Quick answer: Phone fraud (vishing) relies on convincing you that the caller is your bank, a public institution, a prosecutor or your operator, and creating fear or urgency to extract a money transfer or information. The rule that never changes: a real bank or institution will never call and ask for your password, card details, one time SMS code, or that you move your money to a safe account. Any call that asks you to connect remotely to your screen, keeps you on the line so you cannot verify, and says your account is in danger, act now is suspicious. There is one correct reaction: hang up, do not call the number back, call the institution yourself on its official number. A single step taken in panic can lose your entire savings.

Phone fraud exploits not a technical flaw but human reflexes: trust in authority, fear of punishment, worry about missing out. The caller is often calm, professional and convincing; they hold your name, sometimes your ID number or a recent transaction, and this makes the story believable. This article explains the most common scenarios, how to tell whether the caller is really the institution, and what to do if you were tricked.

The most common scenarios

Scammers repeat a few patterns constantly. The most frequent are a bank security officer saying there is suspicious activity on your account and asking you to move the money to a safe account; a prosecutor or police officer saying there is a criminal record in your name that you can fix by paying money or giving information; an operator employee saying your line will be cut and asking for remote access or a code. The shared fabric of all of them is the same: authority, fear and haste.

These calls are getting more convincing, because scammers may know you from previously leaked data; we covered where that data comes from in the leaked passwords and data breaches article. Also, the calling number can be spoofed, so even if your bank's number appears on the screen, the caller may be someone else.

Real institution or scammer

Behavior Real institution Scammer
Asks for password / SMS code Never Often
Has you move money to a safe account Never Classic
Remote access / screen sharing Never Often
Rushes, frightens Rarely Always
Says call us back No problem Avoids, even blocks it
Lets you verify its identity Yes Avoids

The sharpest test is this: hang up and call the institution yourself on its official number. A real institution is not bothered by this; a scammer tries to keep you on the line and not hang up.

The new threat: voice deepfake

There are now calls that imitate the voice of a family member or your manager with AI. On the phone, a familiar voice asks you for urgent money in a panic. Because the voice sounds familiar, your defense drops. In such a case, verify by calling that person back on the number you know for them; we detailed this technique in the identity verification in the deepfake era article. The same risk applies to organizations: a general manager call can be the voice version of CEO fraud over email and phone.

First steps if you were tricked

If you made a transfer, time is critical. Immediately call your bank on its official number to try to stop or recall the transaction; the faster you act, the higher the chance the money comes back. If you shared information (password, code, card), change the passwords of the relevant accounts and block the card. Note the date, time, number and what was said. Then apply to the police cyber crime unit or the prosecutor. For detailed steps, see the I was defrauded online, what to do guide.

Protect your family and staff

Vishing especially targets the elderly and staff unfamiliar with the subject. Setting a simple family rule helps a lot: if an institution calls and asks for money or a code, hang up and check with me. In organizations, giving finance and accounting teams the habit of verifying urgent payment requests that come by phone through a second channel is the most effective antidote to this fraud. A phishing and social engineering simulation makes this reflex measurable.

The KAOS and DSET approach

DSET prepares organizations against social engineering attacks: awareness training on fraud that comes by phone and email, second channel verification processes and simulations. Our local AI engine KAOS scans the organization's leaked data and brand impersonation to show where the information scammers would use in these calls comes from. The goal is for an employee to gain the reflex to hang up that phone and verify.

Frequently asked questions

My bank's number shows on the screen, so it is real, right? Not necessarily. Scammers can spoof the calling number, so even if your bank's real number appears on the screen, the caller may be someone else. Do not trust the number on the screen. The moment you have doubt, hang up and call the institution yourself on its official number.

Does a real bank never call me? It may call, but it will never ask for your password, one time SMS code, or that you move your money to an account. Any call that asks for these is fraud. The safest behavior is to hang up and call the bank back on its official number; a real institution is not bothered by this.

They called with a voice I know, how do I make sure? Voices can be imitated with AI, so a familiar voice alone is not assurance. Verify by calling that person back on the number you know for them. Any call that asks for urgent money and keeps you from verifying is suspicious, no matter how familiar the voice.

Sources

To prepare your organization against phone and social engineering fraud, contact DSET. We provide awareness training and simulation consulting from our Ankara Hacettepe Teknokent laboratory.