Overview
Vishing (voice-based phishing) is one of the most effective and underestimated social engineering vectors in use today. It requires no technical infrastructure to speak of, exploits well-documented psychological mechanisms, and disproportionately targets people who are least likely to have been told what to look for.
“Jane” isn’t her real name, but her story and the $30,000 she nearly lost is very real. Jane came within hours of losing it to a textbook vishing attack from a threat actor. We are sharing this account because the detail matters: the script, the pressure, the OSINT, and the recovery steps taken in the hours that followed.
This case happened in the US, but the tactics are used around the world. The recovery steps and the legal references later on in this post point to US mechanisms, but the core approach applies anywhere.
How the Attack Unfolded
Jane received a text message claiming her Apple Cloud storage payment had failed. Having recently taken over the household's financial matters following the death of her husband, the message seemed plausible. Jane did not notice that the sender's number originated from the Philippines, a detail easy to miss under normal circumstances, and nearly impossible to catch under pressure.

The text directed her to call an 877 number. This is significant because 877 numbers can be purchased through several service providers using prepaid credit or debit cards, with little to no identity verification required. The number is no longer in service and has since been redirected.
The images below show the results of a business listing search and a reverse phone lookup carried out on the number – no business, no registered owner, no traceable identity. This is exactly what anonymous prepaid telephony infrastructure looks like in practice.


Jane called the number and was connected to the threat actor, who opened with a fabricated arrest warrant, claiming Jane was wanted in Texas on drug charges and reinforced the story using basic OSINT about Jane and her family. The effect was immediate. Jane entered what the Fight, Flight, or Fawn model describes as the “compliance” state: appeasing and cooperating to avoid a perceived threat of harm.
From that point, Jane answered questions she would normally never would have dreamed of giving up to a stranger. Information divulged to the threat actor included: the make and model of her car, how much cash was in her house, that she would be alone the following day due to surgery, and that she lived by herself.
When they initially requested payment in cryptocurrency, Jane indicated she would need her sons to facilitate that. Without hesitation, he pivoted to requesting a bank check made out to [Redacted] Construction Inc. From there, the threat actor coached her on what to tell the bank teller if questioned, specifically that the payment was for a home remodel. The bank teller did attempt to raise concerns about the amount and payment method. Jane, still in compliance mode, continued regardless.

The threat actor kept the pressure on throughout, following up with calls and texts from a Washington D.C. number to confirm the actions were being followed through. He requested photographic proof of the check once received and then the UPS shipping receipt. This constant contact, with no gaps in which Jane could pause, reflect, or verify anything, is a hallmark of social engineering: remove the victim's ability to think critically by eliminating time and space to do so.
The physical address used for the check (linked to a New York business) showed several registered occupants and construction companies dating back to 2016 through OSINT analysis. The NYC business licence for [Redacted] Construction Inc is likely linked to a stolen identity, as business licences in New York can be issued without verification of the owner or physical address, a well-documented gap that threat actors exploit routinely.
Jane's daughter and daughter-in-law intervened before the package left UPS custody. They retrieved the check and returned it to the bank. The UPS store manager later informed the family that the threat actor had called the store directly to track the package, confirming the threat actor was actively monitoring the shipment. That intervention gave the family a 24-hour window to act before any identity material could be misused.
Immediate Response: The First 24 Hours
The family filed a police report with their local department. Unlike cryptocurrency payments, a bank check sent to a physical address and gives law enforcement a tangible lead, even if the address itself is a front.
The following steps were completed within the first 24 hours:
- Financial accounts: All of Jane's financial institutions were notified. Passphrases and PIN numbers were added to accounts to prevent unauthorised phone-based activity.
- Credit cards: All cards were placed into a locked state as a precaution, since Jane was uncertain whether she had disclosed any card details during the call.
- Credit freezes: Freezes were placed with all three major credit reporting agencies – Equifax, TransUnion, and Experian. Contact details for each can be found at identitytheft.gov/CreditBureauContacts. Readers outside the US should identify the equivalent credit reporting bodies in their region and contact them as a priority step.
- Government identity accounts: An ID.me account was created for access to the Social Security Administration, and a PIN was placed on Jane's IRS tax account. ID.me is a private digital identity verification provider contracted by the US Government and several states by 2030, to meet NIST federal security standards. It provides verified access to services including the IRS, SSA, HHS, and Veterans Affairs. As a secondary option, an account was also created with the government's alternative authentication service, Login.gov. Non-US readers should look to their national equivalents for government-backed identity verification and tax account protection.
- Family verification word: A shared known word was distributed to close family members to verify identity during calls. This functions as a low-tech second factor against AI-generated voice scams or impersonation calls claiming a family member is in trouble. The principle is the same used with children: if the caller cannot produce the word, communication stops. This measure requires no technology and is equally applicable anywhere in the world.
- Call management: A family member answered all of Jane's incoming calls for the next 48 hours, during this time the threat actor persisted to get back in contact with Jane.
- Monitoring service: An active identity monitoring service was set up, with specific coverage for car title and house title monitoring. These are among the most difficult assets to protect reactively. While manual removal from breach databases is possible, a managed service significantly simplifies the process. Equivalent services exist in most regions, though coverage and capability vary.
Key Takeaways
This case is not unusual. The tactics used – urgency, authority, OSINT-backed personalisation, and relentless follow-up, are well-documented and effective precisely because they bypass rational thinking rather than trying to deceive it. The following lessons apply regardless of geography.
- Treat digital contact as low-trust by default. Unlike a face-to-face interaction, a phone call, text, or email provides the recipient with almost no reliable signal of who they are speaking to. Numbers can be spoofed, identities fabricated, and authority manufactured. Scepticism is not rudeness, it is the correct response.
- Skepticisim should be the default Unsolicited texts from unknown numbers, even seemingly innocuous ones, are more likely to be the opening move of a scam than a genuine wrong number. It is entirely appropriate to verify the identity of anyone who calls, texts, emails, or arrives at the door.
- Pressure and urgency are essential to the attack. If someone is preventing you from pausing, checking, or consulting another person, that pressure itself is the signal something is wrong. Legitimate authorities do not demand immediate compliance with no opportunity for verification.
- Never respond to a victim with blame. Jane is not unusual in having been deceived. The compliance response is a well-understood psychological mechanism, not a character flaw. Victims need to feel safe enough to come forward quickly, that window matters enormously for recovery.
- Known words work. The same mechanism used to verify a trusted adult picking up a child from school applies directly to AI voice scams and impersonation calls. A shared family word, kept separate from any financial passphrase and supplemented by a known family reference or inside detail, is a simple and effective second factor that requires no technology and no budget.
- Save everything. Emails, phone numbers, screenshots, and text messages should all be preserved on an unaffected device if there is any chance of filing a police report or an IC3 complaint. Once a scammer establishes that a target is protected and alert, they typically move on, but documentation matters for any subsequent investigation.
Act Now, Not After
The protections described in this post can be put in place today, before anything happens. Credit freezes, government identity PINs, and family verification words cost nothing and take an afternoon to set up. They add a small amount of friction to legitimate processes. They add a significant barrier to fraudulent ones.
Useful Resources
The following resources are US-specific. If you are based outside the US, we would encourage identifying the equivalent services provided by your national government, credit reporting agencies, and financial regulators.
