STEALTHNET AI
CONFIDENTIAL
Assessment Report

Vishing Assessment
Report

Voice-based social engineering assessment and campaign review

Prepared for
Acme Corporation
Date
Aug 25, 2026
Voice Phishing Call Campaign Review Social Engineering Simulation
Confidential vishing assessment material intended only for authorized recipients.
CONFIDENTIAL
Confidentiality Notice

Please read before sharing or distributing this document.

CONFIDENTIAL

This report contains proprietary and confidential information intended solely for the authorized recipient. Any review, use, disclosure, distribution, or copying by persons other than the intended recipient is strictly prohibited.

The observations in this report reflect the voice-phishing scenarios, user responses, and campaign conditions present during the assessment window. Follow-on remediation, awareness, and procedural decisions should be reviewed by qualified stakeholders.

By accessing this document, you agree to protect its confidentiality and to limit access to individuals with a legitimate business need.

Classification
Confidential
Generated
Aug 25, 2026
Distribution
Need-to-know only
This document is intended to help leadership and operational stakeholders understand user susceptibility, scenario performance, and the call-handling improvements that should be prioritized next.
StealthNet AI · Vishing AssessmentConfidential
Contents

Table of Contents

Cover
Confidentiality
Table of Contents
Executive Security Assessment
Campaign Breakdown
Executive Summary
Methodology
Findings Overview — 20 targeted users
Detailed Findings
Jordan Blake · Password Reset · Failed
Elena Ruiz · Credential Sync (Compliance Audit) · Passed
Marcus Webb · Software Update · Failed
StealthNet AI · Vishing AssessmentConfidential

Executive Security Assessment

Acme Corporation  |  Vishing (Voice Phishing) Simulation  |  ID #1312
Aug 25, 2026
GRADE D
Risk score: 45 / 100
High risk. A majority of targeted users disclosed credentials or sensitive access. Targeted awareness and call-handling improvements are recommended.
StealthNet AIVoice PhishingCampaign Analysis
Targeted Users
20
Users included in the approved voice-phishing campaign scope.
Call Attempts
20
Vishing calls initiated during the assessment period.
Failed Users
11
Users who followed the malicious pretext or otherwise failed the simulation controls.
Passed Users
9
Users who handled the call appropriately or resisted the malicious scenario.
Campaign Outcome Snapshot
11 failed  |  9 passed  |  0 ongoing  |  0 no answer

The assessment team observed a 55% failure rate across the targeted user population. Credential-harvesting pretexts (Password Reset and Credential Sync for Compliance Audit) drove the highest susceptibility. Follow-up awareness should prioritize identity-verification behavior and the scenarios that produced the highest failure rates.

Departments in scope: Finance, IT, Sales, Support, Engineering, Marketing, HR, Legal, Compliance, Operations, Facilities.
StealthNet AI · Vishing AssessmentConfidential
Campaign Breakdown

Scenarios & voices

How each pretext and each configured AI voice performed across the 20-user campaign, ranked by susceptibility and volume.
Scenarios by Failure Rate
Ranked by how often each pretext led to a failed outcome.
Password Reset80%
4 failed of 5 users
Credential Sync (Compliance Audit)75%
3 failed of 4 users
Software Update50%
2 failed of 4 users
Badge Access Sync (Facilities)33%
1 failed of 3 users
Digital Wellness Check-In (HR)25%
1 failed of 4 users
Voice Usage Overview
Configured voice profiles ranked by campaign volume, with failure rate shown beneath each.
Tyler (english)9
56% fail rate | 5 failed of 9 calls
Beth (english)4
50% fail rate | 2 failed of 4 calls
Jessica (english)3
67% fail rate | 2 failed of 3 calls
Olivia (english, British)3
33% fail rate | 1 failed of 3 calls
Diego (spanish)1
100% fail rate | 1 failed of 1 call
Voice profile note: this campaign was run primarily on the Tyler voice, StealthNet's current default English profile. Older campaigns that used the retired "Mike" profile are not reflected here.
StealthNet AI · Vishing AssessmentConfidential
Leadership Summary

Executive Summary

This section summarizes the vishing campaign results in narrative form for leadership and stakeholder review.
The assessment team reviewed user call outcomes, scenario effectiveness, and the control gaps that merit follow-up awareness or process improvements.

The vishing simulation engaged 20 call attempt(s) across 20 targeted user(s) spanning 11 departments, using five pretext scenarios and a mix of configured AI voices.

11 user(s) failed the simulation while 9 user(s) handled the call appropriately, resulting in an observed failure rate of 55%. The highest-risk behavior was verbal disclosure of credentials or sensitive access without independent verification of the caller's identity.

Credential-harvesting pretexts were the most effective: the Password Reset scenario failed 4 of 5 users (80%) and Credential Sync for Compliance Audit failed 3 of 4 (75%). Wellness- and facilities-themed pretexts were resisted more often, but still produced failures, indicating susceptibility is broad rather than isolated to IT-themed calls.

The assessment team recommends targeted follow-up training focused on a single, enforceable behavior — never share credentials by phone and always verify the caller through an independent, known channel — reinforced for the departments and scenarios that produced the highest failure rates.

StealthNet AI · Vishing AssessmentConfidential
Assessment Process

Methodology

This section explains how we conduct a vishing engagement from campaign design and call execution through outcome analysis and reporting.
We use a staged methodology so the assessment team can simulate realistic voice-based social engineering, measure susceptibility, and deliver practical guidance.

We begin each vishing assessment by confirming the approved scope, defining the target population, and selecting the pretexts that best reflect the operational risks faced by the organization. The assessment team reviews campaign objectives, employee roles, and acceptable testing boundaries so the engagement measures realistic voice-based social engineering exposure without exceeding the agreed rules of engagement.

Once the campaign design is set, we prepare the call workflows, AI voice selections, and scenario logic that will be used during execution. Calls are structured to simulate realistic attacker behavior while maintaining safety controls, consistent scripting boundaries, and repeatable measurement criteria across the target group.

During execution, we capture call outcomes, employee responses, and indicators of whether the pretext succeeded, failed, or was interrupted. The assessment team reviews those outcomes to identify which scenarios were most effective, which behaviors increased risk, and where controls such as verification procedures or escalation paths broke down.

After the calls are completed, we analyze the results, calculate the engagement metrics, and translate those observations into reporting for leadership and technical stakeholders. The goal is to provide a defensible picture of user susceptibility, campaign performance, and the training or procedural improvements that should be prioritized next.

StealthNet AI · Vishing AssessmentConfidential
Findings Overview

Per-user results — 20 targeted users

Each targeted user, the scenario and AI voice used, and the outcome. Detailed write-ups for representative pass and fail cases follow.
# Employee Department Scenario Voice Outcome Grade
1 Jordan Blake Finance Password Reset Tyler Failed F
2 Derek Malone Sales Password Reset Tyler Failed F
3 Aisha Rahman Support Password Reset Beth Failed F
4 Kevin Ortiz IT Password Reset Tyler Passed A
5 Sam Whitfield Operations Password Reset Jessica Failed F
6 Marcus Webb Engineering Software Update Jessica Failed F
7 Nina Kapoor Marketing Software Update Olivia Failed D
8 Tom Bishop IT Software Update Tyler Passed A
9 Rachel Kim Finance Software Update Beth Passed B
10 Carlos Mendez Legal Credential Sync (Compliance Audit) Diego Failed F
11 Priya Nair HR Credential Sync (Compliance Audit) Tyler Failed F
12 Elena Ruiz Compliance Credential Sync (Compliance Audit) Beth Passed A
13 Greg Sanders Finance Credential Sync (Compliance Audit) Tyler Failed D
14 Hannah Lee HR Digital Wellness Check-In Olivia Passed A
15 Omar Farouk Support Digital Wellness Check-In Tyler Failed F
16 Beatriz Gomez Sales Digital Wellness Check-In Jessica Passed B
17 Liam Novak Engineering Digital Wellness Check-In Tyler Passed A
18 Chloe Adams Facilities Badge Access Sync Beth Failed F
19 Victor Hsu IT Badge Access Sync Tyler Passed A
20 Dana Kowalski Operations Badge Access Sync Olivia Passed B
StealthNet AI · Vishing AssessmentConfidential
Detailed Findings · representative examples (3 of 20)
Representative sample — a full report includes a detailed finding for every targeted user. To keep this example readable, the write-ups below cover 3 of the 20 users (one pass and two fails across different scenarios). Each detailed finding follows the same structure StealthNet produces for every targeted user.

1. Jordan Blake · Finance

Failed · Grade F Scenario: Password Reset Voice: Tyler Channel: Voice call (vishing)
Details

This simulated vishing engagement targeted Jordan via a phone call from an attacker impersonating internal IT. The caller opened with authority and manufactured urgency around "suspicious activity" on the account, then framed a credential check as a routine, sanctioned security process affecting "all accounts."

Using a stepwise approach — a low-friction identity check escalating to a credential request — the caller pressured Jordan into disclosing account credentials, including a weak password, before closing with false reassurance that the account had been secured. The credentials were compromised.

Why Jordan fell for the call

What Jordan did wrong

What Jordan should have done

Observed tactics
  • Authority pretext: Impersonated the internal IT security team to borrow organizational trust.
  • Urgency and scope: Cited "suspicious activity" and account-wide "unusual login attempts" to pressure fast compliance.
  • Process framing: Presented the credential check as a routine, sanctioned reset procedure.
  • Stepwise elicitation: Escalated from a low-friction identity check to a full credential request.
  • Outcome: Credentials disclosed; account compromised. (Full verbatim transcript available in the delivered report.)
Location
Communication channel: Voice phone call (vishing)
Target phone number: +1 (415) 555-0142
Asset at risk: User credentials (username and password) disclosed verbally
StealthNet AI · Vishing AssessmentConfidential

2. Elena Ruiz · Compliance

Passed · Grade A Scenario: Credential Sync for Compliance Audit Voice: Beth Channel: Voice call (vishing)
Details

This engagement targeted Elena with a compliance-themed pretext. The caller claimed to be from an "IT Compliance Team" running a routine internal audit and applied a soft deadline to "close the audit window today," asking Elena to confirm her username and password so her account could be "synced."

Elena declined to provide any credentials on the call, stating that IT never asks for passwords. She asked for a ticket number, received a vague answer, ended the call, and independently contacted the internal help desk — where no such audit existed — then reported the attempt to the security team the same day.

Why Elena resisted

What Elena did right

Reinforce across the org

Observed tactics & response
  • Pretext: Impersonated an "IT Compliance Team" running an audit that required credential "syncing."
  • Pressure: Applied an artificial audit deadline to encourage fast compliance.
  • Elena's challenge: Requested a verifiable ticket number and offered to call the help desk back independently.
  • Elena's refusal: Declined to share any credentials by phone. Attempt contained and reported.
Location
Communication channel: Voice phone call (vishing)
Target phone number: +1 (628) 555-0117
Asset at risk: None — no credentials disclosed; attempt contained and reported
StealthNet AI · Vishing AssessmentConfidential

3. Marcus Webb · Engineering

Failed · Grade F Scenario: Software Update Voice: Jessica Channel: Voice call (vishing)
Details

The caller posed as IT rolling out a "mandatory security update," telling Marcus his workstation needed to be re-authenticated before the patch could be applied. Under an end-of-day deadline, the caller asked Marcus to confirm his username and a "temporary password" so the update could be applied remotely.

Marcus disclosed both, believing it was required to stay compliant. The credentials were compromised under the cover of routine IT maintenance.

Why Marcus fell for the call

What Marcus did wrong

What Marcus should have done

Observed tactics
  • Pretext: Impersonated IT pushing a "mandatory security update" requiring re-authentication.
  • Urgency: Imposed an end-of-day deadline to rush the decision.
  • Credential request: Framed a username + "temporary password" as required to apply the update remotely.
  • Outcome: Credentials disclosed; account compromised. (Full verbatim transcript available in the delivered report.)
Location
Communication channel: Voice phone call (vishing)
Target phone number: +1 (415) 555-0186
Asset at risk: User credentials (username and password) disclosed verbally
StealthNet AI · Vishing AssessmentConfidential