STEALTHNET AI
CONFIDENTIAL
Assessment Report
Vishing Assessment
Report
Voice-based social engineering assessment and campaign review
Voice Phishing
Call Campaign Review
Social Engineering Simulation
CONFIDENTIAL
Confidentiality Notice
Please read before sharing or distributing this document.
CONFIDENTIAL
This report contains proprietary and confidential information intended solely for the authorized recipient.
Any review, use, disclosure, distribution, or copying by persons other than the intended recipient is strictly
prohibited.
The observations in this report reflect the voice-phishing scenarios, user responses, and campaign conditions
present during the assessment window. Follow-on remediation, awareness, and procedural decisions should be
reviewed by qualified stakeholders.
By accessing this document, you agree to protect its confidentiality and to limit access to individuals with a
legitimate business need.
Classification
Confidential
Distribution
Need-to-know only
This document is intended to help leadership and operational stakeholders understand user susceptibility,
scenario performance, and the call-handling improvements that should be prioritized next.
Contents
Table of Contents
Cover
Confidentiality
Table of Contents
Executive Security Assessment
Campaign Breakdown
Executive Summary
Methodology
Findings Overview — 20 targeted users
Detailed Findings
Jordan Blake · Password Reset · Failed
Elena Ruiz · Credential Sync (Compliance Audit) · Passed
Marcus Webb · Software Update · Failed
Executive Security Assessment
Acme Corporation | Vishing (Voice Phishing) Simulation | ID #1312
Aug 25, 2026
GRADE D
Risk score: 45 / 100
High risk. A majority of targeted users disclosed credentials or sensitive access. Targeted awareness and
call-handling improvements are recommended.
StealthNet AIVoice PhishingCampaign Analysis
Targeted Users
20
Users included in the approved voice-phishing campaign scope.
Call Attempts
20
Vishing calls initiated during the assessment period.
Failed Users
11
Users who followed the malicious pretext or otherwise failed the simulation controls.
Passed Users
9
Users who handled the call appropriately or resisted the malicious scenario.
Campaign Outcome Snapshot
11 failed | 9 passed | 0 ongoing | 0 no answer
The assessment team observed a 55% failure rate across the targeted user population. Credential-harvesting
pretexts (Password Reset and Credential Sync for Compliance Audit) drove the highest susceptibility.
Follow-up awareness should prioritize identity-verification behavior and the scenarios that produced the
highest failure rates.
Departments in scope: Finance, IT, Sales, Support, Engineering, Marketing, HR, Legal, Compliance, Operations,
Facilities.
Campaign Breakdown
Scenarios & voices
How each pretext and each configured AI voice performed across the 20-user campaign, ranked by
susceptibility and volume.
Scenarios by Failure Rate
Ranked by how often each pretext led to a failed outcome.
Password Reset80%
4 failed of 5 users
Credential Sync (Compliance Audit)75%
3 failed of 4 users
Software Update50%
2 failed of 4 users
Badge Access Sync (Facilities)33%
1 failed of 3 users
Digital Wellness Check-In (HR)25%
1 failed of 4 users
Voice Usage Overview
Configured voice profiles ranked by campaign volume, with failure rate shown beneath each.
Tyler (english)9
56% fail rate | 5 failed of 9 calls
Beth (english)4
50% fail rate | 2 failed of 4 calls
Jessica (english)3
67% fail rate | 2 failed of 3 calls
Olivia (english, British)3
33% fail rate | 1 failed of 3 calls
Diego (spanish)1
100% fail rate | 1 failed of 1 call
Voice profile note: this campaign was run primarily on the Tyler voice, StealthNet's current default
English profile. Older campaigns that used the retired "Mike" profile are not reflected here.
Leadership Summary
Executive Summary
This section summarizes the vishing campaign results in narrative form for leadership and stakeholder
review.
The assessment team reviewed user call outcomes, scenario effectiveness, and the control gaps that merit
follow-up awareness or process improvements.
The vishing simulation engaged 20 call attempt(s) across 20 targeted user(s) spanning 11 departments, using
five pretext scenarios and a mix of configured AI voices.
11 user(s) failed the simulation while 9 user(s) handled the call appropriately, resulting in an observed
failure rate of 55%. The highest-risk behavior was verbal disclosure of credentials or sensitive access
without independent verification of the caller's identity.
Credential-harvesting pretexts were the most effective: the Password Reset scenario failed 4
of 5 users (80%) and Credential Sync for Compliance Audit failed 3 of 4 (75%). Wellness- and
facilities-themed pretexts were resisted more often, but still produced failures, indicating susceptibility is
broad rather than isolated to IT-themed calls.
The assessment team recommends targeted follow-up training focused on a single, enforceable behavior —
never share credentials by phone and always verify the caller through an independent, known channel —
reinforced for the departments and scenarios that produced the highest failure rates.
Assessment Process
Methodology
This section explains how we conduct a vishing engagement from campaign design and call execution through
outcome analysis and reporting.
We use a staged methodology so the assessment team can simulate realistic voice-based social engineering,
measure susceptibility, and deliver practical guidance.
We begin each vishing assessment by confirming the approved scope, defining the target population, and
selecting the pretexts that best reflect the operational risks faced by the organization. The assessment team
reviews campaign objectives, employee roles, and acceptable testing boundaries so the engagement measures
realistic voice-based social engineering exposure without exceeding the agreed rules of engagement.
Once the campaign design is set, we prepare the call workflows, AI voice selections, and scenario logic that
will be used during execution. Calls are structured to simulate realistic attacker behavior while maintaining
safety controls, consistent scripting boundaries, and repeatable measurement criteria across the target group.
During execution, we capture call outcomes, employee responses, and indicators of whether the pretext
succeeded, failed, or was interrupted. The assessment team reviews those outcomes to identify which scenarios
were most effective, which behaviors increased risk, and where controls such as verification procedures or
escalation paths broke down.
After the calls are completed, we analyze the results, calculate the engagement metrics, and translate those
observations into reporting for leadership and technical stakeholders. The goal is to provide a defensible
picture of user susceptibility, campaign performance, and the training or procedural improvements that should
be prioritized next.
Findings Overview
Per-user results — 20 targeted users
Each targeted user, the scenario and AI voice used, and the outcome. Detailed write-ups for representative
pass and fail cases follow.
| # |
Employee |
Department |
Scenario |
Voice |
Outcome |
Grade |
| 1 |
Jordan Blake |
Finance |
Password Reset |
Tyler |
Failed |
F |
| 2 |
Derek Malone |
Sales |
Password Reset |
Tyler |
Failed |
F |
| 3 |
Aisha Rahman |
Support |
Password Reset |
Beth |
Failed |
F |
| 4 |
Kevin Ortiz |
IT |
Password Reset |
Tyler |
Passed |
A |
| 5 |
Sam Whitfield |
Operations |
Password Reset |
Jessica |
Failed |
F |
| 6 |
Marcus Webb |
Engineering |
Software Update |
Jessica |
Failed |
F |
| 7 |
Nina Kapoor |
Marketing |
Software Update |
Olivia |
Failed |
D |
| 8 |
Tom Bishop |
IT |
Software Update |
Tyler |
Passed |
A |
| 9 |
Rachel Kim |
Finance |
Software Update |
Beth |
Passed |
B |
| 10 |
Carlos Mendez |
Legal |
Credential Sync (Compliance Audit) |
Diego |
Failed |
F |
| 11 |
Priya Nair |
HR |
Credential Sync (Compliance Audit) |
Tyler |
Failed |
F |
| 12 |
Elena Ruiz |
Compliance |
Credential Sync (Compliance Audit) |
Beth |
Passed |
A |
| 13 |
Greg Sanders |
Finance |
Credential Sync (Compliance Audit) |
Tyler |
Failed |
D |
| 14 |
Hannah Lee |
HR |
Digital Wellness Check-In |
Olivia |
Passed |
A |
| 15 |
Omar Farouk |
Support |
Digital Wellness Check-In |
Tyler |
Failed |
F |
| 16 |
Beatriz Gomez |
Sales |
Digital Wellness Check-In |
Jessica |
Passed |
B |
| 17 |
Liam Novak |
Engineering |
Digital Wellness Check-In |
Tyler |
Passed |
A |
| 18 |
Chloe Adams |
Facilities |
Badge Access Sync |
Beth |
Failed |
F |
| 19 |
Victor Hsu |
IT |
Badge Access Sync |
Tyler |
Passed |
A |
| 20 |
Dana Kowalski |
Operations |
Badge Access Sync |
Olivia |
Passed |
B |
Detailed Findings · representative examples (3 of 20)
Representative sample — a full report includes a detailed finding for every targeted user. To keep this
example readable, the write-ups below cover 3 of the 20 users (one pass and two fails across different
scenarios). Each detailed finding follows the same structure StealthNet produces for every targeted user.
1. Jordan Blake · Finance
Failed · Grade F
Scenario: Password Reset
Voice: Tyler
Channel: Voice call (vishing)
Details
This simulated vishing engagement targeted Jordan via a phone call from an attacker impersonating internal
IT. The caller opened with authority and manufactured urgency around "suspicious activity" on the account,
then framed a credential check as a routine, sanctioned security process affecting "all accounts."
Using a stepwise approach — a low-friction identity check escalating to a credential request — the caller
pressured Jordan into disclosing account credentials, including a weak password, before closing with false
reassurance that the account had been secured. The credentials were compromised.
Why Jordan fell for the call
-
Authority and legitimacy cues: The caller claimed to be from the IT security team,
leveraging internal authority; references to "all accounts" made the scenario sound organizationally
sanctioned.
-
Urgency and fear of compromise: "flagged due to some suspicious activity" and "unusual
login attempts" created pressure to act quickly and comply.
-
Plausible process framing: "verifying credentials and resetting passwords" sounded routine,
reducing scrutiny.
-
Commitment and consistency: After agreeing to help, Jordan was more likely to follow
through with each subsequent request.
- Social smoothing: The caller's polite tone and reassurances lowered Jordan's guard.
What Jordan did wrong
-
Disclosed credentials over the phone: Providing a password verbally is a critical violation
— legitimate IT never asks for a password.
-
Failed to verify caller identity: Accepted the caller's claimed identity without
independent verification via the official help desk or an internal ticket.
-
Bypassed established procedures: A genuine reset should occur through approved self-service
portals, never by sharing the actual password.
- Ignored red flags: Caller hesitations and minor inconsistencies went unchallenged.
-
Weak password hygiene: The disclosed password was trivial and highly insecure, compounding
the risk had this been a real compromise.
What Jordan should have done
-
Refuse to share credentials: State clearly that passwords are not shared and that IT will
never ask for them.
-
Independently verify the request: End the call and contact the IT help desk using a known
official number; ask for a ticket number and confirm it in the ticketing system.
-
Use approved reset mechanisms: Initiate any real reset via the sanctioned self-service
portal or verified IT support, never an unsolicited phone instruction.
-
Report the incident: Alert the security team with the caller's number, time, and details
for awareness and potential call-blocking.
-
Strengthen authentication: Use strong, unique passwords and ensure MFA is enabled to reduce
impact even if credentials are exposed.
Observed tactics
-
Authority pretext: Impersonated the internal IT security team to borrow organizational
trust.
-
Urgency and scope: Cited "suspicious activity" and account-wide "unusual login attempts"
to pressure fast compliance.
-
Process framing: Presented the credential check as a routine, sanctioned reset procedure.
-
Stepwise elicitation: Escalated from a low-friction identity check to a full credential
request.
-
Outcome: Credentials disclosed; account compromised. (Full verbatim transcript available
in the delivered report.)
Location
Communication channel: Voice phone call (vishing)
Target phone number: +1 (415) 555-0142
Asset at risk: User credentials (username and password) disclosed verbally
2. Elena Ruiz · Compliance
Passed · Grade A
Scenario: Credential Sync for Compliance Audit
Voice: Beth
Channel: Voice call (vishing)
Details
This engagement targeted Elena with a compliance-themed pretext. The caller claimed to be from an "IT
Compliance Team" running a routine internal audit and applied a soft deadline to "close the audit window
today," asking Elena to confirm her username and password so her account could be "synced."
Elena declined to provide any credentials on the call, stating that IT never asks for passwords. She asked
for a ticket number, received a vague answer, ended the call, and independently contacted the internal help
desk — where no such audit existed — then reported the attempt to the security team the same day.
Why Elena resisted
-
Held the line on credentials: Recognized that no legitimate process requires disclosing a
password by phone.
-
Independent verification: Refused to act on the caller's channel and re-contacted IT
through a known, trusted number.
-
Read the manipulation: Treated the "audit deadline" as a pressure tactic rather than a
reason to comply.
-
Escalation: Reported promptly, giving the security team an early signal of an active
campaign.
What Elena did right
-
Refused credential disclosure: Did not confirm a username or password despite repeated
prompting.
-
Requested and checked a ticket: Asked for a verifiable reference and did not accept the
vague response.
-
Used a known channel: Called the official help desk directly instead of any number the
caller supplied.
- Reported the incident: Notified security the same day with the caller details.
Reinforce across the org
-
Elena's behavior is the target standard: decline, verify independently, report. Use this
call as a positive example in awareness training.
Observed tactics & response
-
Pretext: Impersonated an "IT Compliance Team" running an audit that required credential
"syncing."
- Pressure: Applied an artificial audit deadline to encourage fast compliance.
-
Elena's challenge: Requested a verifiable ticket number and offered to call the help desk
back independently.
-
Elena's refusal: Declined to share any credentials by phone. Attempt contained and
reported.
Location
Communication channel: Voice phone call (vishing)
Target phone number: +1 (628) 555-0117
Asset at risk: None — no credentials disclosed; attempt contained and reported
3. Marcus Webb · Engineering
Failed · Grade F
Scenario: Software Update
Voice: Jessica
Channel: Voice call (vishing)
Details
The caller posed as IT rolling out a "mandatory security update," telling Marcus his workstation needed to
be re-authenticated before the patch could be applied. Under an end-of-day deadline, the caller asked Marcus
to confirm his username and a "temporary password" so the update could be applied remotely.
Marcus disclosed both, believing it was required to stay compliant. The credentials were compromised under
the cover of routine IT maintenance.
Why Marcus fell for the call
-
Legitimacy of routine IT work: Software updates are normal and expected, so the pretext
raised little suspicion.
-
Manufactured deadline: "before end of day" pressured a fast decision over a careful one.
-
"Temporary credential" confusion: The framing made credential disclosure feel procedural
rather than dangerous.
-
Authority assumption: Marcus assumed anyone calling about patching was authorized to ask.
What Marcus did wrong
-
Confirmed a password to enable an update: Real patching never requires a user's credentials
over the phone.
-
Did not verify the "mandatory update": Took the caller's word instead of checking the
internal IT portal.
- Acted under time pressure: Let an artificial deadline override normal caution.
-
Did not report the call: The attempt went unflagged, delaying awareness across the team.
What Marcus should have done
-
Never confirm a password for an update: Decline any request that ties patching to
credential disclosure.
-
Verify through the IT portal: Confirm any "mandatory update" via the known internal portal
or help-desk number before acting.
-
Slow down under pressure: Treat an urgent deadline as a reason to verify, not to comply
faster.
-
Report the unsolicited call: Especially any that combine urgency with a credential request.
Observed tactics
-
Pretext: Impersonated IT pushing a "mandatory security update" requiring
re-authentication.
- Urgency: Imposed an end-of-day deadline to rush the decision.
-
Credential request: Framed a username + "temporary password" as required to apply the
update remotely.
-
Outcome: Credentials disclosed; account compromised. (Full verbatim transcript available
in the delivered report.)
Location
Communication channel: Voice phone call (vishing)
Target phone number: +1 (415) 555-0186
Asset at risk: User credentials (username and password) disclosed verbally