SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
KnowBe4 launches vishing simulations for staff training

KnowBe4 launches vishing simulations for staff training

Thu, 30th Jul 2026 (Yesterday)
Mark Tarre
MARK TARRE News Chief

KnowBe4 has launched a simulated vishing feature for its security awareness platform, aimed at phone-based social engineering attacks.

The feature lets security teams run customised voice phishing simulations using local caller IDs, realistic personas and multi-step scenarios. It has been added to the attack and simulation section of the KnowBe4 platform, with results feeding into the same reporting used for phishing and training data.

The launch comes as security vendors and incident researchers report a sharp rise in voice-based fraud targeting employees. Phone scams are a growing concern for employers as attackers increasingly use urgency, impersonation and conversational tactics to persuade staff to disclose information, transfer funds or grant access to internal systems.

CrowdStrike reported a 442% increase in vishing activity between the first and second halves of 2024. Mandiant ranked voice phishing among the leading initial infection routes facing organisations, while Verizon found employees were 40% more likely to fall for phone-based simulation tests than conventional phishing emails.

For companies that have invested heavily in email security awareness training, the figures suggest the phone channel remains a weak point. Unlike phishing emails, vishing calls can put workers under immediate pressure and let attackers adapt their pitch in real time.

KnowBe4 said the feature is designed to help security teams test staff under those conditions rather than limiting training to inbox-based threats. Simulation data will also contribute to its Risk Score, which gives customers a single view of risk across human users and AI agents.

Growing threat

Vishing has gained prominence as cyber criminals adopt methods that are harder for employees to verify on the spot. Calls that appear to come from a local number, or from someone claiming to represent the IT department or senior management, can create a sense of legitimacy before a target has time to question the request.

Security specialists have also warned that AI-generated voice cloning is making impersonation more convincing. That has increased pressure on organisations to train staff not only to spot suspicious emails and messages, but also to challenge requests delivered by phone.

Greg Kras, Chief Product Officer at KnowBe4, linked the launch to that shift in attacker behaviour.

"An urgent phone call from someone pretending to be your IT department or a C-level executive creates instant pressure, and cybercriminals are using AI voice cloning to make these calls unbelievably convincing," said Greg Kras, Chief Product Officer at KnowBe4. "To build true organisational resilience, security teams can no longer focus solely on the inbox. With our new simulated vishing capability, we are equipping security leaders with the tools needed to train employees across every major social engineering vector to prevent these types of attacks."

The product is designed to reflect how vishing attacks unfold in practice, with scenarios that develop over several stages rather than through a single scripted interaction. The aim is to mirror attacks in which a caller builds trust over time or adjusts requests based on an employee's responses.

Training gap

Security awareness products have traditionally focused on phishing emails, malicious links and attachment-based threats, in part because those attacks are easier to simulate and track at scale. Voice-based scams have been tested less often, even though they rely on many of the same human factors, including urgency, authority and fear of making a mistake.

As a result, many organisations have limited data on how employees respond to live social engineering by phone. KnowBe4 said its reporting on vishing susceptibility is intended to give security leaders a level of visibility similar to that already available for email-based testing.

Kras said generic call scripts no longer reflect the methods attackers use.

"The organisations getting breached this year were not tricked by a generic phone scam script, but rather by a patient, adaptive conversation that felt legitimate at every step," said Kras. "Training employees against anything less than that is not training them for the threat they will actually face."

KnowBe4 says it serves more than 70,000 organisations worldwide. The company has expanded its platform beyond traditional awareness training to cover attack simulation, collaboration security and security risks linked to AI agents, with vishing now added as another testing area.