What Is Vishing? Voice-Phishing Scams Explained

Vishing is voice phishing. It's a phone scam where criminals call you, pretend to be someone you trust, and try to get your personal or financial information. According to CrowdStrike's 2025 Global Threat Report, vishing attacks surged by 442% in 2024. In Canada, voice-phishing scams are among the fastest-growing fraud tactics, with the Canadian Anti-Fraud Centre reporting that Canadians lost over $704 million to fraud in 2025 across all categories.

You've probably seen the setup before. Your phone rings, the caller ID says your bank, the CRA, or a local number, and the person sounds calm, confident, and urgent. They say there's a problem with your account, a tax issue, or suspicious activity that needs to be fixed right away.

That's why this scam works. It doesn't rely on hacking your device first. It relies on pushing you to act before you stop and verify.

At Typewire, we think awareness is still your best defence. Once you know the pattern, vishing gets much easier to spot.

Last updated: 16 July 2026

What is vishing?

Your phone rings during a busy afternoon. The screen says your bank, the CRA, or a nearby number. The person on the line sounds calm and official, and they want you to confirm a few details “for security.”

That call may be vishing.

Vishing is short for voice phishing. It is a phone scam where someone uses a call, or sometimes a voicemail callback request, to pressure you into sharing personal information, banking details, login codes, or money. The method is simple. Instead of breaking into your device, the scammer tries to talk their way past your judgment.

A woman looks concerned at her phone during an incoming call from a potential vishing scammer.

The basic idea behind voice phishing

Vishing is a form of social engineering. That means the attacker is targeting human trust, not just technology. A convincing voice, a spoofed caller ID, and a stressful story can make an ordinary phone call feel legitimate.

In Canada, the familiar names matter. Scammers often pretend to be the CRA, a bank, a telecom provider, or technical support because those organizations already have a place in your daily life. A fake call about taxes or an account problem can feel believable before you have time to slow down and check.

Practical rule: If an unexpected caller asks for your password, PIN, one-time verification code, remote access, gift cards, or an immediate payment, treat the call as suspicious.

Why this matters in Canada

For Canadians, CRA impersonation scams are a common example because they tap into a specific fear. People worry about tax problems, missed payments, or penalties. Scammers use that anxiety to push for quick decisions, such as “verifying” your identity or paying on the spot.

There is also a privacy angle. If a vishing scammer gets your personal information and it is later mishandled by a business, Canadian privacy obligations under PIPEDA may come into the picture. For individuals, that means stolen details can cause more than a one-time loss. For small businesses, it is a reminder that phone-based fraud can turn into a customer data issue.

The safest habit is straightforward. If a call is unexpected and the caller wants sensitive information, hang up and contact the organization yourself using the number on its official website or on the back of your card. Awareness is your best defence, and with vishing, that pause is often enough to break the scam.

How voice phishing works

Most vishing calls follow a script. Once you understand the steps, the scam feels less mysterious and a lot more predictable.

A diagram illustrating the five-step process of voice phishing, showing how scammers trick victims over the phone.

The call starts with trust

The first trick is presentation. The number may look local. The caller ID may show the name of a bank or government office. That's often possible because scammers can spoof caller ID, which means they can make a call appear to come from a number you recognise.

Then comes the story. The caller might say there's suspicious activity on your account, a tax debt, a service interruption, or a login problem that needs immediate attention. Their actual goal is to stop you from slowing down.

CrowdStrike notes in this guide to vishing attacks that scammers often rely on fear, such as threats of arrest, or urgency, such as an account problem. The same source also warns that some attackers already have partial information from data breaches and use it to convince you to reveal the rest.

Why partial information feels convincing

This confuses a lot of people. They think, “How could it be fake if the caller knew my name, address, or email?” The answer is simple. Knowing a few details doesn't prove the caller is legitimate.

A scammer might know your name from a public profile. They might know part of your phone number, company, or address from an old breach or online listing. They use those fragments like props in a play.

If a caller knows something about you, that should raise your caution, not lower it.

Later in the call, the ask becomes more direct. They may request a one-time passcode, a login, your debit card details, or payment. Cisco's explanation of what vishing is and what attackers want makes the main goal clear: to steal private data for identity theft, financial gain, or account takeover.

Here's a short video if you want to see how these scams are commonly explained in practice.

A typical attack flow

  1. You get an unexpected call from someone claiming to represent a trusted organization.

  2. The caller creates pressure with a problem that sounds urgent.

  3. They build credibility by using your name or other partial details.

  4. They ask for sensitive information or payment.

  5. You're pushed to act immediately so you won't verify the story independently.

Once you see that pattern, the call becomes easier to interrupt. You don't have to win an argument with the scammer. You just have to stop the conversation.

Real vishing examples

The easiest way to recognise vishing examples is to hear how they sound in real life. These calls usually feel ordinary at first. The pressure comes a few seconds later.

The fake CRA call

You answer, and the caller says they're from the Canada Revenue Agency. Their tone is firm and formal. They tell you there's an unpaid balance, and if you don't deal with it now, you could face legal action or arrest.

Then the pressure sharpens. They may tell you to stay on the line, not speak to anyone else, and make payment immediately using gift cards or cryptocurrency. That combination of fear, speed, and strange payment methods is a classic sign of fraud.

The bank fraud department scam

This version sounds helpful, not threatening. The caller says they're from your bank's fraud team and that they're trying to protect you from suspicious activity. They may ask you to confirm a card number, online banking details, or a verification code that just arrived by text.

That code is often the main target. If you read it out, you may be giving them the final piece they need to access your account. The call sounds like security help, but the “verification” is really the theft.

Real security teams don't need you to read back your password or one-time code on an unsolicited call.

The fake service provider or tech support call

A small business version of this scam often targets the person who answers the phone or handles admin tasks. The caller claims to be from the internet provider, software support team, or internal IT partner. They say there's an outage, a login issue, or a service update that requires your credentials.

This works because the request sounds operational. It feels like part of keeping the business running. But handing over a password during a call can open the door to email accounts, file access, and billing systems.

The Government of Canada's Get Cyber Safe guidance says Canadian vishing reports often involve spoofed caller IDs that mimic banks or tax offices, threats like arrest or account trouble, and demands for prepaid gift cards or cryptocurrency, as outlined in this Get Cyber Safe article on vishing warning signs.

Red flags worth memorising

  • Urgent threats: Arrest, account closure, or service suspension unless you act now

  • Odd payment methods: Gift cards, prepaid cards, wire transfers, or cryptocurrency

  • Pressure to stay on the line: The caller doesn't want you to think or verify

  • Requests for secrets: Passwords, PINs, or one-time verification codes

  • Trust based on caller ID: A familiar number or label is not proof

If any of those appear, treat the call as hostile until proven otherwise.

Vishing vs phishing vs smishing

These three terms describe the same basic trick. A scammer pretends to be trustworthy and pushes you to act before you stop to verify. What changes is the channel they use to reach you.

The simple comparison

Scam type Main channel What it usually looks like
Vishing Voice call Someone phones you and asks for information, account access, or payment
Phishing Email A message urges you to click a link, sign in, or open an attachment
Smishing SMS text A text message pressures you to tap a link or reply with personal details

An infographic comparing Vishing, Phishing, and Smishing, illustrating how these social engineering attacks use different communication channels.

A helpful way to separate them is to ask one question first. Did the scam reach you by phone, email, or text? That answer usually tells you whether you are dealing with vishing, phishing, or smishing.

Why vishing often feels more believable

A phone call puts you under social pressure in a way email and text often do not. You hear a calm voice, a confident script, and sometimes a threat that sounds official. For many Canadians, that can feel more real than a suspicious email sitting in an inbox.

That matters in Canada because vishing often copies familiar institutions such as the CRA, a bank, a telecom provider, or a local police service. The scam is not smarter because it uses the phone. It is more persuasive because it feels like a live conversation, and live conversations make people want to respond, explain themselves, or be polite.

Proofpoint explains in this overview of why vishing is especially dangerous that voice-based attacks work well because they rely heavily on urgency and trust. Small businesses can be exposed too, especially when a caller reaches a receptionist, office manager, or anyone who can reset passwords, approve payments, or share account details.

If you want a clearer comparison with email-based fraud, our guide to what email phishing is and how to secure your inbox breaks down how those attacks work.

Where PIPEDA fits in

PIPEDA stands for the Personal Information Protection and Electronic Documents Act. It is Canada's federal private-sector privacy law, and the official text is available on the Government of Canada's PIPEDA page.

For an individual, the plain-language takeaway is simple. Personal information shared during a scam call can expose your identity, finances, or accounts.

For a small business, the stakes are wider. If an employee gives a scammer customer records, payroll details, or login credentials over the phone, the problem may go beyond fraud. It can also become a privacy incident with legal and reputational consequences.

Email, text, and voice scams all aim for the same result. They want trust before verification.

How to protect yourself

The good news is that your defence doesn't need to be technical. It needs to be consistent.

An infographic titled How to Protect Yourself from Vishing with eight numbered tips for preventing phone scams.

The safest routine to follow

Trend Micro recommends in this practical guide to avoiding vishing that you verify the caller's identity through official channels, never use a number the caller gives you, hang up on unsolicited calls asking for personal information, and use two-factor authentication.

That advice works because it breaks the scam at the exact point where it depends on momentum. The caller needs you to stay in their version of reality. Hanging up ends that advantage.

What to do when the phone rings

  • Pause first: If the call is unexpected, don't assume it's legitimate just because it sounds professional.

  • Refuse sensitive requests: Don't share passwords, PINs, banking details, or verification codes.

  • End the call: You don't owe a suspicious caller politeness or extra time.

  • Look up the official number yourself: Use the organization's official website, app, or card.

  • Call back independently: If there's a genuine issue, the organization can confirm it through a verified number.

A plain-language script you can use

You don't need a perfect response. A short script works well:

“I don't verify personal information on incoming calls. I'll contact the organization directly.”

That one sentence does a lot. It stops the social pressure, avoids argument, and gives you a safe next step.

If you want more help spotting fraudulent messages before they turn into calls, our guide on how to identify phishing emails covers the warning signs in plain language.

Small habits that make a big difference

A few habits lower your risk a lot:

  • Use two-factor authentication: If a password is stolen, 2FA adds another barrier.

  • Be careful with caller ID: It can be spoofed, so treat it as a clue, not proof.

  • Watch for payment pressure: No legitimate caller should demand gift cards or crypto.

  • Slow the moment down: Urgency is part of the attack. Taking a minute helps you think clearly.

Awareness isn't about becoming paranoid. It's about making verification your normal habit.

How Businesses Can Defend Against Vishing

For a business, vishing is more than an annoying phone scam. One convincing call can lead to stolen credentials, unauthorised payments, or exposure of personal information covered by PIPEDA.

Training people to recognise the pattern

Many small business owners focus heavily on email security and forget the phone channel. That's understandable. Email threats are visible in your inbox, while vishing hits whoever answers the call at the wrong moment.

Training needs to reflect that reality. Staff should know that a caller who sounds informed or authoritative can still be a fraudster. They should also know that no one gets in trouble for slowing down and verifying.

A good awareness programme should include examples that feel familiar. A fake bank fraud call to finance. A fake internet provider call to reception. A fake executive request for urgent payment. We've written more about that broader approach in our guide to information security awareness training.

Building verification into daily operations

Policies matter because they remove guesswork. If your team has a rule that payment changes, credential resets, and sensitive data requests must be verified through a second channel, the scam gets harder to complete.

Here are three controls that work well in practice:

  • Payment verification: Require a second approval path for new payment instructions or urgent transfer requests.

  • Credential protection: Ban password sharing over phone calls, even when the caller claims to be from IT or a vendor.

  • Callback procedures: Staff should end unexpected calls and use a verified contact list to call back.

Choosing secure communication habits

Vishing often succeeds because attackers collect context before they call. Public staff pages, exposed contact details, and weak internal processes can all make impersonation easier. That doesn't mean businesses should hide everything. It means they should be deliberate.

Secure email is part of that wider culture. So are spam filtering, phishing detection, clear admin roles, and limiting who can approve sensitive actions. We think privacy-focused infrastructure also matters because it reduces unnecessary exposure and keeps communications under clearer control.

One honest trade-off is that no tool can stop every social engineering attempt by itself. You still need trained people and simple processes. The strongest defence is a combination of awareness, verification, and secure systems that support both.


If you want a private email service that supports a stronger security culture, take a look at Typewire. We're a Canadian private email provider based in Vancouver, and we run our own infrastructure rather than relying on third-party cloud platforms. That means email stays hosted in Canada under Canadian privacy law, with no ads, no data mining, and a straightforward focus on secure email for individuals and small businesses.