Attackers don't need sophisticated zero-days anymore. Last July, someone called a Brinks Home IT administrator, sounded professional and urgent, and asked for authorization on a routine software update. The employee granted it. Days later, the entire customer database was gone, handed over to ShinyHunters. 4.9 million records leaked after the company refused to pay ransom, including customer support chats and personal information.
This wasn't isolated. ADT fell to the same approach. Then EY. All three used vishing, voice phishing, to compromise Salesforce environments through OAuth abuse. The attackers impersonated legitimate system administrators, requested access to what looked like standard Data Loader tools, and employees trusted the voice on the line.
Microsoft's security team documented ShinyHunters targeting over 1,000 organizations across campaigns claiming 1.5 billion records. Each time, the method stayed consistent: vishing to trick employees into authorizing attacker-controlled OAuth apps. At Brinks Home, the initial access vector was a compromised Microsoft Entra account. Detection came a week too late.
The numbers tell a story of a technique that's winning
Mandiant's M-Trends 2026 report just confirmed it. Vishing officially overtook email phishing as the primary initial intrusion vector in 2025. CrowdStrike tracked a 442% surge between the first and second half of 2024. By Q1 2025, Cisco Talos reported vishing accounted for over 60% of their phishing incident response engagements. Firewalls get smarter every year. The human voice on the phone remains unpatchable.
Here's where the paradox gets sharp. Google launched "Let Google Call" in November 2025, powered by Duplex. The AI agent places calls to local businesses to check pricing or availability on your behalf. It identifies itself as automated. Businesses accept these calls. We're training the entire world to trust non-human voices making requests over the phone.
When AI assistants become normal, when people stop questioning calls because they've accepted automated ones as routine, attackers gain cover. A human pretending to be a system administrator starts sounding just like another AI doing its job. The technology that promises convenience creates the exact conditions where vishing thrives.
Employees at major corporations are already conditioned. A voice calls, claims to be from IT, requests OAuth authorization for a data tool. The person on the other end might actually be an AI. Or it might be someone counting on you to not care anymore. The trust mechanism that vishing exploits doesn't differentiate.
This material is informational only and does not constitute financial or security advice. Organizations should implement voice verification protocols and security awareness training independently.

