CISO Newsletter

CISO Newsletter: Cyberattacks by phone – was the caller an AI after all?

6 min

By now, everyone is familiar with phishing emails designed to steal passwords. However, attackers are constantly searching for new methods to replace those that have become too familiar. Artificial intelligence has opened up entirely new possibilities for using phone calls in large-scale cyberattacks.
The phone rings, and an office worker at Company Ltd. answers. Let’s call him Frank.
“Hi, this is David from IT Support. Is this Frank? Great. We received an alert because someone is trying to log into your account from Portugal. Are you traveling by any chance? No? Then this looks like a cyberattack. We need to investigate the logs immediately, but we need your approval due to privacy requirements. You have an authenticator app on your phone, right? We can handle the approval the same way as a normal MFA login…”
Part of this story is that Frank is not the most security-conscious employee. Last week he received an enticing email and realized too late that he should not have entered his corporate account credentials. Fortunately, nobody noticed, and after all, MFA should protect him…

Vishing: Voice Phishing

The telephone is by no means a new tool in an attacker’s toolkit. Various phone-based social engineering techniques have existed for a long time, but their usability has been limited. Traditionally, making convincing calls has required manual effort and skilled attackers. Sounding credible over the phone is much more difficult than writing a convincing email.
As a result, vishing was never particularly scalable. It was mainly associated with intelligence operations and highly targeted attacks aimed at obtaining significant rewards.
AI has changed the playing field. Machine translation has been capable of generating convincing text in virtually any language for years, and now the same capabilities are emerging in spoken communication. AI can modify a person’s voice so that it sounds like someone else, such as a company’s CEO whose voice can easily be obtained from publicly available interviews and presentations.
AI can even hold conversations with victims. By combining publicly available components, attackers can create a system that speaks, listens, and uses a language model to interpret what the victim says and determine how best to respond. This enables entirely new attack methods. Vishing can suddenly become a mass-attack technique because machines can conduct numerous conversations simultaneously. As a result, the importance of addressing vishing in organizational security awareness programs has increased significantly.

Many Ways to Use Vishing

But what exactly can vishing be used for? Let’s look at a few examples.
Bypassing MFA
Multi-factor authentication (MFA) is an important security control, but it is not invincible. One common use case for vishing is bypassing MFA protections. Frank’s example demonstrates how an attacker can trick a victim into approving a login request.
Following Up on Other Attacks
Imagine that Frank has already entered his contact information and bank account details while expecting a prize or refund. It then becomes easy for an attacker to call him while posing as a bank security specialist investigating an attempt to compromise Frank’s account. Since the attacker already knows his account number, the story sounds convincing. Naturally, online banking credentials are then required to “verify his identity.”
Strengthening the Credibility of Another Attack Vector
An email asking someone to log in to investigate a “security issue” may seem suspicious. However, the situation becomes more believable if a slightly panicked IT support representative follows up with a phone call emphasizing how urgent the matter is and how important it is to act immediately.
Gathering Information
The purpose of vishing may simply be to collect information about a company or its employees. This could include personal identity numbers, customer information, or organizational data.
“Before we can process the order, we need to verify your identity. Could you please provide your personal identification number?”

How to Protect Yourself

Vishing requires new defensive approaches because it differs from the most common cyberattack methods in several important ways. Traditional technical monitoring and security controls operate within computer networks, but they cannot effectively monitor or block phone conversations. This means security awareness becomes the primary line of defense.
Most employees have been trained to recognize phishing emails. The underlying logic of a phone scam may be similar, but the change of medium makes it harder to identify. Victims are also forced to react immediately. There is no opportunity to carefully consider the situation or ask a colleague for a second opinion. Attackers exploit this pressure by insisting that the issue is urgent and must be handled right away.
Critical thinking and an awareness that unsolicited calls may be fraudulent form the foundation of protection. Include examples of vishing scenarios in security awareness training. Once suspicion has been raised, employees can begin asking questions and verifying details, disrupting the attacker’s plan. This may confuse a human caller and likely disrupt an AI-driven system even more effectively.
For example, ask for the helpdesk ticket number associated with the issue being discussed.
The most reliable defense, however, is to call back through trusted channels. Obtain the contact information from a reliable source and continue the discussion by calling the organization directly or using another verified communication method. This quickly reveals whether the original call was legitimate or fraudulent.

Are Your Security Policies Up to Date?

In addition to awareness training, security policies are an effective management tool. Do your organization’s policies address the following points?
1. Never disclose confidential information over the phone unless you are completely certain of the caller’s identity.
2. Never perform actions requested by a caller unless you are completely certain of their identity.
3. Never install software or modify settings based on instructions received over the phone unless you are completely certain of the caller’s identity.
4. Never approve MFA requests because someone calls and asks you to do so.
5. Report all suspected vishing attempts immediately, as the IT department cannot monitor what happens within telephone networks.

Is the Threat Real Today?

Email-based cyberattacks remain far more common than vishing attacks. For a long time, language barriers and the relatively small size of Finnish organizations limited the practicality of vishing in Finland. However, AI is rapidly removing both of these barriers.
The ability to conduct realistic conversations through AI makes vishing highly scalable and enables mass attacks in virtually any language. Predictably, the cybercrime ecosystem has recognized the opportunity. The market already offers tools for AI-generated speech as well as SaaS platforms designed to manage large-scale vishing operations.
Now is the right time to review your organization’s security policies and awareness training materials. Doing so can ensure that the first vishing attack does not come as a surprise to Frank or any other employees.

Mikael Albrecht,

Senior Security Consultant, 2NS

AI has been used to translate this blog into English.