32.9 C
Rābigh
August 16, 2026
TheLens
Information Security

Stay alert: Voice phishing attacks on the rise

The Information Security Department reminds the KAUST community to remain vigilant against voice phishing (vishing) attacks and fraudulent phone scams. Cybercriminals are increasingly using phone calls, text messages, and messaging applications to impersonate trusted organizations to steal sensitive information, gain access to accounts, or commit financial fraud.

Why should you be cautious?

Voice phishing, also known as vishing, is a form of social engineering in which attackers impersonate trusted entities such as government agencies, banks, telecommunications providers, delivery services, or technical support representatives. These callers often create a false sense of urgency by claiming that immediate action is required regarding your national ID, Iqama, bank account, residency status, traffic violations, package delivery, or account security.

Their goal is to persuade victims to reveal sensitive information, share One-Time Passwords (OTPs), approve authentication requests, install software, or transfer money. Once obtained, this information can be used to access accounts, conduct fraudulent transactions, or compromise personal and organizational data.

How can you stay protected?

To help ensure a safe and secure experience, please follow the guidelines below:

  • Never share your OTP, verification code, passwords, authentication approvals, or personal information with anyone over the phone, regardless of who they claim to be.
  • Remember that legitimate organizations, including government agencies, banks, and service providers, will never ask you to disclose OTPs, passwords, or authentication codes by phone, email, or text message.
  • Be cautious of unsolicited calls that create urgency, pressure you to act immediately, or threaten negative consequences if you do not comply.
  • Verify the caller’s identity independently by ending the call and contacting the organization directly using official contact information available on their website or mobile application.
  • Do not install software or remote-access applications at the request of an unknown caller.
  • Immediately end the call if you are asked to share sensitive information, approve an authentication request you did not initiate, or make a payment under pressure.

Security is a shared responsibility, and remaining alert to voice phishing and other social engineering attacks is essential to protecting yourself and the KAUST community.

For additional guidance or support, please contact AskInfoSec@KAUST.edu.sa.

Leave a Comment