logo

Hello, Operator? A Technical Analysis of Vishing Threats

ID: 26c06b0b-383f-54c2-9c46-0aa333846fe4

STIX ID: report--26c06b0b-383f-54c2-9c46-0aa333846fe4

Feed Name: Threat Intelligence

Threat Score
50/100

Date Published: 2025-06-04

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report describes how attackers use voice-based social engineering (vishing) against service desks—probing employee identification processes, exploiting scripted call-handling and verification gaps, spoofing caller IDs, and leveraging pretexts like forgotten passwords or travel-related phone loss—to gain unauthorized access or reset MFA. It details reconnaissance techniques, escalation paths for account compromise, and recommends defense-in-depth measures and secure verification practices to reduce the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.