New wave of voice phishing attacks targets VPN credentials

Person on phone
(Image credit: Pexels)

Phishing attacks and other online scams designed to steal employee credentials have increasingly become a common occurrence for those working from home during the pandemic.

However, one group of cybercriminals is taking their phishing attacks to the next level by using a voice phishing service which combines phone calls to potential targets with custom phishing sites in order to steal VPN credentials from remote workers.

As reported by Krebs On Security, the cybercriminals behind this new campaign have a remarkably high success rate and operate through paid requests or “bounties” in which their dark web customers seek access to specific companies or accounts. 

Over the past six months, the group has created custom phishing pages that target some of the largest companies in the world though their primary focus is on organizations in the financial, telecommunications and social media industries.

Vishing attacks

A vishing attack normally begins with the cybercriminals making a series of phone calls to employees working remotely at a targeted organization. The attackers say they're calling from the organization's IT department to try and help troubleshoot issues with the company's VPN.

The end goal of the campaign is to convince a remote worker to divulge their credentials either over the phone or by inputting them manually at one of the attacker's phishing websites designed to mimic the legitimate website of their organization. According to ZeroFox's director of threat intelligence Zack Allen, the attackers often target new hires and even go so far as to create fake LinkedIn profiles to make their vishing attempts appear more legitimate.

Normally in one of these attacks, two cybercriminals work together with one speaking on the phone with a potential target while the other tries to log in to the target company's VPN with any disclosed credentials. Even if the attackers are unsuccessful in their vishing attempts, they still gain valuable insights into an organization which they can then use during their next attack targeting another employee at the company.

Vishing has gotten so bad during the pandemic that the FBI and CISA recently issued a joint security advisory warning organizations and their remote workers about the potential threat.

In much the same way that you should never hand out your credentials over email, the same can be said when someone calls you over the phone asking for them. At the same time, it is highly unlikely that your organization's IT department would call you on the phone to ask for credentials they likely already have.

  • Also check out our complete list of the best VPN services

Via Krebs On Security

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in VPN Privacy & Security
Homepage of CloudFlare website on the display of PC, url - CloudFlare.com.
"Network blocking is never going to be the solution" – Cloudflare slams anti-piracy tactics
Panels at RightsCon 2025 during a press briefing about the latest Access Now report of internet shutdowns
2024 was the worst year on record for internet freedoms – again
Vector illustration of the word Censored in a glitch distorted style
Google, Apple, and internet restriction – how Big Tech is making censorship "much worse" according to experts
Google TV onscreen interface showing streaming apps
Why do streaming services geo-restrict content?
Pirate key on computer keyboard
Italy to require VPN and DNS providers to block pirated content
piracy
Canal+ wants to block VPN usage – and VPN providers are fuming
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection