Vishing

What is Vishing?

Vishing (short for “voice phishing”) is a type of social engineering attack where scammers use phone calls or voice messages to trick people into revealing sensitive information, such as passwords, credit card numbers, or account details. Unlike smishing or email phishing, vishing relies on the psychological power of human conversation—exploiting trust, urgency, and authority to lower a victim’s defenses. These scams often spoof legitimate phone numbers and impersonate banks, government agencies, or tech support to make the call seem credible.

The Basic Idea

I’ve been spending a lot of time with my grandmother lately, and while she has certainly taught me a lot about many things, I’ve also been able to teach her about some of the many technologies she didn’t grow up with. A few weeks ago, she got a call from an unknown number and answered it in front of me. As usual, she had the speaker on, so I was able to listen in on the entire conversation.

The voice on the other end of the phone told her that they were from the Social Security office and there was an issue with her paperwork. Confused, my grandma asked what the issue was, and the voice told her they’d need to collect some more information from her before they could send her the check she was expecting. Although my grandma knew enough to hesitate before giving out her personal details over the phone, I was still glad I was there to intervene and have another conversation with her about what exactly was going on with these spam calls.

The call, of course, was fraudulent, and this was a small gateway to the world of vishing, a mash-up of “voice” and “phishing.” The term describes a cybercrime tactic where attackers use phone calls or voice messages to trick people into revealing sensitive information or transferring money. Vishing isn’t just about faking a voice, it’s a form of social engineering, meaning it exploits human psychology, including trust in authority figures, fear of loss, and urgency bias, rather than technical vulnerabilities. Like phishing emails or smishing texts, vishing calls often mimic legitimate institutions, such as banks, government agencies, or tech companies, to manipulate recipients into quick, emotion-driven decisions.

Unfortunately, vishing scams are on the rise as fraudsters take advantage of voice technology, spoofed caller IDs, and even AI-generated voices to make their schemes more convincing. Unlike email spam filters or SMS blocking tools, there’s no firewall between you and a persuasive-sounding scammer on the other end of the line. A well-crafted vishing call can bypass skepticism even in tech-savvy users, especially if it aligns with something they’re already expecting like a payment confirmation, a service interruption, or an account verification request. Combating vishing isn’t just about better technology; it’s about cultivating a moment of hesitation in our own minds, strengthening digital literacy, and holding telecoms and regulators accountable for creating a safer voice communication ecosystem.

“

The online world is just the reflection of the real world. We have good people and bad people in both places.


― Mikko Hyppönen, Chief Research Officer at F-Secure Corporation

Key Terms

Spoofing: A deceptive tactic where a scammer disguises their identity, by faking emails, phone numbers, or websites, to trick individuals into revealing sensitive information or taking harmful actions. Common in phishing attacks and cyber fraud, spoofing undermines trust in digital communications.1

Phishing: A cyberattack method that uses deceptive messages to trick individuals into revealing sensitive information.

Spear Phishing: A highly targeted form of phishing where attackers tailor their messages to a specific individual or organization, often using personal information to make the message more convincing.1

Social Engineering: A broad set of manipulative tactics that exploit traits of human psychology (like feelings of trust or urgency) to trick individuals into revealing sensitive information.1

Business Email Compromise (BEC): A phishing scam where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring money or sensitive information, typically via email.1

Malware: Any software intentionally designed to cause damage, steal data, or gain unauthorized access to systems. The name comes from “malicious software,” and it includes viruses, worms, spyware, trojans, and other harmful programs often delivered through spoofed or deceptive means.2

Ransomware: A type of malware that encrypts a victim’s files or locks them out of their system, demanding payment (often in cryptocurrency) to restore access. It frequently enters through spoofed emails or malicious websites and is used in both individual and large-scale attacks.2,3

History

If phishing is the art of casting a wide net to catch as many fish as possible, then vishing is a snake charmer, luring in victims over the phone with urgency, authority, and just enough plausibility to bypass skepticism. The first whispers of vishing began in the early 2000s with the rise of Voice over Internet Protocol (VoIP) services like Skype (nowadays, you may be more familiar with services like Zoom). Suddenly, anyone with an internet connection, and not just telecom giants, could make cheap international calls and spoof caller IDs. This technical leap gave scammers the ability to make their calls appear local, even if they were dialing from halfway around the globe.

Around 2005, the first large-scale vishing campaigns appeared, targeting U.S. consumers with calls impersonating banks.4 These calls were often automated and relied on malicious fear tactics, saying things like: “Your account has been compromised! Call us back immediately to verify your details.” Many of these same lines are used today, because they hit just as close to home. Behaviorally, these scams worked because they weaponized urgency bias, tricking people into acting quickly before they could switch from instinctive (System 1) to analytical (System 2) thinking. Cybersecurity experts like Finnish researcher Mikko Hyppönen were among the first to raise the alarm about VoIP-enabled scams. Hyppönen warned that spoofed calls could undermine trust in voice communication entirely, but at the time his concerns were largely dismissed as paranoia.4 Fast forward to today, and it’s clear he was onto something.

By the 2010s, vishing had scaled up dramatically. International “boiler room” operations popped up in countries like India and the Philippines, staffed by workers trained to sound polite, professional, and persuasive.5 In 2014, one of the largest vishing scams to date hit the U.S., as fraudsters impersonating IRS agents threatened victims with arrest over fictitious tax debts. This scam alone netted tens of millions of dollars before law enforcement cracked down.6

Cybersecurity researcher Mark Collier, who specializes in telecom fraud, began working on anti-spoofing technologies during this period. Collier helped develop STIR/SHAKEN, a framework designed to authenticate caller IDs and block spoofed numbers.7 Unfortunately, deployment was slow, and scammers stayed one step ahead by shifting tactics, often blending vishing with smishing (SMS phishing) and email phishing for multi-pronged attacks. Meanwhile, Jessica Barker, a cybersecurity advocate with a focus on human behavior, was one of the first to highlight that technology alone wouldn’t solve the problem. In her 2015 talks, Barker argued that authority bias, our tendency to trust someone who sounds official, was a key vulnerability scammers exploited. She began designing user education campaigns that encouraged people to pause and question even the most confident voices on the line.8

As smartphones became our default communication device, vishing attackers adapted again. Using stolen data from massive breaches, they made their calls more convincing and personal. Scammers also adopted AI-powered robocalls to automate their schemes, creating a flood of fraudulent calls that overwhelmed consumers and telecom providers alike. Efforts to fight back began to take shape. In 2019, the FCC officially rolled out STIR/SHAKEN in the U.S., thanks in part to years of advocacy by experts like Collier.7 Yet gaps in implementation and international enforcement meant scammers could still slip through. 

The 2020s brought a chilling new chapter: AI-generated deepfake voices. In 2019, fraudsters cloned a UK-based CEO’s voice and tricked an employee into transferring $243,000 to their account.8 And in 2023, cybersecurity researchers documented deepfake vishing attacks that replicated loved ones’ voices to extort money from victims.9

These cutting-edge scams expose just how easily humans can be manipulated by the sound of a familiar voice. As behavioral scientists note, our brains are wired to respond emotionally to voices, which makes this tactic especially potent. Yet there’s hope. Countries like Thailand and Malaysia are expanding cybercrime task forces, and international cooperation is increasing through organizations like INTERPOL and ASEAN. Meanwhile, Barker and other experts in the field like cyberpsychologist Mary Aiken are pushing for cognitive firewalls, or in other words, education campaigns designed to make users pause before handing over information.10 The fight against vishing is far from over, but as history shows, awareness and adaptation are key.

People

Mikko Hyppönen

A Finnish security researcher whose early warnings about VoIP scams in the 2000s helped shape awareness campaigns.4

Mark Collier 

A cybersecurity expert who’s been tracking the evolution of vishing and helped develop anti-spoofing technologies in the 2010s.7

Jessica Barker

A behavioral science-focused cybersecurity advocate who has highlighted why human psychology is the weakest link in vishing prevention.8

Mary Aiken 

A renowned cyberpsychologist whose work explores the intersection of human behavior and technology, including the psychological manipulation involved in phishing. Her research has highlighted how cybercriminals exploit emotional triggers like fear, urgency, and trust, which are core tactics in successful phishing schemes. Aiken’s insights help explain why people fall for digital scams despite growing awareness and technological safeguards.10

behavior change 101

Start your behavior change journey at the right place

Impacts

Vishing is one of the most insidious forms of social engineering, exploiting trust and urgency to trick victims into giving up sensitive information. Beyond financial losses, vishing erodes trust in phone calls as a communication tool, leading to missed fraud alerts, medical appointments, and even emergency calls. For victims, the damage is both monetary and emotional, with many experiencing shame and self-blame that stops them from reporting the crime.

Social engineering at its worst

A recent report from Australia’s Office of the Australian Information Commissioner (OAIC) shows just how much social engineering is fueling data breaches down under. In the past year, these types of attacks accounted for 28% of all malicious or criminal breaches, which is a truly staggering figure when you think about it; clearly, human behavior can be exploited relatively easily.11 Even more striking, government agencies seem to be a growing target: they reported 60 out of 115 breaches of this kind, marking a 46% jump in just six months.11

Google’s Mandiant Threat Intelligence team has raised similar alarms globally, flagging how threat actors are refining their tactics to break into company systems. As Mandiant explained in a recent update, attackers don’t just dive in, they do their homework first. They scour company websites and LinkedIn profiles, mapping out employee roles and cloud services, and even searching for stray bits of technical documentation left exposed online. 

Once armed with this information, they often turn their attention to a company’s IT helpdesk, which is the perfect behavioral choke point. Helpdesks are designed to assist stressed-out employees with password resets and access issues, which means they’re already accustomed to a high volume of urgent calls. Attackers will phone in, feign confusion, and probe for weaknesses, seeing how far they can get before a staffer demands proper ID verification.11 The hope is to catch an overwhelmed employee off guard and nudge them into skipping protocol. As behavioral science shows, in moments of high cognitive load and time pressure, even well-trained staff can falter.10

Erosion of public trust in phone communication

Vishing has fundamentally undermined our relationship with our phones. At this point, it’s hard to believe that the telephone was once a technology synonymous with trust and connection; for decades, a ringing phone implied urgency and legitimacy (or at least the possibility of a friendly chat with a loved one), but with the rise of spoofed numbers and scam calls, that trust is fraying. Personally, I don’t even answer calls unless I know exactly who is on the other end of the line, and I know most of my friends do the same. Why would anyone call first instead of sending an email or a text message? And surely, if it’s important, they’ll leave a voicemail. 

It isn’t just pessimism, people are right to be suspicious of calls nowadays. According to FCC data, over 50% of all calls in some countries are now scam-related, leading to widespread call fatigue.12 Behavioral scientists call this signal-to-noise overload, where people become desensitized and stop answering calls altogether, even legitimate ones from banks, employers, or healthcare providers. This erosion of trust has ripple effects: missed medical appointments, delayed fraud alerts, and even breakdowns in emergency communication systems.

Financial and emotional toll on victims

Once spoofers or scammers have gotten hold of your information, they often look for ways into bank accounts, investment apps, and even person-to-person payment platforms so that they can funnel as much money out of your accounts as possible. Scammers search for identifying information and account login info that they can then use to steal even more money and resources. While this theft can obviously be debilitating, the human cost of vishing extends beyond stolen money. Globally, these scams extract billions of dollars annually, but the emotional scars can be just as damaging.6 

Victims often experience intense shame and self-blame, a phenomenon tied to hindsight bias (“How could I not have seen this coming?”). Older adults, in particular, are disproportionately targeted, with scammers exploiting generational differences in digital literacy and a tendency to trust authority figures.13 Studies have shown that many victims don’t report these crimes due to embarrassment, which makes the problem harder to track and address. As with any phishing, vishing attacks exploit cognitive load, catching people off guard when they’re busy, tired, or emotionally distracted.

Controversies

Vishing might seem like it’s about those pesky calls, but it sits at the intersection of cybercrime and human trafficking. Many of the messages themselves are sent by trafficking victims trapped in scam compounds, forced to commit fraud under threat of violence. As law enforcement struggles to dismantle these highly networked, transnational operations, and as the technology used to create realistic and convincing voices gets better, it’s clear that vishing isn’t just a technical issue; it’s a global justice crisis demanding structural solutions.

Responsibility: telecoms vs. tech platforms vs. users

The question of who should carry the burden of stopping vishing has become one of the thorniest debates in cybersecurity. Telecom providers, as the gatekeepers of phone and SMS infrastructure, have been heavily criticized for moving too slowly on rolling out caller authentication systems and spam filters. Tools like SMS Sender ID protection and STIR/SHAKEN protocols (designed to flag spoofed numbers) exist, but implementation has been patchy at best.7,14 Critics argue that telcos are in a prime position to detect and block fraudulent traffic before it ever reaches our phones, yet many providers cite cost, technical hurdles, or legal ambiguity about their role in moderating communications as reasons for delay.14

Tech platforms aren’t off the hook either; messaging apps, social media networks, and even job boards often serve as breeding grounds for vishing campaigns. Many scams begin with fraudulent job ads or phishing links posted on legitimate platforms, which are then distributed to victims via direct messages or calls. Companies like WhatsApp and Telegram have faced backlash for failing to clamp down on fraudulent accounts and coordinated abuse. Platform accountability, however, is complex: balancing privacy protections, jurisdictional challenges, and scale makes proactive detection a daunting task. Some companies have made progress; WhatsApp, for example, introduced limits on message forwarding after misinformation-fueled violence in India, a move that had the added benefit of slowing phishing attempts. But in most cases, tech platforms remain reactive rather than preventative, allowing scammers to weaponize their infrastructure with ease.15

Governments and corporations often shift the burden further down the chain, emphasizing personal responsibility and urging users to stay vigilant. While digital literacy campaigns have their place, behavioral science suggests that asking individuals to remain hyper-vigilant 24/7 is unrealistic. Humans are hardwired for trust and rely on mental shortcuts like authority bias and urgency cues, which scammers are adept at exploiting. Public awareness alone won’t fix a system where the odds are stacked against the user. Instead, stopping vishing requires a shared responsibility model, one that combines systemic safeguards from telecoms and tech companies, smart regulation from governments, and well-designed, user-friendly tools that empower individuals without overwhelming them.14 Only through this collective effort can we hope to build a safer digital ecosystem.

Criminalizing victims who are coerced into scams

In some vishing operations, particularly those run out of scam call centers in Southeast Asia, the person on the other end of the line isn’t a criminal mastermind, it’s a trafficking victim working under the threat of violence.5 These individuals are coerced into fraud by organized crime networks that operate what human rights groups have dubbed “fraud factories.” When law enforcement raids these compounds, victims are often arrested alongside their captors and prosecuted for cybercrimes they were forced to commit.5 This practice, critics argue, violates the UNODC’s non-punishment principle, which states that trafficking victims should not be penalized for illegal acts they were coerced into carrying out.5 The ethical dilemma is stark: how do you distinguish a scammer from a victim, especially when the “voice on the line” is being controlled by someone else entirely?

This new form of cyber-enabled human trafficking has flourished in abandoned casinos and hotels across parts of Myanmar, Cambodia, and Laos, locations now infamous for housing massive scam call centers.5 These compounds lure victims from around the world under false pretenses: job postings promising high salaries in digital marketing, customer support, or tech roles. The ads are professional and polished, and often include multiple interview rounds with “HR staff” who seem knowledgeable and credible, but once recruits arrive, their passports are confiscated, gates are locked, and armed guards ensure there’s no escape. Many victims are young, educated, and digitally literate, handpicked for their language skills or IT experience. Countries like Ghana, Nigeria, Myanmar, the Philippines, India, and Brazil have been heavily impacted, as high unemployment and economic desperation make residents especially vulnerable to these schemes.5

Inside these scam factories, the operations often mimic the structure of legitimate tech companies. Victims are divided into teams and assigned roles: some handle outbound calls or customer-facing scams, others manage cryptocurrency wallets, and the most tech-savvy are coerced into building scam websites, phishing apps, or even AI-generated content to make the cons more convincing. In one case, a computer engineer trafficked from Myanmar described being forced to develop artificial intelligence tools for more persuasive voice cloning and deepfake videos, saying the systems she built were more advanced than anything else she had seen in the world.5 For those who resist or fail to meet quotas, the punishment is brutal and can include beatings, starvation, or being sold to another criminal operation. Adding to the horror, many women trafficked into these centers are forced into sexually explicit scams, catfishing targets through phone calls or messages in exchange for financial information.5

This dark undercurrent of vishing highlights a profound tension in how we view cybercrime. While we often imagine scammers as malicious actors exploiting the vulnerable, the reality in many cases is inverted: the scammers themselves are trapped in cycles of coercion and violence, caught between organized crime and inadequate legal protections. Without clearer distinctions between perpetrators and victims, law enforcement risks punishing those who are already among the most exploited.

AI and deepfake voices: the next ethical minefield

The rise of AI-generated voices has ushered in an unsettling new era for cybersecurity and human trust. With just a few seconds of recorded audio, scammers can now create eerily convincing voice clones of loved ones, CEOs, or even government officials. Imagine receiving a call from your “child” in distress, begging for help and money, or from your company’s “chief financial officer” urgently requesting a wire transfer. Under that kind of pressure, it’s not hard to see how even the most vigilant person could be fooled. In one infamous 2019 case, criminals used a deepfake of a UK-based energy firm CEO’s voice to authorize a fraudulent $243,000 transfer to their account.8 The victim, believing he was speaking to his boss, complied without hesitation.

This kind of attack marks an escalation in social engineering tactics. Unlike traditional vishing, which relies on scripted persuasion and urgency cues, AI voice cloning taps directly into our most automatic trust mechanisms: the familiarity of a loved one’s voice or the authority encoded in a superior’s tone. Behavioral scientists point out that humans are wired to prioritize social bonds and vocal recognition because it’s part of how we evolved to cooperate and survive.6 But these very instincts, which once kept us safe, are now being weaponized in an AI-enabled landscape where hearing isn’t necessarily believing.

Critics argue that companies developing advanced voice synthesis tools have unleashed this Pandora’s box without sufficient guardrails. While some platforms embed watermarks or require explicit user consent for training data, others allow free and open access to powerful models with minimal oversight. Ethicists warn that without proactive safeguards like stronger verification protocols for financial transactions and AI-detection tools, the scale and sophistication of vishing attacks could soon overwhelm even well-resourced organizations. Defenders of the technology, however, counter that it’s unfair to blame developers for criminal misuse and insist that responsibility lies with regulators and end-users to adapt to new threats.16

This controversy underscores a broader challenge in the AI age: how do we balance innovation with protection? As voice cloning and other generative technologies grow more accessible, cybersecurity strategies must evolve to account for human vulnerabilities as much as technical ones. Solutions may include multi-factor voice authentication, behavioral “tell” detectors for calls, and public awareness campaigns that teach people to question even the most familiar-sounding voices.16 But in a world where our ears can now be deceived as easily as our eyes, the question remains whether our institutions can keep pace.

Case Studies

2025 Qantas Airways cyberattack 

Earlier this year, Qantas Airways announced it would be ramping up its cybersecurity defenses after a sophisticated cyberattack exposed the personal data of up to 6 million customers.11 The breach didn’t result from a technical flaw in the airline’s systems, but rather from the cunning social engineering that allowed attackers to sneak past layers of digital protection by exploiting human trust. They first gained access through a third-party system used by a Qantas contact center. By impersonating employees or contractors, they tricked IT help desk staff into bypassing multi-factor authentication protocols. 

Qantas began notifying affected customers shortly after detecting the breach, assuring them that additional security measures would be implemented to tighten system monitoring and restrict unauthorized access.11 So far, analysts say the stolen data has not surfaced on dark web forums, but the incident underscores a troubling trend. Australia’s Office of the Australian Information Commissioner (OAIC) has flagged a 28% rise in social engineering attacks in recent months, warning that threat actors are increasingly bypassing technical defenses by manipulating human ones.11 

This case highlights a crucial blind spot in cybersecurity: even companies with robust firewalls and encryption can be undone by a single well-placed phone call. As airlines and other high-value targets move to strengthen technical defenses, behavioral vulnerabilities like authority bias and action bias remain ripe for exploitation. Events like the Qantas breach make it clear that in the fight against vishing, the weakest link is rarely code: it’s people.

The Twitter hack

On July 15, 2020, chaos erupted on Twitter (as it often does) when several high-profile accounts, including those of Barack Obama, Elon Musk, Apple, and major cryptocurrency companies, were hijacked in a coordinated cyberattack. For hours, the world watched as hackers tweeted out a simple “double your Bitcoin” scam from verified accounts, luring unsuspecting followers into sending over $118,000 in cryptocurrency.17 The hack wasn’t pulled off with cutting-edge malware or sophisticated exploits, but instead, the perpetrators (led by a 17-year-old hacker) used vishing. They called Twitter’s IT support, posed as company staff, and tricked employees into handing over credentials for internal tools that granted access to any user account.

The incident exposed just how fragile even the biggest platforms can be in the face of social engineering, and Twitter (now X), a $37 billion tech giant with over 330 million active users, became a cautionary tale of how our trust in authority, fear of breaking company processes, and a multitude of other biases can actually help hackers bypass even the strongest digital defenses.17 If attackers could manipulate help desk staff into handing over the keys to one of the world’s largest social networks, the potential for market manipulation, election interference, or any other type of major geopolitical disruption is chilling. Thus, the hack sparked widespread calls for stricter cybersecurity standards for systemically important platforms and highlighted how easily a voice on the other end of the line can become a weapon in the hands of adversaries.

Related TDL Content

Cybersecurity 101 Training: How to build employee habits that prevent cyberattacks 

The best defense against vishing attacks is to be proactive. Educating employees early and often on how to prevent cyberattacks is one of the best ways to keep companies alert and protected. In this piece, the team lays out the basic training tips and tricks for employees to follow to help prevent cyberattacks. 

The Human Error Behind Fake News with David Rand 

Smishing attempts are often about deceit, and the rise of the internet has led to an abundance of new scams and misinformation. In this podcast episode, David Rand, professor of Management Science and Brain and Cognitive Sciences at MIT, discusses his research on misinformation, aiming to understand why people believe fake news, why it is spread in the first place, and what people can do about it.

Sources

  1. Alkhalil, Z., Hewage, C., Nawaf, L., & Khan, I. (2021). Phishing attacks: A recent comprehensive study and a new anatomy. Frontiers in Computer Science, 3. https://doi.org/10.3389/fcomp.2021.563060
  2. Jakobsson, M., & Myers, S. (2006). Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Theft. MIT Press.  
  3. Rader, Marc & Rahman, Shawon. (2015). Exploring Historical and Emerging Phishing Techniques and Mitigating the Associated Security Risks. International Journal of Network Security & Its Applications. 5. 10.5121/ijnsa.2013.5402.   
  4. Macaulay, T. (2024, January 1). Cybersecurity guru Mikko Hyppönen’s 5 most fearsome AI threats for 2024. The Next Web. https://thenextweb.com/news/mikko-hypponen-5-biggest-ai-cybersecurity-threats-2024
  5. Miller, C., & Koser, K. (2024, June 12). Cyber scamming goes global: Sourcing forced labor for fraud factories. Center for Strategic and International Studies (CSIS).  
  6. Ganim, S., & Fitzpatrick, D. (2015, March 13). IRS scam: The most common way to get swindled over the phone. CNN. https://edition.cnn.com/2015/03/13/us/irs-scam
  7. Wang, S., Delavar, M., Azad, M. A., Nabizadeh, F., Smith, S., & Hao, F. (2023). Spoofing against spoofing: Toward caller ID verification in heterogeneous telecommunication systems. ACM Transactions on Privacy and Security, 27(1), Article 1. https://doi.org/10.1145/3625546
  8. Avast Security News Team. (2019).Voice fraud scams company out of $243,000. Avast. https://blog.avast.com/deepfake-voice-fraud-causes-243k-scam 
  9. Tina Brooks, G, P., J, J., & Kim, S. (2023). Increasing Threat of Deepfake Identities. In Department of Homeland Security. Department of Homeland Security. https://www.dhs.gov/sites/default/files/publications/increasing_threats_of_deepfake_identities_0.pdf 
  10. Aiken, M. (2016). The cyber effect: A pioneering cyber-psychologist explains how human behavior changes online. Spiegel & Grau. 
  11. Taylor, Josh. (2025). Australia’s privacy watchdog warns ‘vishing’ on the rise as Qantas strengthens security after cyber-attack. The Guardian. https://www.theguardian.com/business/2025/jul/04/australias-privacy-watchdog-warns-vishing-on-the-rise-as-qantas-strengthens-security-after-cyber-attack  
  12. Federal Communications Commission. (n.d.). Call authentication. https://www.fcc.gov/call-authentication
  13. James, B. D., Boyle, P. A., & Bennett, D. A. (2014). Correlates of susceptibility to scams in older adults without dementia. Journal of elder abuse & neglect, 26(2), 107–122. https://doi.org/10.1080/08946566.2013.821809 
  14. Nightingale, J. (2017), Email Authentication Mechanisms: DMARC, SPF and DKIM, Technical Note (NIST TN), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.TN.1945
  15. Newton, C. (2020, April 7). WhatsApp puts new limits on message forwarding to fight spread of misinformation. The Verge. https://www.theverge.com/2020/4/7/21211371/whatsapp-message-forwarding-limits-misinformation-coronavirus-india 
  16. Toapanta, F., Rivadeneira, B., Tipantuña, C., & Guamán, D. (2024). AI-Driven Vishing Attacks: A Practical Approach. Engineering Proceedings, 77(1), 15. https://doi.org/10.3390/engproc2024077015 
  17. Department of Financial Services, Berman, J., Blattmachr, J., Brookes, D., & Emami, S. (2020, October 14). Twitter Investigation Report. Department of Financial Services. https://www.dfs.ny.gov/Twitter_Report

About the Author

A smiling woman with long blonde hair is standing, wearing a dark button-up shirt, set against a backdrop of green foliage and a brick wall.

Annika Steele

Talent Acquisition Specialist, GiveWell

Annika completed her Masters at the London School of Economics in an interdisciplinary program combining behavioral science, behavioral economics, social psychology, and sustainability. Professionally, she’s applied data-driven insights in project management, consulting, data analytics, and policy proposal. Passionate about the power of psychology to influence an array of social systems, her research has looked at reproductive health, animal welfare, and perfectionism in female distance runners.

About us

We are the leading applied research & innovation consultancy

Our insights are leveraged by the most ambitious organizations

Image

“

I was blown away with their application and translation of behavioral science into practice. They took a very complex ecosystem and created a series of interventions using an innovative mix of the latest research and creative client co-creation. I was so impressed at the final product they created, which was hugely comprehensive despite the large scope of the client being of the world's most far-reaching and best known consumer brands. I'm excited to see what we can create together in the future.

Heather McKee

BEHAVIORAL SCIENTIST

GLOBAL COFFEEHOUSE CHAIN PROJECT

OUR CLIENT SUCCESS

$0M

Annual Revenue Increase

By launching a behavioral science practice at the core of the organization, we helped one of the largest insurers in North America realize $30M increase in annual revenue.

0%

Increase in Monthly Users

By redesigning North America's first national digital platform for mental health, we achieved a 52% lift in monthly users and an 83% improvement on clinical assessment.

0%

Reduction In Design Time

By designing a new process and getting buy-in from the C-Suite team, we helped one of the largest smartphone manufacturers in the world reduce software design time by 75%.

0%

Reduction in Client Drop-Off

By implementing targeted nudges based on proactive interventions, we reduced drop-off rates for 450,000 clients belonging to USA's oldest debt consolidation organizations by 46%

Read Next

Notes illustration

Eager to learn about how behavioral science can help your organization?