Voice Phishing is a Growing Social Engineering Threat
ID: 2c5a8d7e-23a7-586d-8c48-4a3b6f40469e
STIX ID: report--2c5a8d7e-23a7-586d-8c48-4a3b6f40469e
Feed Name: KnowBe4 Blog
Threat Score
Mandiant found that voice phishing (vishing) overtook email as the leading initial intrusion vector in 2025; live, interactive calls allowed attackers to steer conversations and bypass automated controls, resulting in campaigns (attributed to clusters like UNC6040/UNC6240 and UNC3944) that harvested credentials and authorized attacker-controlled SaaS access, leading to Salesforce compromises and subsequent extortion demands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
