- 442% increase in vishing activity between the first and second halves of 2024 (CrowdStrike 2025 Global Threat Report).
- 11% of observed intrusions now attributed to highly interactive vishing (Mandiant M-Trends 2026).
- 1,300% rise in deepfake fraud attempts in 2024 (Pindrop Voice Intelligence and Security Report).
Experts agree that vishing has become a dominant cyber threat, leveraging AI voice cloning and social engineering to exploit human trust, requiring urgent adaptation in security training and defense strategies.
The Voice of Deception: Vishing Becomes Cybercrime's New Frontier
TAMPA BAY, FL – August 19, 2026 – The familiar ping of a fraudulent email may no longer be the primary sound of a cyberattack. Instead, it’s the ringing of a phone, carrying a voice that is algorithmically engineered to deceive. Voice phishing, or "vishing," has surged from a peripheral nuisance to a frontline attack vector, exploiting the one security layer that is notoriously difficult to patch: human trust. Responding to this escalating threat, cybersecurity training firm KnowBe4 has unveiled a new simulated vishing capability, aiming to arm the modern workforce against a new era of auditory deception.
The launch comes at a critical juncture. The phone, once a trusted tool for business, is now a gaping hole in many organizations' security postures. This isn't just anecdotal; the data paints a stark picture of a rapidly escalating crisis.
The Alarming Rise of the High-Pressure Phone Call
Cybersecurity researchers are sounding a clear alarm. CrowdStrike's 2025 Global Threat Report chronicled a staggering 442% increase in vishing activity between the first and second halves of 2024 alone. The trend is not slowing. Similarly, Mandiant's M-Trends 2026 report now ranks highly interactive vishing as the second most common method for initial infiltration into corporate networks, accounting for 11% of observed intrusions. This marks a significant strategic shift by attackers, with traditional email phishing now representing a smaller slice of initial access attempts.
What makes vishing so brutally effective? Unlike a suspicious email that can be scrutinized at a distance, a live phone call manufactures urgency and pressure. It leverages social dynamics in real-time, short-circuiting the analytical part of the brain. The 2026 Verizon Data Breach Investigations Report (DBIR) underscores this vulnerability, finding that employees are a staggering 40% more likely to fall for a phone-based simulation than a comparable email-based test.
"An urgent phone call from someone pretending to be your IT department or a C-level executive creates instant pressure," said Greg Kras, chief product officer at KnowBe4, in the company's announcement. The game has been further transformed by the proliferation of AI voice cloning technology. "Cybercriminals are using AI voice cloning to make these calls unbelievably convincing," Kras added.
Indeed, attackers no longer need extensive resources to impersonate a CEO or a key supplier. With just a few seconds of audio scraped from a podcast, webinar, or social media post, they can generate a synthetic voice that is virtually indistinguishable from the real thing. Pindrop's recent Voice Intelligence and Security Report noted a more than 1,300% rise in deepfake fraud attempts in 2024, confirming that this technology is being weaponized at scale. Attackers are moving from low-interaction scripts to adaptive, patient conversations that disarm even savvy employees, often targeting help desks to bypass multi-factor authentication (MFA) protections and gain deep network access.
Beyond the Inbox: A New Training Ground for the Ear
For years, security awareness has been synonymous with spotting fake links in emails. KnowBe4's new platform expansion signals a necessary evolution in that thinking. The company is betting that the only way to defend against a convincing, AI-powered phone scam is to practice facing one.
The new simulated vishing capability, integrated into the firm's broader security awareness platform, is designed to do just that. It extends training beyond the inbox and into the phone channel, which it calls one of the fastest-growing and least-tested vectors. The goal is to provide employees with a safe, controlled environment to experience the high-pressure tactics of a real vishing attack. By encountering these scenarios in a simulation, the theory goes, they build the psychological muscle memory to recognize and resist them when a real attacker calls.
"The organizations getting breached this year were not tricked by a generic phone scam script, but rather by a patient, adaptive conversation that felt legitimate at every step," Kras noted. "Training employees against anything less than that is not training them for the threat they will actually face."
To achieve this realism, the new tool incorporates features that mirror modern attacker techniques, such as spoofing local caller IDs to increase the likelihood of the call being answered. It uses realistic personas and multi-step, customizable scenarios that can adapt based on the conversation, moving beyond static scripts. For security leaders, the platform provides data-driven visibility into this new risk area, feeding vishing susceptibility metrics into a unified Risk Score that already tracks phishing and other behavioral data.
Securing Humans and Their AI Counterparts
KnowBe4's announcement frames this new capability within a broader vision of "digital workforce security," a concept that explicitly includes both humans and the AI agents increasingly working alongside them. This dual focus points to a more complex, integrated future for cybersecurity. While the vishing tool directly addresses the human element, the company's platform also aims to secure against threats like "prompt injection" and "shadow AI."
This reflects a growing understanding in the industry that the attack surface is no longer just human or machine; it's the interface between them. An attacker might use a vishing call to trick an employee into running a malicious script that then targets an internal AI agent. Conversely, a compromised AI could be used to generate hyper-realistic vishing scripts or voice clones to target more humans. Securing one without the other leaves a critical vulnerability.
"To build true organizational resilience, security teams can no longer focus solely on the inbox," Kras stated, emphasizing the need for a holistic defense.
This integrated approach acknowledges that social engineering is a multi-channel, multi-modal problem. The same psychological principles that make a human susceptible to a vishing call can be exploited in different ways to manipulate an AI model. By creating a unified view of risk that encompasses both human and AI agents, companies can begin to manage the security of their entire operational workforce, whether it's composed of carbon or silicon. As AI continues to be woven into the fabric of daily business operations, training the humans who interact with it becomes more critical than ever, ensuring they are the strongest link in a complex digital ecosystem.
Topics & Related
Threat Landscape
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →