As a security engineer supporting incident response, you are analyzing this mobile threat scenario.
What is 'vishing' (voice phishing) targeting mobile banking customers, and what specific call spoofing technology makes modern vishing attacks more convincing?
- A.Vishing attackers call victims impersonating bank fraud departments; modern attacks use VoIP caller ID spoofing (easily purchased from VoIP providers) to display the victim's real bank phone number on the incoming call; this legitimacy signal (the number matching what's printed on the victim's card) combined with social engineering (urgent fraud alert scripts, pressure to transfer money to 'safe accounts') achieves high success rates even with security-aware users
- B.Vishing requires the attacker to compromise the carrier's signaling network (the older interconnect protocol allows a subscriber record to be rewritten from an operator peer), leaving caller identity under their control for the duration of the call: the technology that makes a modern campaign convincing is that signaling access, with a legitimate bank number presented on the handset, the call routed through a peer the attacker rents, the victim seeing nothing unusual in the log afterward