Beware of Phone Scams: Cishing & Vishing
Cishing – Fraud via Phone Calls
Cishing is a form of social engineering where scammers impersonate bank employees, IT support, or even colleagues over the phone.
Their goal: stealing login credentials, credit card details, or other sensitive data.
How does Cishing work?
Call from a seemingly reputable source
The caller ID may be spoofed to appear trustworthy.
Manipulation through urgency
Scammers claim there’s an urgent issue, such as suspicious account activity or IT problems.
Request for sensitive information
Victims are tricked into revealing passwords, PINs, or remote access credentials.
Follow-up attacks
Stolen data can be used to log into accounts, withdraw money, or launch further fraud attempts.
Vishing – The New Era of Phone Scams
While many companies have strengthened their defenses against email phishing, criminals are increasingly turning to Vishing (“Voice Phishing”)—fraud via phone calls. Attackers pose as bank employees, IT support, or even CEOs to steal sensitive information or trick employees into making fraudulent transfers.
Especially alarming: Thanks to AI-powered voice synthesis, scammers can now mimic voices with astonishing accuracy!
How does Vishing work?
CEO Fraud
A fake “boss” calls, urgently demanding a wire transfer.
IT Support Scam
A supposed Microsoft employee asks for login credentials.
Bank Fraud
Customers are asked to confirm “suspicious transactions”—but end up losing their money.
Why Are Cishing & Vishing So Dangerous?
Abuse of Trust
Fraudsters impersonate legitimate institutions, making it difficult for victims to detect deception.
Psychological Manipulation
Scammers create pressure to force quick decisions.
AI-Powered Deception
Deepfake technology can convincingly imitate real voices.
Risk for Businesses
An inattentive employee might disclose credentials, leading to data breaches or cyberattacks.
How Can You Protect Yourself?
Stay skeptical
Never disclose confidential information over the phone without verifying the caller’s identity.
Establish corporate policies
Set clear guidelines for handling sensitive data and suspicious calls.
Train employees
Regular awareness training helps recognize fraud tactics.
Verify identity
Always call back using the official phone numbers of the organization.
Strengthen IT security
Regularly change passwords and enable multi-factor authentication (MFA).
Use a professional backup solution
Even with all precautions, an attack can still happen. A secure, independent backup is crucial to prevent data loss. Businesses should not solely rely on internal backups or cloud services but invest in external, immutable backups.
Question Everything – Don’t Trust Blindly!
Cishing and Vishing rely on psychological manipulation to deceive victims. Companies should educate employees and protect their data with a reliable backup strategy—because once attackers gain access, it’s often too late.
Stay alert – and if a call seems suspicious, hang up!