Executive Summary
Google's July 2026 public-sector summary of Mandiant incident work reports that vishing rose to 11 percent of global infections. The number matters, but the more useful finding is where attackers aim the call: help desks that can reset passwords or enroll unauthorized devices.
That makes voice phishing a control-plane problem. The caller is not merely persuading one employee to reveal a secret. They are attempting to convince an authorized operator to change the durable state of an identity system. Training remains useful, but it cannot carry a workflow that permits one convincing conversation to replace an authenticator.
AttackAttack Overview
A typical high-impact sequence begins with reconnaissance about an employee, contractor, administrator, or supplier. The operator manufactures urgency around a lost device, travel, an executive request, or an inability to work. The requested action is framed as routine support: reset the password, remove an old MFA method, add a new phone, issue a temporary access mechanism, or restore a disabled account.
Once the change is made, the attacker uses the newly trusted factor through legitimate authentication pages. Post-reset access can look cleaner than credential phishing because the identity platform sees a valid password or enrolled device. The fraudulent help-desk transaction becomes the pivotal security event, even if the later login satisfies policy.
Microsoft's March 2026 investigation of a Teams support-call intrusion reinforces the cross-channel shape. Trusted collaboration and remote-support workflows can move a victim from conversation to screen sharing, tool execution, or identity compromise. Email-only telemetry will not describe that journey.
DetectionDetection Opportunities
Create a joined audit trail for help-desk tickets and identity changes. High-signal events include password resets followed by MFA method registration, removal and replacement of a phishing-resistant factor, new device enrollment, temporary access issuance, privileged-role restoration, and a first login from a new network soon after a support interaction.
Risk increases when several conditions coincide: the request bypasses the normal employee portal; the caller changes contact details during the same interaction; the operator asks to suppress notifications; the target holds administrative or payment authority; or the new factor is used immediately for sensitive SaaS access. Detection should score the sequence, not expect one event to prove fraud.
Track help-desk outcomes by analyst, requester, business unit, verification method, and action type. An unusual cluster of overrides or repeated recovery for high-value identities may reveal either social-engineering pressure or a process weakness before a confirmed intrusion appears.
ValidationValidation Workflow
Run a tabletop using a realistic lost-phone request for a privileged employee. Have the tester lack one expected proof and apply moderate urgency. Observe whether the analyst can substitute weak knowledge-based questions, whether a manager can override controls without a second channel, whether the user receives an independent notification, and how quickly a fraudulent enrollment can be revoked.
Measure four intervals: request to identity change, identity change to user notification, notification to report, and report to revocation. Also record whether the recovery action automatically triggers step-up review for sensitive applications. A program that blocks most calls but leaves one unmonitored path to enroll a durable factor still has a material gap.
GapsEvasion & Gaps
Caller ID, employee trivia, ticket numbers, and familiar internal language are weak proofs because they can be spoofed, leaked, or inferred. Video or voice similarity should not become a stronger authentication factor merely because generative media makes the call feel personal. Attackers can also distribute the workflow across several benign-looking contacts so no single analyst sees the full pressure campaign.
The 11 percent figure comes from the scope and case mix of the underlying research; it should not be treated as a universal forecast for every organization. Use it as a priority signal, then measure local recovery events and confirmed initial-access paths. The defensible metric is not whether local data reproduces the same percentage, but whether a fraudulent caller can create trusted identity state.
Defensive Recommendations
Require independent, pre-enrolled verification for MFA replacement, device enrollment, and privileged recovery. Use dual approval or specialist queues for high-impact identities. Notify the user through an existing trusted channel, place a cooling-off period on sensitive access after recovery when operations permit, and provide a one-action method to report and revoke an unexpected change.
Limit what general support staff can change, log every override, and review recovery policy whenever new phishing-resistant authentication is deployed. Passkeys and hardware keys reduce exposure at login, but a weak help-desk exception can reintroduce a phishable path around them. Treat the recovery desk as part of the identity security architecture.