During Cyber Security Awareness month, we will be exploring some cyber related terms you may have heard of but may not fully understand. We hope to raise awareness and ultimately work to improve UK cyber security resilience. In this article, we will explore vishing. Vishing, a portmanteau of voice and phishing, is a type of social engineering attack where fraudsters use telephone calls to deceive individuals into divulging sensitive information such as passwords, credit card numbers, or other personal data. It is a sophisticated form of phishing that leverages human interaction to exploit vulnerabilities in security protocols and human psychology. The Mechanism of Vishing At its core, vishing relies on the manipulation of human trust. Attackers often pose as authoritative figures such as bank officials, IT support staff, or government agents to gain the victim’s confidence. The overarching goal is to create a sense of urgency or fear, prompting the victim to act hastily without considering the authenticity of the request. Common Vishing Techniques
- Impersonation: Attackers may impersonate trusted entities, such as a bank or a technical support team, to extract sensitive information. They might use spoofed phone numbers to make the call appear legitimate on caller ID systems.
- Pretexting: This involves creating a fabricated scenario to engage the victim. For example, the attacker may claim there is a problem with the victim’s account that needs immediate attention.
- Urgency and Threats: By instilling a sense of urgency, such as claiming that the victim’s account will be locked, attackers can pressure victims into revealing confidential information quickly.
- Social Engineering: Attackers may use information gleaned from social media or other sources to make their approach more convincing. They can reference personal details to establish credibility.
- Multi-Stage Attacks: Some advanced vishing schemes involve multiple interactions, where initial calls gather basic information that is later used to execute the final attack.
Targets of Vishing Attacks While anyone can be a target, certain groups are more vulnerable to vishing:
- Individuals: Personal accounts, especially those with significant funds or sensitive information, are prime targets.
- Businesses: Corporate executives and employees with access to sensitive data or financial systems are often targeted.
- Call Centres: Given their role in handling customer accounts, call centres are frequent targets for vishing attacks. Attackers may aim to reset passwords or gain access to accounts through social engineering.
Preventing Vishing Attacks
- Awareness and Training: Education is the first line of defence against vishing. Employees and individuals must be trained to recognise the signs of a vishing attempt. Regular awareness programs can help build a culture of vigilance.
- Verification Protocols: Organisations should establish strict verification protocols for handling sensitive information over the phone. This might include call-back procedures where employees can verify the caller’s identity through official channels before proceeding with any request.
- Advanced Call Filtering: Using technology to filter and block suspicious calls can mitigate the risk. Call filtering services and caller ID verification can help identify and block spoofed numbers.
- Encouraging Scepticism: Individuals should be encouraged to question unsolicited requests for information. Legitimate organisations rarely ask for sensitive information over the phone, and any such request should be treated with caution.
- Establishing Clear Communication Channels: Organisations should ensure that employees and clients are aware of the official communication channels and protocols. Clear guidelines about when and how sensitive information will be requested can help prevent confusion and reduce the likelihood of falling victim to vishing.
- Monitoring and Reporting Mechanisms: Implementing systems for monitoring and reporting suspicious activities can help organisations detect and respond to vishing attempts promptly. Employees should be encouraged to report any unusual or suspicious calls to the IT or security department immediately.
Steps to take if you suspect a vishing attack If you suspect you are the target of a vishing attempt, consider the following steps:
- Hang up: If a call seems suspicious, it is best to hang up immediately.
- Verify the Caller’s Identity: Contact the organisation directly using a verified phone number to confirm the legitimacy of the call.
- Report the Incident: Notify your organisation’s IT department or relevant authorities about the suspicious call.
- Monitor Accounts: Keep an eye on your accounts for any unusual activity and report any discrepancies immediately.
The Future of Vishing As technology evolves, so too do the tactics of cybercriminals. The advent of artificial intelligence and deepfake technology presents new challenges in combating vishing. Attackers could potentially use AI-generated voices to mimic trusted individuals, making it even harder to discern legitimate calls from fraudulent ones. Organisations and individuals must stay ahead of these evolving threats by continuously updating their security protocols and maintaining a high level of awareness. The key to mitigating the risks associated with vishing lies in a combination of technology, education, and vigilance. What can Arcanum do about it? Arcanum has recently conducted a vishing campaign on a call centre as directed by a client. We utilised professional intelligence trained consultants to complete Open-Source Intelligence (OSINT) collection on the client and call centre IT helpdesk. The aim of the OSINT collection was to ascertain details that would be of use to a threat actor to enable a credible vishing attack against the call centre in an attempt to facilitate the reset of an account password or MFA token such as:
- Help desk telephone numbers to facilitate targeting the help desk.
- Details of call centre procedures to help identify weaknesses that may be exploitable.
During the campaign, we attempted to gain password reset details and tested service desk analysts’ adherence to procedure and whether they identified suspicious activity. We can do the same for your business and advise on how to best secure your organisation against future threats. Get in touch to find out how we can help.