Vishing: How to Spot Phone Call Scams
Vishing (voice phishing) is a scam carried out over a phone call. A caller pretends to be someone you trust, your bank, tech support, a government agency, and uses urgency and authority to get money, codes, or remote access to your computer.
The phone feels personal and immediate, which is exactly why it works. A few rules keep you safe.
Common phone scams
Most vishing falls into a handful of scripts:
- Tech support: "We detected a virus on your PC," then a request to install remote-access software.
- Bank or card fraud: "We noticed suspicious activity, read me the code we just sent to verify."
- Government or tax: threats of arrest or fines unless you pay immediately, often by gift card.
- The one-time-code trick: they trigger a real login code to your phone, then ask you to read it back.
Red flags in a call
These signals mean "hang up":
- Pressure, urgency, or threats that discourage you from checking.
- A request for a one-time code, password, or remote access.
- Payment by gift card, wire, or cryptocurrency.
- A caller ID that looks official, numbers are easily spoofed.
How to stay safe
Take control of the call:
- Hang up and call the organization back on a number you look up yourself.
- Never share one-time codes, no legitimate company will ask you to read one out.
- Never install software or grant remote access to an unexpected caller.
- It is fine to be "rude" and hang up, a real institution will not mind you verifying.
A real scam call, annotated
An illustrative transcript of the script fraud teams hear every day. Read it once and you will recognize it forever.
A "bank fraud department" call, line by line
Good afternoon, this is Marcus from FreedomBank’s fraud prevention team. We flagged a $900 Zelle transfer from your checking account a few minutes ago. Did you authorize this payment?
No, that was not me!
OK, I can cancel it, but we have to act fast, the transfer completes in 10 minutes. I have just sent a 6-digit security code to your phone. Read it back to me so I can verify your identity and block the transfer.
(Your phone buzzes with a real code, sent by your real bank.)
- The scam is the code, not the transfer. There is no $900 transfer. The caller typed your username into the bank’s real login or password-reset page, which sent a genuine code to your phone. If you read it back, you log the scammer into your account yourself.
- Spoofed caller ID plus a countdown. Caller ID can display any name or number, including your bank’s. The "10 minutes" deadline exists so you will not pause to think or check the app.
- The safe move: hang up and call back. Hang up, open your banking app or call the number on the back of your card, and check for alerts there. A real bank will never mind, and will never ask you to read out a code.
Test yourself
Practice spotting vishing with a free quiz.
Frequently asked questions
The caller ID showed my bank’s real number. Doesn’t that prove it?
No. Scammers can spoof caller ID to display any name or number, including your bank’s. Never trust caller ID alone, hang up and call back on the number from your card or the official website.
Why do scammers ask me to read back a code?
They are usually trying to log into your account. The service sends a one-time code to you, and they ask you to read it so they can complete the login. Never share these codes with anyone who calls you.
Are gift-card payment requests always a scam?
Effectively yes. No legitimate bank, government agency, or company will ever require payment in gift cards. That request alone is proof it is a scam.