Vishing Awareness: Canada’s IT Help Desks Under Attack

Office workers using computers in a modern workspace, representing IT help desk staff targeted by voice phishing

The phone rings at a Canadian IT help desk. The caller identifies themselves as someone from the security team, explains that an account is about to be locked out, and asks the agent to quickly reset the user’s MFA credentials. The call is convincing, the urgency feels real, and the agent has been trained to be helpful. This is vishing, and the Canadian Centre for Cyber Security has issued a direct advisory warning that it is one of the most effective techniques attackers are currently using to compromise Canadian organisations. For anyone responsible for the human layer of your cybersecurity program, this advisory demands immediate attention.

Voice phishing has overtaken email as an attack vector

According to Mandiant’s M-Trends 2026 report, voice phishing rose to 11 percent of all confirmed initial access vectors in 2025, making it the second most common way attackers gain entry to an organisation. Email phishing, by contrast, fell to just 6 percent as automated filtering improved. In cloud-hosted environments, vishing accounts for 23 percent of initial compromises.

The CCCS advisory AL26-010, published April 30, 2026, describes the technique precisely. Attackers contact help desk staff by phone, impersonating internal IT employees, identity providers, or trusted software vendors. They manufacture urgency, claiming that an MFA token is about to expire or that an account is under active investigation, then guide the agent through steps that hand over credentials or trigger a password reset. The victim never visits a suspicious link. The attacker never needs an exploit. All that is required is a cooperative person on the other end of the call.

Why IT help desks became the primary target

On July 26, 2026, the Genesis ransomware group publicly claimed Canadian IT services firm Servonix Technologies Inc. as its latest victim, threatening to publish sensitive company data unless negotiations began. While the exact method of initial compromise was not publicly disclosed, the attack fits a pattern that Mandiant’s M-Trends 2026 data makes concrete: the window between initial access and handoff to a ransomware partner has collapsed to 22 seconds in 2025, down from more than eight hours in 2022. An agent who complies with a vishing request may trigger a chain of events that ends in ransomware deployment before anyone on the security team receives a single alert.

The CCCS advisory also highlights a detail that changes the calculus for most security teams: post-compromise activity in these campaigns frequently skips malware deployment entirely, moving directly to data exfiltration and extortion. Endpoint detection and response tools, the primary defence layer in most Canadian organisations, cannot intercept an attack that never touches an endpoint.

In our work running phishing simulations across Canadian organizations, we consistently see click rates that drop fast in the first quarter of a program and then plateau. The rise of voice phishing explains part of that plateau: as employees improve at recognising suspicious emails, attackers move to the phone, and most awareness programs have not yet made that same shift.

What your organisation should do this week

The CCCS AL26-010 advisory recommends three immediate controls: deploy phishing-resistant MFA (hardware-based FIDO2 keys where feasible), establish a strict out-of-band verification protocol requiring a callback to the employee’s registered phone number before any credential change is processed, and train help desk staff specifically on social engineering impersonation scenarios. Running vishing simulations that test real readiness, not only email-based tests, is the most direct way to measure whether your team actually recognises and refuses these calls under realistic pressure.

The release of AL26-010 is an opportunity to close a gap that most security programs have left open. Review your help desk verification protocol this week. Every credential modification should require a logged support ticket, a manager co-authorisation, and a live callback to the employee’s registered number. These are not bureaucratic obstacles; they are the controls standing between a caller with a convincing script and full access to your organisation’s cloud environment.

Sources