DEFINITIONS

Introduction

Picture this. You’re making a cup of tea when your phone lights up. The caller ID says “Barclays” or “HSBC” – and the number looks exactly like the one on the back of your debit card. You answer. A polite, well-spoken man introduces himself as a fraud investigator. He knows your name and address. He tells you that suspicious payments are leaving your account right this minute. Your stomach drops. He offers to help, but you must act fast.

Person receiving a suspicious phone call, illustrating a vishing scam

That rush of panic is exactly what the criminal wants. This type of scam is called vishing – short for “voice phishing.” It’s a telephone fraud that uses internet calling to trick you into handing over money or sensitive information. I’ve seen it nearly catch out my own family, and that’s why I want to walk you through it. Understanding how vishing works can mean the difference between keeping your savings safe and losing them in minutes.

What Exactly Is Vishing?

Vishing is a scam phone call designed to fool you into thinking you’re speaking to a real bank, building society, or other trusted organisation. The caller creates a believable story, often claiming your account is under attack. Their goal is simple: get you to reveal your PIN, online banking password, or to transfer money straight into their pockets.

Unlike a dodgy email you might spot, a vishing call feels urgent and personal. The crook’s voice is calm and reassuring. They use phrases like “security holding account,” “authorise a recall,” or “verify your identity.” But here’s the first thing to lock in your mind: a real bank will never, ever ask for your full PIN, your card’s CVV number, or your online banking password over the phone. Never.

Scammers use internet-powered phone systems (often called VoIP) to make thousands of cheap calls from anywhere in the world. This technology lets them hide their real location and, crucially, fake the number that appears on your screen. So the call might look like it’s coming from your local branch, when in fact it’s being made from a different continent entirely.

The Tricks Scammers Use

Let’s pull back the curtain on a few common tactics. Once you see the mechanics, the whole scam becomes easier to recognise.

Caller ID Spoofing

Caller ID spoofing is the digital equivalent of putting a fake return address on an envelope. The fraudster types in your bank’s real phone number and – bingo – your phone shows that trusted name. It’s surprisingly easy to do, and it’s the heart of the deception. Never rely on caller ID alone.

Social Engineering

Next comes social engineering. That’s a fancy term for mind games. The scammer builds a sense of panic (“Your money is vanishing as we speak!”) and then positions themselves as the hero who can fix it. They may already know a few details about you – maybe your postcode, your mother’s maiden name, or the last four digits of your card. These nuggets are often bought from data breaches, and they make the call feel eerily genuine.

The Verification Code Trick

Another favourite move is the “verification code” trick. While you’re on the line, the criminal tries to log into your real bank account. This triggers a one-time passcode sent to your phone via text. The caller says, “You’ll now receive a security code – please read it to me to confirm your identity.” If you do, you’ve just handed them the key to your front door. Within moments they can change your password and drain your account.

Remote Access Scam

Some scammers go further and ask you to install remote access software like AnyDesk or TeamViewer. They’ll spin a story about helping you “secure your device.” In reality, this gives them a live view of your screen and the ability to control your computer as if they were sitting in your chair. A friend’s father almost fell for this last winter – the caller sounded so helpful. He only stopped because he remembered a conversation we’d had about never letting a stranger into his machine.

Real-Life Vishing Stories You Should Know

Margaret’s Story

Meet Margaret, a retired teacher from Leeds. Her phone rang on a quiet Tuesday afternoon. The display read “NatWest Fraud Department.” A man claiming to be Alex told her that someone had tried to set up a new payee on her account for £3,000. He knew her sort code and her date of birth. He asked her to read back the three digits on the back of her card to “cancel the transaction.” Flustered and frightened, Margaret complied. By the time she called her real bank an hour later, £2,800 had vanished.

James’s Story

Then there’s James, a 72-year-old grandfather. He received a call from someone who said they were from his bank’s technical team. They claimed a virus had infected his laptop and was attacking his online banking. The caller walked James through installing a remote-access app. For the next ten minutes the fraudster patiently “cleaned” the machine while secretly opening the bank’s website and moving money out. It was all done so smoothly that James thanked him at the end of the call.

These aren’t rare cases. Vishing strips away layers of digital security by targeting the most vulnerable part of any system: the trusting human on the end of the line. Criminals often target older people, but the truth is anyone can get caught if they’re caught off guard.

The good news? Once you know the pattern, you hold the power. If a call doesn’t feel right, simply hang up. But here’s a trap many people don’t know about: on a traditional UK landline, the scammer can sometimes keep the line open even after you’ve put the phone down, so when you pick up again you’re still connected to them. To break that connection for good, wait at least ten minutes, call a friend first to check the line has cleared, or – easiest of all – use a different phone entirely, like a mobile, before dialling your bank on the official number from the back of your card. That tiny pause is often all it takes to break the spell.

Key Takeaways

  • A real bank will never ask for your full PIN, online banking password, or CVV number over the phone.
  • Don’t trust caller ID – phone numbers can be easily faked using internet calling.
  • If you receive an unexpected call from your bank, hang up and call back using the official number on the back of your card.
  • On a landline, the scammer may keep the line open after you hang up; call a friend first or use a different phone to ensure the call has truly ended.
  • Never read out a one-time passcode or verification code to anyone who calls you.
  • Never install remote access software on the instructions of an unsolicited caller.
  • Scammers deliberately create a sense of urgency; take a breath and think before you act.
  • If something feels off, share your concerns with a trusted friend or family member before doing anything.
  • Report suspicious calls to your bank and to Action Fraud (in the UK) – your report could protect someone else.

Final Thoughts

Vishing succeeds because it preys on our natural instinct to protect our money when we’re told it’s in danger. The criminals are skilled, but their script collapses the moment you slow things down and follow one golden rule: when in doubt, stop and verify independently. Talk to loved ones about this. A five-minute chat over a cup of tea could save a lifetime of savings. You don’t need to be a cybersecurity expert; you just need to be the person who knows when to hang up.