Vishing: An Evolving Threat to SLTT Organizations
ID: 96524f0e-11b8-5fd0-bf8b-1321dc9580d2
STIX ID: report--96524f0e-11b8-5fd0-bf8b-1321dc9580d2
Feed Name: CISecurity.org Insights Blog
## Executive Summary The CIS CTI team assesses vishing will likely pose increasing risk to U.S. SLTT organizations over the next 12 months as threat actors—enabled by AI and social-engineering tradecraft—impersonate help-desk and senior staff to harvest OTPs, transfer MFA/passkeys, and gain unauthorized access; documented effects include vendor account compromise and large-scale data exfiltration. The bulletin details observed incidents, industry trend data, AI-enhanced capabilities, supply-chain consequences, and actionable defenses such as strengthened help-desk verification, monitoring for authentication anomalies, FIDO2 adoption, and MS-ISAC participation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
