A remote software engineer receives an unexpected phone call from an individual claiming to be a senior network administrator from the corporate IT helpdesk. The caller states that an urgent security patch requires immediate account validation and requests that the engineer approve a multifactor authentication (MFA) push notification sent to their mobile device. Which social engineering threat vector is primarily being conducted in this scenario?
- VishingAnswer
- BSpear phishing
- CWhaling
- DWatering hole attack
Answer
Vishing is the correct classification because the attack is conducted over a phone call (voice phishing) to manipulate the user into approving authentication access.
The attack uses telephone communication (voice phishing/vishing) to trick the user into granting access by approving an MFA push notification under the guise of an IT support request.
Step-by-Step Solution
Key Concept
Social Engineering Delivery Vectors