The Workforce Has a Blind Spot, and It’s Ringing

KnowBe4 Team | Sep 10, 2026

With inboxes increasingly well guarded, cybercriminals are turning to a more vulnerable front in their attacks against your digital workforce.

Voice is the fastest-growing attack vector, and it’s because it’s dangerously effective. According to Verizon’s 2026 Data Breach Investigation Report, phone-centric attacks are 40% more successful than traditional email-based phishing.

Voice phishing (vishing) is a smart attack vector, especially with AI enabling comprehensive target reconnaissance and tailoring. But the real problem is deeper: vishing tests a skillset that is underdeveloped among most workforces.

How is Vishing Different from Phishing?

Security teams have spent years training their workforce to spot phishing emails. They’ve drilled them to scrutinize the sender address and watch out for email typos. But vishing tests a different muscle entirely. Users can’t stop and analyze a call mid-conversation like they can an email, and that turns into more mistakes at the moment of risk.

Security awareness training provides a strong baseline, but it doesn’t build muscle memory. People forget close to 90% of what they learn within a month when that knowledge isn’t tested and reinforced in the real world. Closing this gap takes real practice against the actual attack.

And that’s exactly what Simulated Vishing is built to deliver.

Practice Against the Real Thing

Simulated Vishing extends KnowBe4’s attack simulation capabilities across the voice channel, giving your workforce practice against the automated vishing attacks behind some of today’s costliest breaches. Test your workforce with sophisticated simulations based on current attacks so they’re better able to spot the red flags and shut down cybercriminals.

  • Real attack patterns, ready to launch: Pick from dozens of templates modeled on real-world scenarios, such as tax form verification and IT helpdesk scams.
  • Put your high-risk workflows to the test: Create custom simulations using uploaded audio or AI text-to-speech to test voice-based workflows used at your organization.
  • Test security behavior, not language proficiency: Pre-built and custom templates support 25+ languages and dialects, so you can run tests at global scale without worrying about language barriers.
  • Make practice feel real: Localized caller ID and automatic number cycling mean wrong area codes and carrier spam flags don’t tip off users before they pick up.

New Attack Vector, Proven Risk Reduction Formula

Realistic simulations expose vulnerabilities, but closing these gaps and driving real behavior change is another matter entirely. This is where KnowBe4 excels, tapping into 16+ years of experience analyzing threat intelligence and behavioral signals to drive real risk reduction. Every Simulated Vishing campaign feeds into a Vish-prone Percentage and rolls into the Risk Score already guiding your security awareness program.

Pass or fail, each simulation can also trigger an automated response, adjusting the difficulty and frequency of future simulations and auto-enrolling high-risk users into remedial vishing training. With 100+ vishing-specific training modules, including quick video micro-lessons and interactive games, you can design remedial training programs for learners of all types. You can even trigger in-the-moment SecurityTips with Real-Time Coaching, reinforcing training as simulations happen.

This continuous learning loop is what makes the difference between discovering risk and actually driving the behavior change that reduces it. And while bad actors may be re-discovering voice as an attack channel, the methodology behind the KnowBe4 risk reduction loop has a proven track record: the average customer sees the share of employees susceptible to phishing drop from 33.1% to 4.1% within a year.

Attackers are always looking for an edge, and they’ve found it with voice. With Simulated Vishing, give your workforce real, repeatable practice spotting the red flags before they find themselves in the crosshairs. Schedule a demo today to learn more.

FAQs

What is Simulated Vishing?

Simulated Vishing is KnowBe4's attack simulation capability for the voice channel. It lets organizations test employees against realistic vishing scenarios, using pre-built templates or custom audio, and measure results through a Vish-prone Percentage that feeds into an organization's overall Risk Score.

How does KnowBe4 help reduce vishing risk after a simulation?

Each simulation can trigger an automated response, adjusting future simulation difficulty and auto-enrolling high-risk users in remedial vishing training. KnowBe4 also offers Real-Time Coaching, which delivers in-the-moment Security Tips as simulations happen to reinforce learning.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.