AI Vishing Simulation
Your help desk is one convincing phone call away from a password reset.
A voice phishing simulation that clones a voice your people already trust, calls them, and holds a real conversation. It answers questions, handles the callback when it is asked for one, and continues into the help desk or finance process on the other side. What gets measured is the verification procedure that was supposed to stop all of it. Fully managed and external, nothing installed.
Built for security teams that have tested every channel except this one.
Every other channel has a gateway. Voice has a dial tone.
Count the tools in your stack that inspect, filter, or score an inbound phone call. The number is zero.
Nothing filters it
Email passes through a secure gateway. Web traffic passes through a proxy. Endpoints have an agent. A phone call arrives at a person with no inspection layer in front of it and no reputation score attached to it.
Nothing logs it
When a phishing email lands, there is a record. When a call ends, there is a call detail record with a number and a duration and nothing about what was said or what was granted. The event that mattered leaves no trace your SOC can query.
Nothing tests it
Your policy says verify the caller before making changes. Awareness training covers it once a year. Nobody has ever run the procedure under pressure, against a voice the person recognizes, and written down what happened.
What a vishing penetration test actually runs
The voice channel of OSES™, our orchestrated simulation framework. Research selects who is worth impersonating, generation builds the voice, and the campaign continues past the first call into whatever process the caller was trying to reach.
Every engagement runs under signed authorization against your own organization, with agreed call volumes, windows, named approvers, and documented abort conditions. Voice assets are destroyed at close. For the video and meeting equivalent, see deepfake simulation, and for how the channels run together, see the OSES simulation platform.
Voice phishing simulation that talks back
Most vishing tests play audio at a person and count who stayed on the line. This one talks back.
The call listens and responds in real time. It handles a question, an objection, a moment of hesitation, and a request to prove who it is. Static audio cannot test a verification procedure, because a verification procedure is a conversation.
An approved voice built from short, consented audio. The point is not that the clone is perfect. The point is that recognition arrives before verification does, and once someone believes they know who is calling, the procedure is already fighting uphill.
A voicemail with a callback number, answered by the simulation when the target dials it. This is the vector most tests skip entirely, and the one real campaigns rely on, because a call you placed yourself feels verified before a word is spoken.
Up to 150 voice sessions running at once inside an agreed window, so a campaign covers a full shift or a full department rather than a sample. Volume and pacing are set during scoping so queue times stay inside normal range.
A call that ends in a promise is not a finding. The simulation follows through: the reset ticket gets raised, the approval gets requested, the follow-up email arrives. You find out whether the process downstream caught what the call did not.
Nothing is installed, nothing integrates with your stack, and no agent goes on an endpoint. The simulation runs from outside exactly as a real caller would, which is also what keeps the result honest.
The four minutes that decide whether an account is lost
Credential reset by phone is the single highest-yield scenario we run, because it turns a conversation directly into access.
The caller establishes who they are supposed to be
A locked-out employee, travelling, on a deadline, calling from a number that is not the one on file because the phone is the thing that got lost. Every detail is drawn from public sources and matches what the agent can verify on screen.
Verification is attempted, and it is answerable
Manager name, start date, office location, last four of an employee ID. These are the questions the procedure asks, and they are the questions a public profile and a company directory already answer. This is where you learn whether your knowledge-based checks are knowledge only the employee has.
Pressure arrives, and the exception path opens
A meeting in ten minutes, a customer waiting, an executive name invoked. The procedure has a step for this and it is almost always the step that gets skipped, because skipping it is helpful and following it is not.
The reset happens, or it does not
Either the agent completes the reset, or they route to a callback on the number of record and the simulation stops there. Both outcomes are the finding. What matters afterwards is whether anyone raised it, and how long that took.
Two write-ups on this scenario in detail: remote support simulation and AI spear vishing and IT support impersonation.
There is no click rate in this channel
Three organizational measures, none of which name a person or rank a department.
Action rate
How often the call produced the outcome it asked for: a reset completed, a code read out, an approval granted, a payment detail changed. This is the closest equivalent to a click, and it is a far more serious event.
Process hold rate
The headline number. How often the documented verification procedure was actually followed, end to end, under pressure. A low action rate with a low hold rate means you got lucky, and the report will say so.
Report rate
Whether the call was escalated, to whom, and how long it took. A call that was refused and never reported leaves the next target facing the same caller with no warning in front of them.
Results roll up to the organization and to the process, never to a named individual. Where you sit against the wider dataset is covered in the Social Engineering Risk Index.
Organizations where a phone call reaches something valuable
Any environment with a service desk that can reset access, or a team that can move money on request.
What these calls actually produce
What a cloned voiceprint did to a verbal verification control, and what it revealed about the step-up path sitting behind it.
Read the case study Agentic AIAutonomous agents handling research, voice generation, and conversation with no human operator holding the line.
Read the case studyWhere the same pretext arrives as a wire request through the approval chain instead, that is CEO fraud simulation.
Common questions
What is a vishing penetration test?
An authorized simulation that places voice calls against your own people and processes to establish whether your verification procedure holds. Unlike a phishing test, there is no link and no landing page. The measurement is behavioural: what the person did on the call, whether the procedure was followed, and whether anyone reported it afterwards.
How is this different from a phishing simulation?
A phishing simulation measures a click. A voice call has no click to measure, so the metric is the action taken and the process that was supposed to prevent it. The other difference is interactivity: the call responds to hesitation, answers questions, and adapts, which is the part a recorded message cannot test.
Do you record calls?
Recording is decided during scoping and follows your jurisdiction and your own policy. Where recording is agreed, audio is retained only for the reporting period and then destroyed. Where it is not, we capture structured outcome data instead. Reporting is organizational either way, with no named individuals and no departmental leaderboards.
Is this legal, and how is authorization handled?
Every engagement runs under signed authorization against your own organization, within an agreed scope, window, and call volume, with named approvers and documented abort conditions. Voice assets are generated only for individuals whose likeness use has been approved in writing, and they are destroyed at the close of the engagement.
What do we get back?
A report covering action rate, process hold rate, and report rate, broken down by scenario and by the control that was supposed to catch it. It includes the specific points in the conversation where verification was skipped, prioritized remediation for the procedure itself, and evidence written for auditors without a rewrite.
Find out whether your verification procedure holds
Thirty minutes. We will look at your help desk reset path and your approval chain, and pick the scenario worth running first.
Or see how voice runs alongside video, email, and SMS in the OSES platform.
