Introduction
Difference between Vishing, Phishing, and Smishing
Vishing, phishing, and smishing are all social-engineering techniques designed to trick individuals into disclosing sensitive information, approving fraudulent activity, or enabling unauthorised system access. The key difference is the communication channel used by the attacker.
| Threat Type | Primary Channel | Typical Objective | Example |
|---|---|---|---|
| Vishing | Voice call or voicemail | Obtain credentials, MFA OTP codes, payment approvals, or account information through verbal deception. | A caller impersonates IT support and asks an employee to re-enrol MFA or disclose an OTP. |
| Phishing | Email or web link | Direct users to malicious links, fake login pages, or infected attachments. | An email claims the user must verify their account through a spoofed login page. |
| Smishing | SMS or messaging app | Prompt users to click malicious links or disclose account details through mobile messages. | A text message claims an account will be frozen unless the user confirms their credentials. |
Vishing Examples
- Help Desk Password Reset: Attackers pose as IT support staff, claiming that a system migration requires an urgent password change or MFA re-enrolment, allowing the attacker to hijack corporate credentials.
- Executive Voice Cloning / Deepfakes: Cybercriminals use AI-generated voice cloning of a CFO, Managing Director, or other senior leader to instruct a finance employee to make an urgent and confidential wire transfer.
- Vendor Bank-Change Pretexting: Scammers call the accounts payable department pretending to be an established supplier and request an immediate change to vendor bank account details.
Recent Vishing Incident
On 7 August 20261, Google’s Threat Intelligence Group reported vishing campaigns employed by a financially motivated threat cluster tracked as UNC6671. While UNC6671 has not been directly attributed to the recent attacks on U.S firms, the group has historically used vishing to support ransomware and data-extortion activity against the financial and legal sectors in Australia, Canada, and the United States.
UNC6671’s vishing activity involves targeting employees’ personal mobile devices directly and, in some cases, spoofing legitimate IT helpdesk numbers to appear credible2. Victims are directed to spoofed login portals hosted within adversary-in-the-middle (AiTM) infrastructure, which intercepts credentials and MFA session tokens in real time. These portals are typically designed to mimic enterprise authentication pages, using pretexts such as passkey enrolment, MFA re-enrolment, or Single Sign-On migration. Once attackers gain access through an employee account, automated scripts are used to exfiltrate data from enterprise cloud environments such as Microsoft 365 and Okta. To delay detection, attackers may delete password-reset indicators or related alerts.
In addition to conventional extortion tactics such as encrypted communication channels and short response deadlines, UNC6671 is known to hijack internal corporate platforms to message executives and HR personnel directly, increasing pressure during ransom negotiations involving exfiltrated data.
Warning Signs
- An unsolicited telephone call concerning your account, a purported “security issue,” or a request to “verify your identity.”
- A request to disclose your password, personal identification number, or a one-time passcode sent to your registered device.
- A request to access an unfamiliar website to “re-enrol,” “confirm,” or “migrate” your account credentials.
- Pressure to act immediately, including threats that your account will be suspended, frozen, or disabled.
- Spoofed phone numbers that appear to be from trusted businesses or institutions, subtly different from the real ones.
Recommended Actions
The activity attributed to UNC6671 highlights how threat actors can combine voice-based social engineering with adversary-in-the-middle (AiTM) infrastructure to bypass authentication controls and access enterprise environments. To reduce exposure to similar threats, financial institutions should consider the following actions:
- Review controls on employee login sessions and monitor for session-token reuse, unusual authentication patterns, and suspicious TLS fingerprinting.
- Raise employee awareness on voice-phishing tactics, including spoofed helpdesk calls, requests for MFA codes, and prompts to enrol in passkey or SSO migration processes.
- Apply safeguards such as holding periods, dual control for MFA reset and re-enrolment requests, and independent notifications to both user and security team.
- Establish out-of-band verification procedures for unsolicited helpdesk or IT support calls, enabling employees to validate callers through a known and trusted channel.
- Monitor for lookalike domains and phishing websites impersonating the organisation to support timely takedown.
- Share relevant cyber-threat information with MAS’ Research & Intelligence team.
How We Can Help
At Kai Global, we partner with various IT specialist firms, to assist you in understanding of your IT security, performing GAP analysis, and proposing action plans to achieve your IT resilience and data protection objectives.