The FBI is warning of hackers carrying out ongoing vishing attacks targeting companies around the world. Specifically, the hackers seek to steal corporate accounts and credentials, to access a network and escalate privileges.
Vishing is a social engineering attack in which hackers impersonate a trusted entity during a voice call to convince unsuspecting targets to reveal sensitive information, such as banking details and login credentials.

According to the FBI’s warning, hackers are using Voice over Internet Protocol (VoIP) – also known as services – to target employees of companies around the world. During the attacks, hackers trick targeted employees into logging into a phishing page they control to collect usernames and passwords . In many cases, once they gain access to a company’s network, hackers gain more network access than expected, which allows them to escalate privileges using the accounts of the compromised employees. In this way, they can gain further access to the compromised networks and cause significant financial damage to the targeted company.
The FBI reported that in one of the vishing attacks targeting companies, hackers found an employee through the company’s chatroom and convinced him to log in to a fake VPN page they operated. They then used those credentials to log in to the company’s VPN and conducted reconnaissance to identify someone with higher privileges. The cybercriminals used a messaging service to communicate and trick the employee into providing them with their login credentials.
As BleepingComputer reports, this is the second time since the outbreak of the COVID-19 that the FBI has warned of vishing attacks targeting company employees, as a large percentage have resorted to remote work.

In August 2020, the FBI and CISA issued a joint advisory to remote workers, warning them of an ongoing phishing campaign targeting companies across various industries.
Specifically, at that time the following was reported: “In mid-July 2020, cybercriminals launched a phishing campaign – gaining access to employee tools of several companies – with the aim of making a profit. Using the vished credentials, they stole data from corporate databases, which concerned personal customer information, to exploit in other attacks.”
Additionally, in the August attacks, hackers used malicious sites that “cloned” companies’ internal VPN login pages, which helped them bypass two-factor authentication (2FA) or one-time passwords (OTP). After tricking victims into approving OTP or 2FA prompts, the crooks gained control of their phones and bypassed 2FA and OTP in a SIM swapping attack.

The FBI has shared some steps that companies should take to avoid vishing/phishing attacks:
- Implement multi-factor authentication (MFA) for access to employee accounts to minimize the chances of a breach.
- When new employees are hired, network access should be granted at the least privilege level. Periodically reviewing this network access for all employees can significantly reduce the risk of vulnerabilities and/or weak points within the network being compromised.
- Active scanning and monitoring for unauthorized access or modifications can help identify a potential breach in order to prevent or minimize data loss.
- Network segmentation should be implemented to divide a large network into many smaller networks which allows administrators to control the flow of network traffic.
- Two accounts should be issued to administrators: one account with administrative privileges to make changes to the system, and one account to be used for email, deploying updates, and generating reports.
