Cybercriminals are constantly changing their tactics, and one of the fastest-growing threats isn't arriving in your inbox—it's calling your phone.
Known as voice phishing, or vishing, these attacks involve criminals posing as trusted individuals, such as your IT provider, Microsoft support, your bank, or even a company executive. Their goal is simple: convince you to hand over sensitive information or approve a login request that gives them access to your organization's systems.
This summer, cybersecurity researchers linked the hacker group ShinyHunters to several high-profile attacks that began with convincing phone calls to employees. Instead of exploiting a technical vulnerability, the attackers exploited something much harder to patch: human trust.
How Voice Phishing Works
A typical vishing attack may look something like this:
- You receive a call from someone claiming to be Microsoft or your IT support team.
- They tell you there's suspicious activity on your account or a problem that needs immediate attention.
- They ask you to share a verification code, approve a multifactor authentication (MFA) request, reset your password, or install a remote support tool.
- Once you comply, the attacker gains access to your account and can move deeper into your organization's network.
Because these calls often create a sense of urgency and appear legitimate, even experienced employees can be caught off guard.
How to Protect Your Business
Voice phishing attacks rely on trust and urgency. A few simple habits can dramatically reduce your risk:
- Never share passwords or MFA verification codes over the phone.
- Be cautious of unsolicited calls claiming to be Microsoft, your bank, or technical support.
- If someone requests sensitive information, hang up and contact the organization using a verified phone number.
- Treat unexpected MFA prompts as a warning sign, not something to automatically approve.
- Report suspicious calls to your IT team immediately.
Stay One Step Ahead
Cybercriminals are increasingly targeting people instead of technology because it's often easier to manipulate an employee than break through modern security controls.
The good news is that a combination of security awareness training, strong authentication policies, and proactive monitoring can significantly reduce your risk.
If you have questions about protecting your organization from voice phishing or other emerging cyber threats, Common Knowledge Technology is here to help.

