KnowBe4 Vishing: What's Built In + How Mirage Extends It
What KnowBe4's vishing tools do (Vishing Security Tests, AIDA callback templates, Spot the Vish) and how Mirage adds live conversational AI calls via KSAT.

If you're searching "KnowBe4 vishing," you're probably asking one of two questions: does KnowBe4 simulate voice phishing? and is that enough for the attacks my team is actually seeing?
Short answers: yes, and it depends on your threat model. KnowBe4 ships real vishing capabilities inside KSAT, and for automated, at-scale phone testing they work well. But the vishing driving today's breaches, a live human or a live AI improvising against your help desk, behaves nothing like a robocall. That's the gap our KSAT integration closes.
Key takeaways
- KnowBe4's native vishing tools are the Vishing Security Test (automated calls, keypad-entry fail condition), AIDA's callback phishing templates, and the Spot the Vish training game.
- These test whether employees interact with automated phone attacks. They don't hold a live, adaptive conversation.
- Mirage adds conversational AI vishing calls, deepfake executive impersonation, and multi-channel attack chains, and syncs every outcome into the KSAT user timeline for smart groups and training assignment.
- You don't replace KnowBe4. You augment it: Mirage generates the realistic voice-channel risk signal, KSAT turns it into training and reporting.
What Does KnowBe4 Offer for Vishing?
Vishing (voice phishing) is social engineering delivered over a phone call: an attacker poses as IT, a vendor, or an executive to talk a target into handing over credentials, resetting MFA, or moving money. KnowBe4 covers it from three angles inside its Security Awareness Training (KSAT) platform:
- Vishing Security Tests (VST). Upload a CSV of employee phone numbers, pick a template, and launch: the same set-it-and-forget-it model as their phishing security tests. The calls are automated scenarios, and the fail condition is concrete: if an employee enters data on their telephone keypad in response to the test, that's a fail, which can trigger a short remedial training module (KnowBe4).
- AIDA callback phishing templates. KnowBe4's AI Defense Agents include a Callback Template Generation Agent that builds simulated callback scams: the blended attack where an email pressures the target into dialing a phone number (KnowBe4 AIDA).
- Spot the Vish. A gamified training module, launched in June 2026, that drops users into realistic audio scenarios and asks them to make split-second recognize-resist-report decisions (KnowBe4).
That's a genuinely useful baseline: automated pressure-testing of the phone channel, plus training content that gets people listening for red flags.
Where Automated Vishing Tests Stop
Here's the thing about the vishing behind real incidents: nobody asks the victim to press 1.
According to CrowdStrike's 2025 Global Threat Report, vishing attacks surged 442% in the second half of 2024, and the curve hasn't bent back since. The attacks doing the damage are conversations, not IVR trees. Scattered Spider talks its way through help desks with improvised pretexts and mid-call pivots. Criminal platforms like p1bot are weaponizing ElevenLabs voices to run adaptive AI calls at scale. McAfee research found that roughly three seconds of audio is enough to clone a voice convincingly (McAfee).
A scripted call with a keypad fail condition measures something real, but it can't measure the moment that decides a breach: what your employee does when the "IT technician" answers their objection, builds rapport, and escalates the pressure. That skill only shows up, and only gets trained, in a live conversation.
How Mirage Augments KnowBe4 Vishing
Mirage is an AI social engineer: it places live, fully conversational voice phishing calls that adapt in real time, the way a human attacker (or a modern AI attack platform) does. Since March 2025, it's been the first AI social engineer integrated directly with KSAT.
The augmentation works as a loop:
- Mirage generates the signal. Employees receive realistic simulations your existing tools can't produce: conversational AI vishing calls, executive deepfake impersonations, and multi-stage attack chains that move across email, SMS, and voice.
- KSAT receives the outcome. Every Mirage result syncs into the KnowBe4 user timeline, next to your phishing test history, so human risk from the voice channel finally shows up where you already report on it.
- KnowBe4 acts on it. Build smart groups from Mirage risk data, auto-assign remedial training (including modules like Spot the Vish) to people who failed a live call, and track improvement across campaigns.
- Training closes the gap. For employees without reachable phones (or teams that need reps, not just tests), Mirage's Adaptive Training puts a simulated call in the browser with personalized coaching afterward.
At a glance:
| KnowBe4 native | With Mirage augmentation | |
|---|---|---|
| Voice calls | Automated VST templates; keypad-entry fail condition | Live conversational AI calls that adapt mid-conversation |
| Callback phishing | AIDA-generated email templates | Full email-to-phone attack chains with a live voice on the line |
| Impersonation | Generic scenarios | Deepfake voice impersonation of your own executives |
| Channels | Phone tests + email phishing tests | Coordinated email, SMS, and voice campaigns in one pretext |
| Reporting | KSAT user timeline, smart groups, training assignment | Same: Mirage outcomes sync into the exact same timeline and groups |
Nothing gets replaced. KnowBe4 stays your system of record for human risk and training; Mirage makes the voice-channel data flowing into it reflect the live, conversational attacks driving today's incidents. For where voice simulation fits in a broader program, see our AI social engineering strategy guide.
Setting Up the Integration
Existing KnowBe4 customers can enable Mirage in minutes: generate an API key in your KSAT admin console and enter it in Mirage, following the KnowBe4 integration documentation. From that point, Mirage events flow into user timelines automatically. Mirage customers with questions can reach us through their dedicated Slack channel.
Frequently Asked Questions
Does KnowBe4 make live AI voice calls?
No. KnowBe4's Vishing Security Test places automated, template-based calls, and its fail condition is keypad data entry. Live, conversational AI vishing calls come from Mirage and sync back into KSAT through the integration.
Do I need to replace KnowBe4 to run realistic vishing simulations?
No. That's the point of the integration. KSAT remains your training and reporting platform; Mirage adds the attack realism and feeds results in.
Can Mirage results trigger KnowBe4 training automatically?
Yes. Mirage outcomes appear in the KSAT user timeline and can drive smart groups, which lets you auto-enroll employees who failed a live vishing call into targeted remedial training.
What attacks does Mirage add on top of KnowBe4?
Live conversational vishing that adapts to what the employee says, deepfake voice impersonation of your actual executives, and multi-channel campaigns that chain email, SMS, and voice into one pretext.
Hear the Difference Yourself
The fastest way to understand the gap between an automated vishing test and a live AI social engineer is to take the call.