Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Glossary graphic explaining vishing — voice phishing — on dark navy background with teal accent

What Is Vishing? The Phone Scam Behind This Week’s Major Banking Breach

Vishing — short for voice phishing — is a social engineering attack delivered by phone. Instead of a dodgy email, someone rings you (or your staff) pretending to be a vendor, a bank, or internal IT support, and talks their way into getting credentials or remote access.

It just worked against one of the biggest financial technology providers in the world. Jack Henry & Associates, which supplies core banking platforms to more than 7,200 banks and credit unions, confirmed on 31 August that attackers from the ShinyHunters group used vishing to breach a portion of its internal corporate environment. The caller impersonated a trusted contact, obtained credentials, and got in without exploiting a single software flaw.

Why it matters right now

Most Australian businesses train their teams to spot phishing emails. Very few train them for phone calls. In our client environments, we consistently see security awareness programs that cover email, dodgy links, and even QR codes — but phone-based social engineering barely rates a mention. That gap is exactly what groups like ShinyHunters exploit. If a caller sounds confident and knows your account details, most people will comply.

In Jack Henry’s case, the attackers didn’t touch production banking systems, and client data exposure was limited to fewer than 10 institutions. But the breach still triggered an extortion demand (which Jack Henry refused to pay) and a federal law enforcement investigation.

What to do about it

Add a verbal verification step for any phone request that involves credentials, remote access, or changes to accounts — even when the caller claims to be from a vendor your team recognises. A quick callback to the vendor’s published number is the simplest defence, and it costs nothing. If your security awareness training doesn’t cover vishing scenarios, it has a blind spot worth fixing before your next session.

If you’re not sure whether your team’s training covers phone-based attacks, talk to us and we’ll walk through what a practical vishing drill looks like.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →