Security leaders are facing a critical vulnerability as social engineering shifts from the inbox to the telephone. KnowBe4 is addressing this growing exposure by launching a simulated vishing capability designed to train employees against voice-based attacks. This move comes as organizations struggle to defend against sophisticated phone-based deception. By integrating voice simulations into its existing security awareness framework, the company aims to provide a unified defense mechanism that covers both human employees and AI agents, targeting a communication channel that has seen significant increases in malicious activity.
Rapid Growth in Voice-Based Social Engineering
The strategic pivot toward voice-based simulation follows a documented surge in telephony-based threats. According to CrowdStrike's 2025 Global Threat Report, vishing activity increased by 442% between the first and second halves of 2024. Furthermore, Mandiant's M-Trends 2026 Report now classifies voice phishing among the primary initial infection vectors for modern organizations. The difficulty of defending this channel is underscored by the 2026 Verizon Data Breach Investigations Report, which indicates that employees are 40% more likely to succumb to phone-based simulation tests than traditional email phishing attempts. KnowBe4 is positioning this new capability to bridge this specific gap in security awareness. The company's chief product officer, Greg Kras, noted that cybercriminals are increasingly utilizing AI voice cloning to create high-pressure, convincing scenarios that mimic IT departments or executive leadership, necessitating a shift in training focus beyond the email inbox.
Integrating Vishing into the KnowBe4 Platform
This new capability is being deployed within the attack and simulation pillar of the KnowBe4 Platform. Rather than operating as a standalone tool, the simulated vishing results are designed to feed directly into the company's existing reporting and risk visibility infrastructure. This integration allows vishing susceptibility data to influence the proprietary Risk Score™, which provides a unified view of risk across multiple channels for both humans and AI agents. The simulation features are built to mirror actual attacker methodologies, including the use of local caller ID, realistic personas, and multi-step customizable scenarios. By simulating these adaptive, patient conversations, the platform intends to move training away from generic scripts toward the complex, legitimate-feeling interactions that characterize modern breaches. This approach allows security teams to gather data-driven insights into how their workforce responds to high-pressure verbal prompts, ensuring that voice-based risk is quantified alongside traditional phishing metrics.
Key Takeaways
- Vishing activity saw a 442% increase between the first and second halves of 2024, according to CrowdStrike.
- Employees are 40% more likely to fail phone-based simulation tests compared to email phishing, per Verizon's 2026 report.
- Simulated vishing results integrate directly into the KnowBe4 Risk Score™ to provide unified visibility across human and AI risk.
TechInsyte's Take
In our view, KnowBe4’s move into simulated vishing is a necessary response to the weaponization of AI in social engineering. As voice cloning technology matures, the "human firewall" becomes significantly more porous, as evidenced by the 40% higher failure rate in phone-based testing. By linking these results to a centralized Risk Score, KnowBe4 is attempting to solve a major visibility problem for CISOs: the fragmentation of threat data across different communication vectors. This signals a broader industry trend where security awareness must evolve from static, text-based training to dynamic, multi-modal simulations to remain effective against adaptive, AI-driven attackers.
Questions & Answers
How does the new vishing capability impact existing security reporting?
The simulation results are integrated into the KnowBe4 Platform's existing reporting structure, specifically influencing the Risk Score™. This allows security leaders to view voice-based susceptibility alongside traditional phishing data in a single, unified dashboard.
What specific attacker tactics does the simulation attempt to replicate?
The capability uses realistic personas, local caller ID, and multi-step customizable scenarios. These features are designed to mirror the "patient, adaptive conversations" that modern attackers use to establish legitimacy during a call.
Why is the phone channel considered a high-risk vector for enterprises?
Data from Mandiant and Verizon suggests the phone channel is a top initial infection vector where employees are significantly more vulnerable. Specifically, employees are 40% more likely to fall for phone-based simulations than email-based ones.
Does this training apply to AI agents within the organization?
Yes, the KnowBe4 Platform is designed to secure both humans and AI agents, and the new vishing capability is part of an attack and simulation pillar aimed at protecting both entities.
Source: Businesswire