KnowBe4 Launches Simulated Vishing Training to Combat Rising Voice Phishing Threats
KnowBe4, the global leader in digital workforce security, securing both humans and AI agents, announced its new simulated vishing capability designed to help organizations close ......
KnowBe4, the global leader in digital workforce security, securing both humans and AI agents, announced its new simulated vishing capability designed to help organizations close what has become the fastest-growing gap in security awareness: the phone channel.
Vishing has moved from a niche tactic to a mainstream attack vector. CrowdStrike’s 2025 Global Threat Report cited a 442% surge in vishing activity between the first and second halves of 2024, and Mandiant’s M-Trends 2026 Report now ranks voice phishing among the top initial infection vectors organizations face. The 2026 Verizon Data Breach Investigations Report found that employees are 40% more likely to fall for phone-based simulation tests compared to traditional email phishing.
“An urgent phone call from someone pretending to be your IT department or a C-level executive creates instant pressure, and cybercriminals are using AI voice cloning to make these calls unbelievably convincing. To build true organizational resilience, security teams can no longer focus solely on the inbox. With our new simulated vishing capability, we are equipping security leaders with the tools needed to train employees across every major social engineering vector to prevent these types of attacks.”
– Greg Kras, chief product officer, KnowBe4
Simulated vishing is now available within the attack and simulation pillar of the KnowBe4 Platform, aimed to protect both humans and AI agents. Vishing simulation results feed the same reporting and risk visibility organizations already rely on for phishing and training data, influencing the Risk ScoreTM, which highlights one unified view of human and AI risk across channels. Highlights of the new capability include:
- Training for Evolving Threats: Extends security awareness training to the phone channel, one of the fastest-growing and least-tested vectors for social engineering.
- Real-World Resilience: Employees practice recognizing live, high-pressure phone tactics in a safe environment, rather than encountering them for the first time from a real attacker.
- Visibility for Security Leaders: Reporting on vishing susceptibility gives security leaders the same data-driven view of voice-based risk that contributes to the overall Risk Score.
- Real Attacker Tactics: Local caller ID, realistic personas, and multi-step customizable scenarios mirror how modern vishing attacks are actually carried out.
“The organizations getting breached this year were not tricked by a generic phone scam script, but rather by a patient, adaptive conversation that felt legitimate at every step. Training employees against anything less than that is not training them for the threat they will actually face.”
– Greg Kras, chief product officer, KnowBe4

