
In a notification letter filed with the California Attorney General in August 2026, Quantum Health said unauthorized access to its IT network resulted from a user responding to a vishing call on May 29, 2026.
Source: Quantum Health notification letter to California residents — Quantum Health, Inc. (filed with the California Attorney General), 2026-08-14
The Identity Attack Ledger holds 12 cited incidents for social engineering of a person in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Verify callers at the help desk with something an attacker cannot look up, such as a push to the user's existing authenticator or a callback to a number on file, and require a second approver for privileged resets.
Related terms
Threat actors that use it
- ALPHV Blackcat
Profile with government sources
- Black Basta
Profile with government sources
- Scattered Spider
Profile with government sources
Sources
- Quantum Health notification letter to California residents — Quantum Health, Inc. (filed with the California Attorney General), 2026-08-14
Last reviewed Oct 2, 2026