
Phishing, a term now familiar across industries, is defined by the National Institute of Standards and Technology as a technique that seeks sensitive data—such as bank account numbers—through fraudulent emails or websites, where the attacker pretends to be a legitimate business or individual.
Rise of voice‑based phishing, or vishing
The Office of Information Security described “vishing” in an August 2022 report as the practice of extracting information or influencing actions via telephone. A follow‑up publication from April 2024 examined social‑engineering attacks aimed at the health‑care and public‑health sectors, noting that advances in technology and artificial intelligence lower entry barriers for cybercriminals and boost attack sophistication.
One highlighted method is Telephone‑Oriented Attack Delivery (TOAD). In this scheme, attackers shift the initial contact from email to phone, enticing victims to call fraudulent call centers that harvest credentials or install malware. Because the originating emails often lack URLs or attachments, traditional detection tools may miss them.
Impact on health‑care and finance
Data from 2023 shows an average of 1.99 health‑care electronic medical records breaches involving at least 500 records each day, with roughly 364,571 records exposed daily.
Health‑care and finance remain the most targeted sectors. Multi‑factor authentication (MFA) is often bypassed through techniques such as SIM swapping, adversary‑in‑the‑middle attacks, MFA prompt bombing, token theft, and vishing or smishing.
MFA is frequently compromised.
Related: User Blocked by Social Media Platform
The launch of ChatGPT in November 2022 coincided with a reported 1,265 % surge in phishing‑related attacks, including vishing and smishing. Training emerged as the top risk‑mitigation factor, according to the same OIS analysis.
Okta, a common MFA provider, has seen a rise in attacks where perpetrators call victims or IT help desks, persuading them to weaken or reset MFA controls. The NIST framework of prevention, detection, and correction aligns with both cybersecurity best practices and HIPAA compliance. Prevention involves training; detection can be carried out by software or vigilant staff; correction requires rapid reporting to technology teams or IT departments.
Cybercriminals are likely to increase both the frequency and sophistication of attacks, especially as AI tools become more accessible. A February 2026 settlement announced by the U.S. Department of Health and Human Services Office for Civil Rights highlighted a successful phishing breach that stemmed from inadequate safeguards, including a missing annual risk analysis. This highlights the growing liability for covered entities and business associates.
For organizations, addressing all phishing variants, staying abreast of the evolving threat environment, and implementing concrete steps against vishing are essential to limit both attack risk and potential legal exposure.
In practice, the surge in voice‑based scams means that employees who routinely handle MFA reset requests may find themselves on the front line of defense. A single misplaced phone call can open a pathway for attackers to bypass layers of security, making it important for firms to embed clear verification protocols into daily workflows.




