Threat Intelligence Report

Vishing: Voice Phishing Evolution

Understanding the transition from primitive cold calls to sophisticated AI-driven voice synthesis. A technical breakdown of how modern telecommunication vulnerabilities are exploited to target Canadian citizens.

A high-tech digital visualization of sound waves morphing in
Historical Context

The Progression of Deception

1990s

The Analog Era

Fraudsters relied on manual dialing and basic social engineering. Scams were limited by long-distance costs and lacked the ability to mask caller IDs effectively. The primary targets were credit card holders through simple "bank representative" impersonation.

2010s

VoIP & Spoofing

The mass adoption of Voice over IP (VoIP) allowed for automated mass-dialing (robocalls) at near-zero cost. Attackers began using CRA impersonation tactics, leveraging Caller ID spoofing to appear as legitimate government agencies.

2024+

AI & Deepfake Voice

Modern vishing utilizes Generative AI to clone specific voices from short audio clips found on social media. This technology fuels high-stakes Grandparent Schemes where the attacker sounds exactly like a family member in distress.

Engineering Breakdown

Technical Spoofing Mechanics

Caller ID spoofing is the practice of causing the telephone network to indicate to the receiver of a call that the originator of the call is a station other than the true originating station. This is achieved by manipulating the "From" field in the Session Initiation Protocol (SIP) headers used in VoIP communications. Because the global telephony backbone was built on trust, many older exchanges do not verify the authenticity of this data.

In Canada, the implementation of STIR/SHAKEN (Secure Telephone Identity Revisited/Signature-based Handling of Asserted Information Using toKENs) aims to combat this. However, attackers bypass these protocols by routing calls through international gateways in jurisdictions where these standards are not enforced. This creates a "trust gap" where a call from overseas can appear with a local "613" or "416" area code.

⚠ Warning: Verification Failure

Never rely on the name or number displayed on your screen as proof of identity. Modern software allows attackers to change these values in milliseconds. Refer to the Glossary for technical definitions of SIP and STIR/SHAKEN.

Protocol

Operational Instructions for Incoming Calls

  1. 1

    Initial Silence Phase

    When answering an unknown number, remain silent for 3 seconds. Automated systems often disconnect if they do not detect an immediate voice response.

  2. 2

    Identity Verification

    If the caller claims to be from a bank or government agency, ask for their employee ID and department name. Do not provide any personal data to "verify" your identity.

  3. 3

    The "Hang Up and Call Back" Rule

    Terminate the call immediately. Use a different phone line (if possible) to call the official number listed on the back of your bank card or the official .gc.ca website.

Indicator Vishing Tactic Risk Level
Urgency "Your account will be frozen in 1 hour." Critical
Secrecy "Do not tell anyone about this investigation." Critical
Payment Request for gift cards or crypto transfers. Extreme
Audio Quality Unnatural pauses or slight metallic echo. High (AI)

Have you encountered a suspicious call?

Immediate action is required to secure your telecommunications hardware and report the incident to the Canadian Anti-Fraud Centre.

The Small Thatch project serves as an independent technical reference and educational resource. This platform is not affiliated with, endorsed by, or connected to any Canadian government agencies, law enforcement organizations, commercial telecom providers, or financial institutions. All information is provided for preventative educational purposes only.