This file collects what the corpus can say about voice phishing after a year in which it reached every sector this database covers.
The List Is Long Enough To Be A Finding
UK retailers at 25-0430, 25-0501 and 25-0929. Insurers at 25-0529, 25-0618 and 25-0622. Airlines at 25-0627 and 25-0701. Coinbase support agents at 25-0514. SaaS tenants at 25-0806. Universities at 25-1208.
Different countries, different sectors, different security budgets. One technique.
It Defeats The Entire Technical Stack
There is no packet to inspect, no attachment to detonate, no domain to block, no certificate to check, no anomalous login to alert on. The output of the call is a legitimate action by an authorised person.
That is why 25-0810 matters so much: the best-resourced organisation in this database was reached the same way as a nursery group. The technique does not care what the security budget is, because it does not touch anything the budget bought.
And The Sophistication Argument Is A Distraction
The corpus filed at 25-0724 that four people aged 17 to 20 were arrested over incidents that cost a retailer a nine-figure sum, and argued that an unsophisticated technique which works is worse than a sophisticated one because it is available to far more people.
Nothing this year contradicted that. The barrier is a plausible voice and knowledge of a verification script — the sector-research argument at 25-0512.
What Actually Helps
Not training. A support agent who correctly refuses 999 calls and is deceived on the thousandth has not failed — that is the habituation argument at 25-0311, and it applies to people as well as dialogues.
What helps is removing the outcome from the conversation: verification that cannot be performed over the phone, credential resets that require a second channel or a manager, and — the point at 25-0701 — limiting how much a single ordinary session can reach, so that a successful call is worth less.
Every one of those slows the help desk down. That is the trade being made, and it is being made by default, in favour of speed, in almost every organisation in this database.
It synthesises the voice-phishing incidents recorded across this database. Attribution and campaign membership follow published research in each underlying file. Corrections: corrections@forensicpost.com.