**Context** For years, organisations have invested heavily in email security awareness, teaching employees to identify phishing emails and avoid clicking suspicious links. While these campaigns have improved resilience against traditional phishing, attackers have adapted. Increasingly, they are targeting the one communication channel that has received far less attention: the telephone. Recent high-profile breaches across multiple industries have demonstrated that a single convincing phone call can bypass technical controls, undermine established processes, and provide a direct route into an organisation. **Problem** Helpdesks, service desks and support teams are under constant pressure to deliver a positive customer experience while resolving issues quickly. Skilled social engineers exploit this environment by combining publicly available information, psychological manipulation and increasingly sophisticated AI technologies to create highly believable scenarios. Even organisations with strong identity controls, including multi-factor authentication and phishing-resistant authentication methods, remain vulnerable when employees are persuaded to override or circumvent their own security processes. **Methodology** Drawing on real-world red team engagements, this session breaks down the modern vishing attack lifecycle from reconnaissance and pretext development through to telephone engagement and account compromise. Using practical examples and a live AI voice cloning demonstration, the talk illustrates how attackers build credibility, manipulate conversations and exploit human decision-making. It also explores the ethical considerations involved in realistic social engineering exercises and explains how these engagements can be conducted safely and responsibly. **Results** Attendees will leave with a clear understanding of how modern vishing attacks succeed, considerations when planning and delivering vishing simulations, and some of the gotchas that have got my team caught! The audience will gain actionable insights they can apply when delivering vishing engagements, either standalone or as part of a wider red team.