Vishing “Help Desk” Scams and Lookalike Phish Surge

eSecurity Planet · Medium sophistication
Last updated August 17, 2026

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that use valid HTTPS certificates to look legitimate, especially on mobile devices. Separately, a confirmed Levi Strauss incident is attributed to social engineering that led to compromised employee computers.

How the attack worked

In one pattern described in this roundup, attackers impersonated internal IT support staff over the phone. They told employees there was an urgent account or security issue and pushed them to a phishing site to sign in and resolve it. The page was built to capture both the employee's password and their authentication code in real time. This phone-based activity reportedly touched infrastructure tied to more than 200 organizations, with finance, operations, and executive staff among the targeted roles.

A second pattern relied on lookalike domains impersonating WhatsApp and Instagram. These sites used valid TLS certificates, so browsers showed the padlock icon and treated the connection as secure, even though the domain itself was not the real service. Victims were prompted to sign in or verify their account, handing over credentials and one-time verification codes to the attacker instead.

Why it succeeded

Both scenarios exploit trust signals people are trained to rely on. A phone call from "IT support" carries authority, especially when framed as urgent. A valid HTTPS certificate carries the same kind of implied trust, since many users equate the lock icon with a safe site. On mobile devices this is worse, because smaller screens can hide deceptive URLs, making it harder to notice a slightly altered domain before entering credentials.

What to watch for

  • An unsolicited call claiming to be IT support that asks you to log in through a link
  • A request to read back or enter an authentication or verification code during a call or after clicking a link
  • Urgency or pressure to complete a login immediately
  • A login or verification page that arrived from an unexpected message rather than a bookmarked or typed-in address
  • A domain name that looks close to a familiar service but is not quite right, even if HTTPS is present

Building resistance

  • Establish a trusted help-desk verification procedure, such as calling a known internal number rather than trusting an inbound call or a link
  • Prohibit entering credentials or authentication codes after an unsolicited call or message
  • Reinforce that HTTPS and the padlock icon do not prove a site is legitimate; the actual domain still needs to be checked
  • Treat one-time passcodes as something that should never be shared or typed into a page reached from an unexpected link
  • After any suspected compromise, contain affected devices and rotate exposed credentials quickly, as was done following a reported incident involving compromised employee computers at Levi Strauss

Key findings

  • Attackers impersonating IT support staff used phone calls to steer employees to phishing sites that capture passwords and authentication codes “in real time,” targeting 200+ organizations.
  • Lookalike WhatsApp/Instagram phishing domains used valid TLS (HTTPS) certificates to appear trustworthy and steal login verification codes; mobile users are at higher risk due to reduced URL visibility.
  • Levi Strauss reported a breach in which attackers used social engineering to compromise three employee computers and expose corporate data.

Who’s being targeted

  • Commonly targeted roles: Finance, Operations, Executives/Managers, IT help desk, All employees (especially mobile users).
  • Affected industries: Finance, Retail/Apparel, Healthcare/Dental insurance, Logistics and transportation.
  • Attack channels: vishing, website.
  • Impersonated: Internal IT support / help desk, WhatsApp or Instagram login/verification page.

Red flags to watch for

  • Unsolicited help-desk call asking you to sign in via a link
  • Request for an authentication code (MFA) during an inbound call
  • Pressure/urgency to complete the login immediately
  • HTTPS/lock icon is present but the domain name is slightly wrong
  • Login/verification request arrives unexpectedly
  • On mobile, the full domain may be hidden or hard to inspect
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do fake IT help-desk vishing calls work?

Attackers call employees posing as internal IT support, claim there is an urgent account issue, and direct the victim to a phishing site to sign in, capturing passwords and authentication codes in real time.

Does HTTPS mean a login page is safe?

No. Lookalike WhatsApp and Instagram phishing domains used valid TLS certificates to appear trustworthy, so the lock icon alone does not confirm a site is legitimate.

Why are mobile users more at risk from these lookalike sites?

Smaller screens on mobile devices can hide or truncate deceptive URLs, making it harder for users to spot a slightly wrong domain name before entering credentials.

What should employees do if they get an unexpected help-desk call?

They should refuse to enter credentials or authentication codes during the call and verify the request through a known, trusted internal channel instead of the link provided.

Read the video transcript

Imagine this: you get a call, “Hi, this is IT support, there’s an issue with your account, open the link I’m sending and sign in.” These fake help‑desk vishing scams have hit over 200 companies, steering people to phishing sites that grab your password and MFA code in real time. Here’s the nasty twist: the site can even show HTTPS and a lock, just like real WhatsApp or Instagram, especially on mobile where the full address is hidden. Your move: if anyone calls or messages you to 're-authenticate' via a link, hang up, ignore the link, and contact our real help desk using the number on the intranet.

Similar attacks

Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Zero-Click Prompts Hijack AI Browsers via Email/X

Zero-Click Prompts Hijack AI Browsers via Email/X

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing…

August 6, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026