The phone rings; you see a number that looks like your bank’s, and you pick up without thinking twice. That’s exactly what vishing is: a phone scam that uses social engineering and identity theft to steal your login credentials, verification codes, or money.
The term is a portmanteau of “voice” and “phishing,” and in recent years it has become one of the fastest-growing types of fraud in Spain.
What exactly is vishing?
Vishing is a phone scam in which the attacker impersonates a trusted entity (a bank, the tax authority, a telecommunications provider, or a company’s technical support) to trick the victim into revealing sensitive information or authorizing a transfer. No malware is involved, and there is no link to click; the entire attack happens during the conversation.
According to data from INCIBE, the public cybersecurity agency handled more than 120,000 cybersecurity incidents in 2025—a 26% increase from the previous year—and the industry itself reports that vishing was one of the fastest-growing types of cyberattacks during that period.
The Ministry of the Interior recorded 489,248 cybercrimes in 2025, of which 430,493 were computer scams. Far from being an outdated channel for fraud, the telephone has become one of scammers’ preferred methods.
How Does Vishing Work? The Anatomy of a Fraudulent Call
A vishing attack usually follows a fairly recognizable script once you’re familiar with it, even if it seems convincing at the time:
- Caller ID spoofing. The number you see on the screen looks real—it even matches your bank’s number—because the attacker has forged it.
- A sense of urgency. They alert you to a suspicious charge, an account freeze, or a held package. The goal is to make you act out of fear rather than calmly.
- Request for information or codes. They ask you to “confirm” your identity by providing an SMS code, your PIN, or saying “yes” out loud—information that can later be used to access your accounts, just like an infostealer that compromised your device.
- Quick hang-up. Before you can verify anything through another channel, the call ends and the damage is already done.
What has changed in recent years is the technical sophistication. Voice cloning using artificial intelligence now makes it possible to imitate the voice of a family member or an executive with just a few seconds of audio—something that sounded like science fiction a few years ago but is now a real threat to businesses and individuals alike.
You might be interested in:> SIM Swapping: What It Is, How It Works, and How to Avoid This Scam in 2026
Examples of vishing currently circulating
Here are some of the most common examples of vishing reported in Spain:
| Call Type | What they say | What they’re looking for |
| Fake Bank Security Department | “We’ve detected suspicious activity in your account” | SMS code or online banking password |
| Fake technical support | “Your computer has a virus; we need remote access” | Install remote control software |
| Fake Tax Agency | “You have a pending tax refund—please confirm your information” | Bank and personal information |
| Voice-Based CEO Fraud | “I’m the CEO; I need an urgent wire transfer” | Payment authorization from an employee |
| Fake telephone operator | “We’re going to upgrade your plan—please confirm the code you receive” | Fraudulent number porting |
This last scenario is particularly dangerous because, if the scammer manages to port your number, they can intercept the verification codes from your banking apps.
How to Spot a Vishing Attack Before It’s Too Late
There are signs that are almost always present, although sometimes it’s hard to see them in the heat of the moment:
- They contact you unexpectedly and in a hurry, leaving you no time to think.
- They ask for information that the real organization would never ask for over the phone, such as your full PIN or an SMS code.
- They insist that you don’t hang up and call that number yourself to “verify” that it’s legitimate: that’s exactly the opposite of what you should do.
- The caller ID matches your bank’s actual number—but that’s no longer a guarantee of anything, since caller ID spoofing is commonplace.
An important note: the classic advice to “hang up and call the number you have saved” is still valid, but only if you manually dial the number from your own phone—never call back or press any buttons the scammer suggests.
How to Avoid Vishing
Preventing vishing doesn’t depend on having more technology, but on changing a few habits:
- Never give out verification codes over the phone. No legitimate organization asks for them that way.
- Hang up and verify through another channel. Contact your bank through the official app or the phone number listed on your documents—not the one that called you.
- Be wary of any sense of urgency. Almost any real problem can wait ten minutes while you verify the information.
- Install a call blocker that uses a database of numbers reported as fraudulent.
- If you run a business, train your team. Voice-based CEO fraud has grown because many employees don’t know it exists.
If you’ve already provided any sensitive information, act quickly: block your cards or access through your bank’s app, change your passwords, and file a report with the police or the Civil Guard. The sooner you act, the less time the scammer has to use that information.
Vishing in the Business World: Continuous Monitoring vs. Exposure
For a company, even one employee falling victim to vishing can open the door to a credential leak, CEO fraud, or unauthorized access to internal systems. One-time training is no longer enough; you must know at all times what data, credentials, or references about the organization are circulating externally, because many vishing campaigns are built using information from previous data breaches or exposed corporate profiles.
This is precisely what Continuous Threat Exposure Management (CTEM) is—a cyber-surveillance approach that continuously monitors what information about your company, your employees, or your suppliers is accessible to a potential attacker before they can use it.
Kartos, Enthec’s cybersecurity monitoring solution, applies this CTEM model to businesses, detecting leaked credentials, data exposure, and attack surfaces that are later exploited in targeted vishing campaigns.
Frequently Asked Questions About Vishing
Is vishing the same as phishing?
No. Phishing occurs via email or a link, while vishing occurs via a phone call. Both aim to steal data or money, but they use different channels and different manipulation techniques.
Can the bank refund my money if I fall victim to a vishing scam?
It depends on the specific case. If someone accessed your account without your consent, PSD2 regulations require the bank to refund the amount. If you authorized the transaction under false pretenses, the process is more complicated, although Spanish courts are increasingly ruling in favor of victims.
How do I know if a call from my bank is real?
Hang up and call the official number listed on your card or in the app yourself. Never use the number that called you or the one the caller suggests.
Are small businesses also targets of vishing?
Yes, in fact, they are a common target precisely because they tend to have fewer verification protocols than large corporations, and a single transfer authorized by mistake can result in a significant loss.


