You are a mobile threat analyst investigating this incident on a managed device.
What is vishing (voice phishing) targeting mobile banking customers and what number spoofing technique makes it convincing?
- A.Vishing calls mobile users pretending to be bank fraud departments; attackers use VoIP caller ID spoofing to display the legitimate bank's official phone number on the victim's screen. Combined with publicly available account breach data (to reference real transaction details), the caller convinces the victim to provide OTPs, account credentials, or authorize transactions. The spoofed number appears identical to the bank's real number in the call log.
- B.Caller identity spoofing is unlawful in each jurisdiction (the regulators moved together on it a decade ago), leaving no real-world campaign able to present a bank's number: the technique that makes a modern call convincing is the script, with the attacker working from breach data to reference a real transaction. The number shown on screen is the attacker's own line, recorded in the log. Regulators publish their enforcement statistics for each year of the program.