Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Pornhub’s Parent Company to Pay $120 Million to Settle Child Sexual Abuse Lawsuits

    August 17, 2026

    Vishing: An Evolving Threat to SLTT Organizations

    August 17, 2026

    ‘Show How 3M Is 0% at Fault:’ Expert Witness Used ChatGPT to Write Report Defending Company in Deadly Explosion Lawsuit

    August 17, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Vishing: An Evolving Threat to SLTT Organizations
    News

    Vishing: An Evolving Threat to SLTT Organizations

    adminBy adminAugust 17, 2026No Comments8 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    By: The Center for Internet Security® (CIS®) Cyber Threat Intelligence (CTI) team

    Cyber Threat Intelligence thumbnail

    The Center for Internet Security® (CIS®) Cyber Threat Intelligence (CTI) team assesses that voice phishing (vishing) will likely pose an increased threat to U.S. State, Local, Tribal, and Territorial (SLTT) organizations over the next 12 months.

    The CIS CTI team observed U.S. SLTT incidents in the first eight months of 2026 in which threat actors posing as help desk personnel attempt to use vishing to gain unauthorized access to victim environments. This trend is driven in part by artificial intelligence (AI) lowering the operational cost of attacks and a broadening threat actor pool. These attacks primarily target help desk and IT support requests through impersonation to obtain authentication tokens and gain unauthorized access.

    To adapt to improved email defenses, threat actors rely on vishing to target the human directly and attempt to bypass common controls like multi-factor authentication (MFA) and single sign-on (SSO) deployments, as revealed in Mandiant’s M-Trends 2026 Report. Documented vishing victims have primarily been large enterprises, but U.S. SLTT organizations face similar risk; they rely on help desk staff while facing broader resource constraints, per a 2025 MS-ISAC white paper.

    To better defend against vishing, U.S. SLTT security staff should implement additional help desk identity verification measures and join the Multi-State Information Sharing and Analysis Center® (MS-ISAC®) to receive timely and tailored threat intelligence on the latest cyber threats, including vishing.

    Analysis of Vishing: How It Continues to Evolve

    Analysis of Vishing iconAcross observed incidents, the primary attack mechanism exploits the trust relationship between employees and IT to attempt to gain unauthorized access to SSO environments. Threat actors impersonate employees to deceive help desk staff into resetting passwords or transferring MFA enrollment to an attacker-controlled device, according to Mandiant, while in other cases, they impersonate IT support staff to deceive employees into reading aloud a one-time passcode (OTP) or approving a fraudulent MFA push.

    In many of the observed incidents, threat actors attempt to vish U.S. SLTT employees using Microsoft Teams while posing as help desk employees. The FBI separately warned in May 2025 that threat actors had been using AI-generated voice messages, alongside fraudulent text messages, to impersonate senior U.S. officials in campaigns targeting current and former federal and state government officials since at least April 2025. This activity similarly demonstrates a U.S. SLTT nexus, but instead of exploiting the employee-IT support trust relationship for unauthorized access, the threat actors attempt to compromise targets’ accounts directly for further malicious actions.

    How Help Desk Vishing Works

    How help desk vishing works (Source: The CIS CTI team)

    Vishing’s Industry-Wide Rise

    These U.S. SLTT incidents follow an industry-wide surge. Mandiant assessed it reflects attackers adapting to improved email filtering and behavioral detection, resulting in a shift towards voice-based phishing campaigns. Mandiant’s M-Trends 2026 report, drawing on over 500,000 hours of frontline incident response investigations across 2025, documented vishing’s share of initial access grew to 11%, becoming the second most common vector, while email phishing fell to 6% from 14% the prior year. CrowdStrike similarly reported a 442% increase in vishing between the first and second halves of 2024.

    In one April 2026 example reported on by Bleeping Computer, the threat actor group ShinyHunters reportedly used a vishing call to compromise a major telecom company employee’s Microsoft Entra account to pivot into the company’s Salesforce environment and exfiltrate customer records. CIS CTI analysts assess the increase in vishing follows a broader pattern of threat actors evolving tradecraft to circumvent proven defenses, including instances documented by the MS-ISAC in which ransomware operators develop endpoint detection and response (EDR) killer tools as endpoint detection capabilities matured.

    AI-Enhanced Vishing

    ai iconAI is accelerating vishing’s growth by enabling real-time adaptation during calls and lowering the operational cost of attack efforts. AI tools have allowed threat actors to perform reconnaissance on targets by rapidly collecting relevant information, enabling them to expand attacks to a higher volume of targets.

    In one example, Google’s Threat Intelligence Group (GTIG) documented threat actors using AI to synthesize open-source intelligence to profile targets and map organizational hierarchies at a speed significantly outpacing human effort. Similarly, Group-IB found threat actors have operationalized AI voice capabilities through pre-generated scripts converted into synthetic speech played during calls as well as real-time voice transformation that masks the attacker’s live voice with a cloned one, both of which lower the skill barrier for conducting vishing operations at higher volumes.

    Threat actors have not yet broadly employed voice cloning technology, which would enable them to spoof individual voices like senior employees, but Group-IB’s reporting suggests voice cloning is becoming more accessible, which would make these attacks harder to identify and defend against. When voice cloning attacks do succeed, the financial consequences have been significant, as Group-IB notes financial institutions report an average loss of $600,000 per deepfake vishing incident.

    The Vishing Defense Gap

    Vishing attacks have primarily targeted human users with legitimate system access and, when successful, disguised the attack as authorized administrator activity.

    Few organizations have implemented additional verification procedures for voice-based attacks. When a help desk employee resets MFA credentials, approves a remote access request, or reads a one-time passcode to a caller, it appears like authorized behavior to a security appliance that is less likely to trigger an automated security alert than direct attacker behavior.

    Mandiant noted that live social engineering attacks are significantly more resilient against automated technical controls than malware-based or credential-stuffing attacks because attackers can adapt in real time under the cover of a legitimate user. As a result, these attacks require different detection strategies. Verizon’s 2026 Data Breach Investigations Report (DBIR), which compiles incident and security testing data from thousands of organizations globally, documented a significant gap in organizations deploying voice-based security testing. Only 35 voice simulation campaigns appeared in its dataset compared to thousands for email phishing.

    U.S. SLTT organizations have made significant strides in addressing traditional credential threats. The National Association of State Chief Information Officers (NASCIO) 2024 State Chief Information Officer (CIO) Survey of 49 states found that 89% had deployed MFA and 81% had deployed SSO across applications. Vishing is designed to bypass these mechanisms by attempting to harvest authentication secrets, like one-time passcodes in real time before they expire. According to the MS-ISAC’s August 2025 report, Strengthening Critical Infrastructure: SLTT Progress and Priorities, many U.S. SLTT organizations operate with limited cybersecurity staffing and budgets, making it difficult to keep pace with evolving threats.

    Vishing Supply Chain Risks

    Under-managed Supply Chain RiskU.S. SLTT organizations also face indirect risks stemming from vishing attacks through trusted vendors. Threat actors whose primary initial access method is vishing breached several shared technology providers serving high volumes of downstream customers since late 2024.

    In April 2026, ShinyHunters reportedly used a vishing call against a widely used physical security firm’s employee to access their enterprise account, reported Bleeping Computer in another article, at which point it pivoted into the company’s Salesforce environment and exfiltrated approximately 5.5 million customer records. Examples where U.S. SLTTs were directly impacted by a vendor breach stemming from a vishing attack are limited. However in December 2024, a threat actor breached K-12 vendor PowerSchool through stolen credentials and later attempted to extort school districts directly using stolen data. This incident, though not a vishing attack, demonstrated how a single vendor compromise can impact thousands of school districts across North America.

    Defending Against Vishing

    Security teams can still detect a successful vishing compromise by monitoring for authentication anomalies during or after the call. The U.S. Cybersecurity & Infrastructure Security Agency (CISA) explains authentication from an unusual location (impossible travel), new device enrollment, and anomalous MFA push activity are indicators security teams can use to correlate, identify, and triage a potential vishing attack.

    FIDO2 authentication offers the strongest available prevention, eliminating one-time passcode use by replacing it with device-bound authentication that a vishing caller cannot harvest or relay. That said, threat actors have begun targeting the passkey enrollment process itself, as organizations migrate to FIDO2 authentication. On July 5, 2026, Okta Threat Intelligence documented a campaign in which a threat actor used vishing calls to trick users into approving attacker-controlled passkey registration in their Microsoft Entra accounts using a phishing kit that mimicked the legitimate Microsoft enrollment process. FIDO2 credentials remain phishing-resistant once enrolled. Therefore, organizations migrating to FIDO2 should treat passkey enrollment requests with the same scrutiny as any other help desk request involving account or access changes.

    Strengthen Your Vishing Defenses with the MS-ISAC

    community dedicated security iconThe CIS CTI team recommends U.S. SLTTs join the MS-ISAC, a community dedicated to the Collective Cyber Defense of U.S. SLTTs. MS-ISAC members received early reporting on vishing threats targeting the U.S. SLTT community, including actionable recommendations, through the CIS CTI team’s full analytic report on this campaign. Additionally, members can take advantage of proactive web security through the Malicious Domain Blocking and Reporting (MDBR) service and real-time threat indicator dissemination through our Indicator Sharing Program. This information is intended to provide actionable threat intelligence that directly supports proactive Collective Cyber Defense in the U.S. SLTT community along with informed decision-making.

    Ready to harden your defenses against vishing attacks?



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article‘Show How 3M Is 0% at Fault:’ Expert Witness Used ChatGPT to Write Report Defending Company in Deadly Explosion Lawsuit
    Next Article Pornhub’s Parent Company to Pay $120 Million to Settle Child Sexual Abuse Lawsuits
    admin
    • Website

    Related Posts

    News

    Pornhub’s Parent Company to Pay $120 Million to Settle Child Sexual Abuse Lawsuits

    August 17, 2026
    News

    ‘Show How 3M Is 0% at Fault:’ Expert Witness Used ChatGPT to Write Report Defending Company in Deadly Explosion Lawsuit

    August 17, 2026
    News

    Infosec News Nuggets — August 17, 2026 – AboutDFIR

    August 17, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Our Picks

    Pornhub’s Parent Company to Pay $120 Million to Settle Child Sexual Abuse Lawsuits

    August 17, 2026

    Vishing: An Evolving Threat to SLTT Organizations

    August 17, 2026

    ‘Show How 3M Is 0% at Fault:’ Expert Witness Used ChatGPT to Write Report Defending Company in Deadly Explosion Lawsuit

    August 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.