Vishing: When the Bank Employee Is an AI

In mid-April BACS warned about a scam that has been circulating in Switzerland for months: calls from supposed bank employees who talk their victims into installing remote access software like AnyDesk or TeamViewer. The pretext varies between suspicious account activity, a security update, or an “urgent verification”, but the outcome is always the same: the attackers end up with full access to the computer, including e-banking, email and corporate data.

We see this in our client work all the time, and what has changed recently is that these calls have gotten noticeably better in terms of quality and conviction.

Why vishing works

You can ignore a phishing email, flag it or delete it, but when someone calls you, calm and professional, “from your bank”, telling you your account might be compromised, you react immediately and without thinking. That is exactly what the attackers are counting on.

The numbers back this up: Mandiant ranked voice phishing as the second most common initial attack vector in 2025, right behind classic email phishing. CrowdStrike documented a 442 percent increase in vishing attacks year over year, and total damages are estimated at over 40 billion dollars for 2026.

Then there is the AI angle: voices can now be cloned with three seconds of audio material, meaning a LinkedIn video, a podcast snippet or a recorded conference call is enough. The technology is freely available and you do not need a computer science degree to use it. Pindrop reported a 1210 percent increase in AI-based voice fraud attempts in 2025.

Typical sequence

The call usually comes in the morning when you are not fully awake and the coffee is half finished. The caller ID looks legitimate because spoofing phone numbers costs practically nothing, the caller speaks calmly and competently, often knows the victims name and sometimes even which bank they use.

Then the pivot: “We have detected unusual activity on your account. To verify this we would need to briefly look at your screen. I will guide you through installing a security tool.”

The “security tool” is AnyDesk or TeamViewer. Once the connection is established the attacker navigates to e-banking, has credentials confirmed or simply initiates transfers directly. Sometimes they also install malware on the side which stays active long after the call ends.

Risk profile for SMEs

Private individuals are the most frequent victims, but SMEs have a different and honestly more dangerous risk profile. Picture this: an accounts clerk responds to one of these calls. They are not just exposing their personal e-banking access but potentially opening the company account, payroll and client data. In small teams there is often nobody to check with; the accountant is alone in the office, the boss is travelling, and the “bank advisor” on the phone keeps pushing: “this needs to happen now.”

We see this in our penetration tests regularly, and even trained employees fall for well crafted vishing calls. The success rate is consistently above 30 percent, which is higher than email phishing. Most of our clients find that surprising; we honestly do not, not anymore.

Countermeasures

No bank will ever ask you to install remote access software over the phone. If you have internalised that single sentence you are immune to this specific attack.

But the principle goes further: any unexpected call demanding immediate action (install this software, confirm these credentials, approve this payment) deserves a simple “I will call you back”, via the banks official number and not the number the caller gives you.

For companies there is one measure that takes about an hour to implement and eliminates an entire attack vector: your IT policy should explicitly state that remote desktop tools may only be installed by internal IT. Where AnyDesk or TeamViewer are not needed (and that is most departments) they should be blocked via group policy.

And here is something suprisingly few companies do: awareness training that includes vishing scenarios, not just phishing emails. A phone simulation costs almost nothing, takes an afternoon, and shows you where the real vulnerabilities are.

Outlook

The BACS warning about fake bank employees is not an isolated case. Voice phishing is getting easier and more convincing every month, driven by AI voice cloning and cheap number spoofing, and defence needs to adapt accordingly: away from “I will spot the fraud” towards processes that catch fraud even when nobody spots it. Because at some point, nobody will…

Our social engineering assessments include phone-based attack scenarios, simulated vishing calls and AI-based voice manipulation. Want to know how your people would respond? Get in touch.

Sources: BACS Weekly Review KW 15, CrowdStrike Global Threat Report 2026, Pindrop Voice Intelligence Report 2025