5 ms·
> In 2023, hackers used vishing (voice phishing) to impersonate employees and gain access to the internal systems of MGM Resorts International and Caesars Enter
by james_marks 1y ago
> In 2023, hackers used vishing (voice phishing) to impersonate employees and gain access to the internal systems of MGM Resorts International and Caesars Entertainment on the Las Vegas Strip, causing hundreds of millions of dollars in financial losses.
First time I’ve heard the term “vishing” to describe the attack we’ve all seen coming.
- electroglyph 1y agosocial engineering is as old as hacking itself
- ChrisMarshallNY 1y agoThat was Mitnick’s specialty, and he was hacking before the Web.
- AstroNutt 1y agoThe Art of Deception was one of my favorite books when it came out.
- wrayjustin 1y agoPhishing (Email), Smishing (SMS/Text Messages), and Vishing (Voice) are all standard industry terms, though obviously phishing is most well known. Then there's even subcategories that further define some of these, like Spear Phishing, Whaling. The industry loves its fun naming.
- airstrike 1y ago"Phishing" isn't limited to email
- lostlogin 1y agoThat’s lucky. Putting ‘ishing’ on the end of something email related doesn’t work very well.
- jerrythegerbil 1y ago[flagged]
- gpm 1y agoThat's not my understanding, or wikipedia's [1] understanding, of the term. Phishing is the general category of tricking people into telling you things they shouldn't. Email phishing, voice phishing (vishing), sms phising, and so on are subcategories. [1] https://en.wikipedia.org/wiki/Phishing https://en.wikipedia.org/wiki/Phishing Etymologically "phreak" and "fishing" both have nothing to do with email, "phreak" is "phone freak" and I believe it originally described messing with the tones that controlled the telephone system...
- jerrythegerbil 1y agoThat’s my exact point. Just because you repeatedly see it used a certain way by non-practitioners to generalize for simplified communication doesn’t mean it’s the correct usage, and leads to the exact confusion I’m attempting to clarify for you. Phishing is by default email. It’s varying mediums are subcategories. Bottom paragraph of first section of the very same Wikipedia article. “Phishing techniques and vectors include email spam, vishing (voice phishing), targeted phishing (spear phishing, whaling), smishing (SMS), quishing (QR code), cross-site scripting, and MiTM 2FA attacks.”
- airstrike 1y agoPhishing is not by default email
- mmaunder 1y agoNever heard of vishing. I’m in the industry.
- saithound 1y agoWrong industry. It is primarily the "sell anti-phishing training to enterprise employees" industry that uses these terms.
- deleted 1y ago[deleted]
- antonymoose 1y agoI was worked in an anti Phishing / brand protection firm back in 2012 and we had Vishing and Smishing terminology baked in the to projects back then.
- Razengan 1y ago> Smishing uh that's something completely different (and not Monty Python)
- Ekaros 1y agoWhy is it not emishing with email?
- StanislavPetrov 1y agoIn my day we used to call it "social engineering".
- Barbing 1y ago“human hacking”