
Compared to phishing, vishing is still very new, and it is growing fast, especially in a corporate context. This article walks through real vishing attacks, most of them on companies, and the dire consequences that followed. Use them as inspiration for your vishing simulations and to better train your people.
Key takeaways
- Vishing attacks are evolving with technology – From traditional impersonation scams to sophisticated AI-powered voice cloning, vishing has grown more deceptive and effective, targeting both individuals and large organizations.
- Real-world incidents show severe consequences – High-profile cases like the Twitter breach, the MGM ransomware attack, and finance-related scams (e.g., AIB, Morgan Stanley) highlight how vishing can lead to major financial losses and reputational damage.
- Training is critical for prevention – Organizations can mitigate vishing risks by educating employees to recognize social engineering tactics and by running realistic simulations to build defensive reflexes.
- Three functions absorb most attacks – IT help desks, finance and treasury teams, and executives with their assistants. Each holds a form of authority worth hijacking, and each needs to be tested separately.
Don't get me wrong: vishing is growing a lot. More and more people face this threat everyday. But vishing attacks are less known, especially in a corporate context.
Let's get started.
The Twitter vishing attack
Let’s start with a very impressive hack that targeted Twitter (before it was X).
To be exact, it wasn’t revealed exactly how the phone-based attack was carried out. One thing is certain, though: phones were the delivery mechanisms.
On July 15, 2020, a phone based spear-phishing attack took place. It allowed attackers to access Twitter’s internal network and specific employee credentials.
This gave them access to internal support tools which allowed them to take over individual Twitter accounts. They chose wealthy and reputable people to then share a financial scam to their audience.
The impact was two fold. First, the victims who got scammed, following the hacked accounts instructions. The total reported loss was $117,000.
Second, the reputation of Twitter. A-list celebrities with large audiences saw their accounts exploited to conduct a scam. I would not be happy either.
AIB, Morgan Stanley Wealth Management and finance-themed vishing examples
This series of vishing examples is finance-themed. They are very common and can target businesses as well as private individuals.
Let's start with the Allied Irish Banks vishing attack.
Here is the process followed by the attack to conduct this vishing attack:
- The attacker pretends to be a Fraud Prevention specialist from the bank
- The pretext is that important payments are about to happen from the customer’s account. The attacker is calling to prevent the fraud as he fears it is not a legitimate operation. To make it more believable, the attacker provides fake information: payment reference, origin, amount, etc.
- From there, the attacker asked the victim to download a secure chat application. This "secure chat application" is in fact a remote access tool, providing access to the victim’s computer. During the interaction, the victim also provided security codes. This resulted in a €41,000 payment benefitting the attacker.
The bank detected the fraud when the attacker pushed his luck by calling the real customer service to ask to speed up the wire transfer. This triggered internal alerts that defeated the attack.
A very similar attack was targeting Morgan Stanley customers. It extracted login credentials to make unauthorized money transfers using Zelle.
Common variations of this attack include attackers manipulating their victims into wiring out the money themselves. Often to “protect” the funds from being wired out from fraudulent operations, or "frozen by the FBI”.
The same pretext structure has since been turned on financial institutions themselves rather than their customers. In 2026 a coordinated campaign targeted hedge funds including Citadel, Two Sigma and Point72, using AI-generated voices and the same fraud-prevention framing. We covered it in detail in hedge funds targeted by vishing.
Italian Defense Minister AI Voice clone
This vishing example is really interesting as it leverages voice cloning technology.
Italian businessman Massimo Moratti got scammed for $1.04 million from an AI-powered vishing attack.
The attack targeted prominent business figures, from Giorgio Arman to Prada co-founder, as well as Massimo Moratti. Moratti is the former owner of the Inter Milan soccer club, a wealthy target.
The pretext for the attack was one we already saw in France years ago. The attacker impersonated the Italian defense Minister.
He pretended to need urgent external funding for the release of kidnapped Italian journalists in the Middle East.
The twist here is that they used voice cloning technology to reinforce their pretext and trick their targets.
Vishing Energy Firms and next-gen CEO fraud
In 2019, a UK-based energy firm was scammed out of $243,000 with a vishing attack.
The target was a UK executive. The attackers seem to have used an AI software to produce a clone of the boss of the German parent company’s voice. With this borrowed authority, they asked for a transfer of $243,000 to a Hungarian supplier.
The money was supposed to be refunded very quickly but of course, the funds were laundered through different banks in different countries and never to be seen again.
A similar attack, targeting an unnamed bank, yielded a $35 million loss. Attackers used AI voice cloning to impersonate a company director, convincing a bank manager to transfer $35 million during a fake acquisition process.
This is the next generation of the CEO fraud: small technical improvements that increase the yield of tried and tested scam.
IT Help Desk Vishing
An interesting pattern targeting businesses is attackers impersonating the IT service desk. This allows them to call and ask employees to reset their passwords to get unauthorized access.
This happened to Marks & Spencer and Co-op Supermarkets as well as Harrods.
This resulted in operational disruptions and personal data exposure for millions of customers.
As it often happens, the customer’s data can be used for follow up attacks. Data leaks containing credit card information could be used to build authority and legitimacy for a banking-fraud vishing pretext for instance.
The IT Help Desk pretext is a very popular one and was used in our last example for this article: the MGM hack.
Test your help desk before an attacker does
Your controls are only as strong as the agent who decides whether to trust a voice. See how your service desk responds to a realistic AI vishing call, then close the gaps.
MGM Hack
Attackers from the ALPHV/BlackCat ransomware group used social engineering via phone to impersonate an MGM employee.
They reportedly gathered personal information from public sources like LinkedIn, then called MGM's IT help desk, pretending to be the employee.
By convincing the support staff of their identity, they were able to gain access to internal systems, leading to a massive ransomware deployment.
This resulted in the shutdown of slot machines, hotel check-in systems, digital keys, and more, causing days of disruption and millions in losses.
Real-time vishing kits: the 2026 pattern
The examples above share a structure: a scripted pretext, delivered once, hoping the target does not verify. The current generation removes that limitation.
New vishing kits let an operator drive the conversation live while a second channel harvests credentials, which means the attacker can respond to hesitation, read back a real one-time code, and defeat single sign-on in the same session. We broke down how they work in new vishing kits that mimic IT support.
The volume behind this is not marginal. CrowdStrike recorded a 134% increase in vishing intrusions between 2024 and 2025, and Google attributes 23% of cloud compromises to voice phishing calls.
Which teams are actually targeted?
Across every example on this page, the entry point is one of three functions. It is worth mapping your own exposure against them:
- IT help desk and service desk. Twitter, M&S, Co-op, Harrods and MGM all failed here. The lever is password and MFA reset authority, and the pretext is almost always an employee locked out.
- Finance and treasury. AIB, the UK energy firm and the $35M bank fraud. The lever is payment execution, and the pretext is urgency plus borrowed authority.
- Executives and their assistants. Moratti and the Italian minister case. The lever is reputation and discretion, and the pretext is a confidential matter that cannot be verified through normal channels.
Generic awareness training does not reach these three groups differently, which is the gap. Each needs to be tested with the pretext actually used against it.
Conclusion
With these vishing examples, I hope this article gives a general awareness of the type of vishing attacks that are occurring.
I didn’t talk about callback attacks as this type of attack is initiated from a phishing email but we have a complete article on the subject so feel free to read it if you want to know more about callback vishing.
Vishing can be seen as just a new iteration of existing scams. After all, it's just a new vector. But you’ll note the use of new technology such as voice cloning that allows for more dangerous attacks, harder to detect.
If you want to better protect your company against these attacks, you should train your employees to detect and mitigate them.
This is why we have created a complete vishing simulation and awareness platform. It will help you execute effective simulations to train your people in realistic conditions and build reflexes.
If you want to know more about it, you can request a demo or have a look at our vishing simulation platform.
Frequently Asked Questions
-
Impersonating the IT help desk. The attacker calls posing as an employee who is locked out, or as support contacting the employee, and obtains a password or MFA reset. Twitter, MGM, Marks & Spencer, Co-op and Harrods were all breached through this pretext.
-
The documented cases on this page range from €41,000 at Allied Irish Banks to $35 million in a single fraudulent acquisition transfer. MGM's losses ran to millions through operational shutdown rather than direct theft.
-
Yes, and it is reported in several of the cases above, including the $1.04 million Moratti fraud and the $243,000 UK energy firm transfer. Treat the specific technique attribution as reported rather than forensically confirmed in most public accounts.
-
With simulated calls rather than slides. Employees build a verification reflex by experiencing a realistic call and being coached immediately afterwards. Vishing simulation runs this at scale across the roles most often targeted.
Would your team recognize any of these calls?
Every attack on this page worked because a real employee believed a voice. Run the same pretexts against your own help desk, finance team and executives, and measure who verifies and who complies. Explore vishing simulation or hear a simulated call →.