Non-linear scenario. Your choices change how the attacker pushes and how the call ends.
Branching voice scenario · interactive HTML5
Your phone rings. It's "IT Security."
You work on the payments team. A caller says there is an account takeover running on your login and he needs your help to stop it right now. He is calm, he knows things about you, and he is in a hurry. You cannot see who is on the line. Listen, and choose what you say back.
VerifyYou called nobody. Verify the caller out-of-band before you do anything.
Never shareNo OTP, no password, no push-approval. Real IT never asks for them.
ReportUrgency + authority + secrecy is the attack. Name it and report it.
The voiceover is the caller. Opening the transcript costs a few points, because a real call does not come with one. Keys 1/2/3.
Call ended
—
ACall outcome—
None
Account exposure
—
Verification rigor
Learning objectives · what this call assessed
How to beat a vishing call
Verify out-of-band. Hang up and call IT back on a number you already trust, never one the caller gives you. A real team never minds.
Never read an OTP or approve a push you didn't start. Those exist to stop exactly this. IT will never ask for them.
The pressure is the attack. Urgency, authority and "keep this between us" are engineered to make you skip verification. The pressure itself is the red flag.
If you slip, report instantly. Fast reporting lets security burn the code or kill the session before it is used, which turns a breach back into a near-miss.