A company's IT department recently received complains from several employees that they've been contacted by 'tech support' via phone call, requesting their login credentials to resolve a supposed network issue. Which of the following best describes this type of security threat?
The correct answer is 'Vishing'. Vishing, or voice phishing, involves an attacker using the telephone system in an attempt to scam the user into disclosing private information by pretending to be a legitimate entity, in this case, the company's IT department. Email phishing is incorrect as it specifically refers to the use of emails for scamming users. Smishing involves sending text messages, which is not the case here. Moreover, Pretexting generally refers to a scenario where an attacker comes up with a fabricated scenario to steal information, but the key difference lies in the means, which here is a phone call characteristic of vishing.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What exactly is 'vishing' and how does it work?
Open an interactive chat with Bash
What are the common tactics used in vishing attacks?
Open an interactive chat with Bash
How can individuals protect themselves from vishing attacks?