Purpose

Social engineering remains a major threat to information security, not due to technical skill but by exploiting human behavior. While research has examined user susceptibility and awareness training, less is known about how attackers develop skills in real-world contexts. This study follows a beginner conducting vishing calls in the Austrian healthcare system.

Design/methodology/approach

Using a predefined script and anticipated responses, a novice attacker made 20 phone-based attempts to persuade staff to visit a fake internal web page and read a short code aloud, simulating a minor breach. Over time, the attacker progressed from hesitant reading to confident improvisation, adjusting to feedback in real time.

Findings

Targets were often friendly and unresisting, reinforcing the attacker’s confidence. With practice, the attacker refined their approach quickly, demonstrating how ordinary workplace interactions can serve as inadvertent training grounds.

Research limitations/implications

The study was small, involved a single institution and one attacker, limiting generalizability. Nonetheless, consistent observations offer useful ideas for larger studies and understanding attacker behavior.

Practical implications

High-trust environments like healthcare need not only training but also structural changes encouraging polite skepticism, verification of unexpected requests and active questioning. Everyday norms of helpfulness and trust can unintentionally enable attackers to learn and improve.

Originality/value

While vishing effects on organizations are documented, the attacker’s perspective is rarely studied. Focusing on skill development provides new insight into how quickly attackers improve in real-world settings.

Social engineering is one of the most persistent and adaptable threats in information security. Unlike technical vulnerabilities, which can be patched or addressed systematically, human behavior is unpredictable and depends heavily on context (Hatfield, 2018). Methods such as phishing, pretexting, baiting and vishing exploit common cognitive biases, emotional reactions and organizational blind spots. Research consistently shows that most breaches involve some human factor, highlighting the importance of treating social engineering as a core security issue rather than a secondary concern (Hatfield, 2018; Krombholz et al., 2015).

Within this landscape, vishing (Jones et al., 2021) presents a specific set of challenges. Unlike phishing via email, which has been widely studied (Stembert et al., 2015; Jones et al., 2021), vishing requires real-time interaction, quick thinking and an ability to interpret subtle human signals. Success depends on sounding credible, using authority convincingly and creating a sense of urgency, all while maintaining psychological pressure (Heartfield and Loukas, 2018; Frangopoulos et al., 2010; Altrichter et al., 2002). Rather than relying on static vulnerabilities, vishing plays out as a dynamic exchange where the attacker continuously adapts their language, tone and claims. This makes it especially hard to detect or prevent using technical tools and difficult to reproduce accurately in training scenarios.

Although the effects of vishing on organizations have been explored (Heartfield and Loukas, 2018; Jones et al., 2021), the attacker’s experience has received far less attention. Most research focuses on why people fall for these attacks or how organizational defenses fail (Jones et al., 2021; Kroll, 2023; IBM, 2023), which are important questions. However, the process by which attackers build their skills has been largely overlooked. This is a serious gap, especially given how easy it has become to start using social engineering techniques. With access to online guides, free tools and even artificial intelligence-based resources, people without any technical background can now run convincing attacks after minimal preparation (Schmitt and Flechais, 2024).

This trend is supported by concepts from experiential learning and situated cognition. Rather than acquiring knowledge in the abstract, attackers improve by interacting with real situations, reflecting on the results and making adjustments along the way (Nalla et al., 2022). Much like professionals who refine their abilities through practice, attackers build competence through repetition and feedback from live conversations. If learning curves are short and social responses help reinforce behavior, vishing becomes not just a technical threat but a learning opportunity for the attacker, built into the system itself.

Healthcare organizations are especially vulnerable to this kind of manipulation. Staff are trained to be helpful, responsive and caring. While these qualities are essential in a care setting, they can be turned against employees in vishing attempts. Simultaneously, healthcare institutions manage sensitive personal data and must comply with strict privacy laws such as the GDPR (Kolb, 1984). Yet research shows that following regulations does not always mean behavior is secure in practice (Kroll, 2023; Europol, 2023). High workload, unclear guidelines and a strong focus on patient outcomes may unintentionally lower awareness of security risks among frontline staff (IBM, 2023; Ashfaq et al., 2024).

Vishing incidents in healthcare are rarely reported. This may be due to embarrassment, uncertainty about what happened or simply not realizing that anything suspicious took place (Jones et al., 2021; Åhlfeldt, 2008). As a result, many incidents go unnoticed by both researchers and security teams. This makes it harder to understand the true scale of the threat, to develop countermeasures or to track how attacker methods evolve.

This paper addresses that gap by shifting focus from the target to the attacker. We present the results of a field study in the Austrian healthcare system, where a researcher with no prior social engineering experience carried out a series of vishing calls. By examining how their skills developed, how they adapted to the situation and what responses they encountered, we map out the learning curve of a social engineer operating in a real-world environment.

Although the study was small in scale, it provides new insight into how quickly attacker skills can improve and how ordinary workplace behavior may unintentionally support that development. The project followed strict ethical standards in line with Austrian research guidelines. These results contribute to ongoing discussions about awareness training, adaptive defenses and the psychology behind successful deception.

Ultimately, this study suggests a shift in how the problem is framed. The attacker is not just an outsider trying to get in, but a learner who evolves by interacting with the very systems we aim to protect.

This paper is an expanded and substantially revised version of our previously published conference paper (Nohlberg and Schrefel, 2026). It provides a more detailed examination of the attacker’s call strategies, the relationship between encountered obstacles and the techniques employed, and a comprehensive account of the incident that concluded the experiment, including the attacker’s perspective and the resulting implications.

This section outlines how the study was carried out. Throughout this paper, the term “attacker” refers to the researcher simulating vishing attempts, unless the meaning is clearly otherwise.

The study was designed as a qualitative, exploratory field experiment within a real healthcare setting. The main purpose was to explore how a beginner attacker develops skills when making vishing calls to healthcare employees. Rather than examining how targets behave or how organizations defend themselves, this work focuses on the attacker’s side.

The research draws on theories of situated learning and experiential learning, which emphasize how competence develops through real interaction, reflection and gradual adaptation (Altrichter et al., 2002). The attacker received no formal training in advance. Instead, their skills were expected to grow naturally through repeated experience, mirroring how attackers often begin with minimal preparation and learn from trial and error.

The attacker was a male university student in his mid-20s with limited prior experience in social engineering or psychological manipulation. At the time of the study, he was writing his BSc thesis within a degree program focused on technical information security. This deliberate choice allowed the study to observe how quickly someone without prior experience could become more confident and effective through self-guided practice.

To support the attacker, a fixed script was prepared along with a set of likely responses to common questions. These tools were designed to reduce mental strain during calls and offer basic structure, while still leaving space for improvisation. As the study progressed, the script and answers were updated based on what had happened in earlier calls.

Twenty vishing calls were made to employees at a large public healthcare organization in Austria. The organization was selected because its staff contact details were accessible, it provides public healthcare, and it had agreed to take part in the study. Calls were made during regular business hours using a personal mobile phone. The study lasted for several weeks, allowing for variations in context, timing and caller confidence.

To make the scenario realistic but ethically sound, the attacker tried to persuade the target to visit a fake internal web page. The site was presented as part of an update or internal verification process. Once opened, it showed a browser warning in clear language, stating that the site was not secure and that no personal data should be used.

If the target ignored the warning and continued, they saw a short numeric code and were asked to read it aloud, under the pretext of confirming account access. At no point were they asked to log in or enter any personal information. This mirrors techniques used in real attacks that aim to collect temporary codes or bypass two-step authentication.

A successful call was defined by three steps:

  1. The target agreed to visit the website.

  2. The target ignored the warning.

  3. The target read the displayed code aloud to the attacker.

This setup allowed the study to simulate a realistic social engineering process without gathering any actual data or breaching any systems.

The series of calls was originally planned to continue beyond the twentieth attempt. However, the study was terminated prematurely due to an organizational incident that followed one of the interactions. Importantly, the interruption did not occur because the attacker had reached a point of diminishing returns or because sufficient data had been gathered, but because the reaction inside the organization exceeded what had been anticipated within the ethical risk assessment.

In the call that triggered the incident, the attacker successfully persuaded the employee to access the prepared website and to read the displayed code. Apart from limited, nonsensitive background information volunteered during the conversation, no unusual or confidential data was obtained. From the attacker’s perspective, the interaction appeared comparable to many earlier exchanges and did not signal that it would lead to wider organizational consequences.

Shortly after the call, the contacted employee – who held the role of head nurse – initiated an immediate switch of the department to manual operation. Digital systems were avoided, documentation was performed on paper, and electronic records were not updated during this period. The decision was based on the nurse’s interpretation that the call was meant to inform about a planned IT shutdown. This reaction illustrates how uncertainty, stress, and responsibility can interact in high-stakes environments such as healthcare, where precautionary behavior may be favored over procedural verification (Åhlfeldt, 2008).

The lockdown had tangible operational implications. Manual documentation increased workload, slowed information flow and introduced delays in routine processes. While no patient harm was reported, the situation demonstrated how easily social engineering can indirectly affect service delivery even without data exfiltration or technical compromise. Prior work has emphasized that the impact of social engineering often lies in disruption, confusion and loss of trust rather than purely in stolen credentials (Hatfield, 2018; Krombholz et al., 2015).

A notable aspect of the incident was the absence of immediate communication with the security function. The department did not report the incident through the channels that had been defined during preparatory coordination. Instead, the attacker remained unaware of the consequences for several days and only received information after being contacted by hospital IT management. This gap highlights a well-known challenge in security governance: employees may recognize anomalies, yet still fail to escalate them in a structured way (Jones et al., 2021; Åhlfeldt, 2008).

From an attacker perspective, the incident is particularly revealing. Considerable disruption was achieved without advanced preparation, persistence or technical capability. The caller did not apply sophisticated manipulation, nor was additional reconnaissance required. The outcome emerged primarily from the target’s interpretation of uncertainty. This aligns with research showing that social engineering effectiveness often depends less on attacker mastery and more on how organizational actors make sense of ambiguous situations under pressure (Heartfield and Loukas, 2018; Frangopoulos et al., 2010).

Equally important, subsequent calls made after the department had already shifted to manual procedures did not indicate that staff shared awareness of the situation. Individuals who were contacted later behaved as if normal operations were ongoing. The disruption therefore remained locally contained rather than institutionally communicated, limiting opportunities for collective learning.

When the incident was eventually discussed with management, it became clear that existing playbooks and awareness routines did not explicitly anticipate this type of response. Staff had been encouraged to report suspicious communication to the security department, either directly or anonymously, but no guidance described when or how clinical operations should be suspended. The nurse’s decision therefore represented an improvised protective action in the absence of clear procedural anchors.

Following this clarification and in agreement with the organization, the experiment was discontinued. Normal digital workflows were restored, and additional effort was required to transfer handwritten documentation back into electronic systems. The episode demonstrates that even ethically constrained simulations can trigger significant secondary effects, and that social engineering resilience must account not only for the prevention of disclosure but also for the management of uncertainty and recovery.

Because social engineering relies on deception, ethical safeguards were a core part of the study design. The research was conducted in accordance with the Austrian Academy of Sciences’ Guidelines for Good Scientific Practice (Åhlfeldt, 2008) and followed advice from earlier social engineering research that focused on minimizing risk and avoiding unnecessary harm (Jones et al., 2021; Frangopoulos et al., 2010).

To protect those who were contacted, several restrictions were applied to the simulated attacker:

  • No sensitive information such as passwords, health records or personal identifiers could be requested or accepted.

  • Every call was structured to end before any risk of violating confidentiality could arise.

  • The pretexts were designed to sound realistic but remain harmless, such as pretending to work in internal IT or conducting a survey.

  • No individuals were named in any report, and the name of the healthcare organization was withheld to prevent reputational damage.

Participants were not aware that they were part of a research study, and as a result they could not be debriefed. This lack of informed consent was judged to be ethically acceptable due to the absence of harm, the academic and educational purpose of the research, consent from the organization and the fact that similar methods have been used in past field studies within this domain. The greatest risk identified was the possibility of momentary confusion or discomfort for the target. This risk was reduced through the respectful tone used in all calls, the short duration of each conversation and the attacker’s careful avoidance of aggressive or overly manipulative tactics.

Each vishing call was followed by structured documentation. The attacker recorded details such as the time of the call, the target’s role when identifiable, the organizational setting, the pretext used, the estimated length of the call and a brief summary of the conversation. These notes were also supported by qualitative reflections focusing on several aspects:

  • how confident and fluent the attacker felt during the call;

  • whether the attacker followed the script or chose to improvise;

  • observations about the target’s tone, behavior and emotional signals; and

  • the overall outcome, categorized as success, partial success or failure.

To better capture how the attacker’s skills developed over time, a field journal was kept throughout the study. In this journal, the attacker noted expectations before each call, reflections after it, emotional reactions, lessons learned and any specific plans for adjusting the approach next time. Over time, the journal became a detailed narrative of learning, revealing subtle changes in thinking and strategy that would have been difficult to document using only coded summaries.

The analysis of the call logs revealed recurring obstacles that frequently prevented targets from immediately complying with the request. At the same time, Figure 1 shows how the attacker gradually developed practical ways of guiding recipients past these barriers and toward rehearsing the requested action, namely, accessing the website and reading the displayed code.

Figure 1.
A flowchart maps call stages from introduction through six person responses to multiple attacker strategies and follow-up actions.The flowchart begins with Start call, followed by Introduction and explain necessity for the call. The flow then branches to six responses: Person is stressed and overloaded on work; Person wants to schedule a call back; Person was not able to follow the commands due to lacking skills; Person wants a business email as form of proof; Person was sceptical of attackers identity and motive; and Person wants to be informed via mail before complying. Multiple arrows connect these responses to six strategies: Reassure that it is very fast and no hassle; Convey that it is stressful for the attacker to do the calls and there are several more to call; Establish authority and explain that the task has to be done; Give specific advice tailored to earlier problems encountered; Explain why the task has to be fulfilled and the consequences if not; and Convince that further formal information will be sent later on. These strategies connect through multiple arrows to six follow-up actions: Explain that there is a time constrain; Try to get exchanged to a co-worker; Adhere to the persons guilt of creating more work for the attacker; Give general I T advice without gathered information; Remind that the call is tasked from a managing authority and only the task is being done; and Explain that there is no known alternative and the call is the planed way.

Most common interaction obstacles and persuasion techniques

Figure 1.
A flowchart maps call stages from introduction through six person responses to multiple attacker strategies and follow-up actions.The flowchart begins with Start call, followed by Introduction and explain necessity for the call. The flow then branches to six responses: Person is stressed and overloaded on work; Person wants to schedule a call back; Person was not able to follow the commands due to lacking skills; Person wants a business email as form of proof; Person was sceptical of attackers identity and motive; and Person wants to be informed via mail before complying. Multiple arrows connect these responses to six strategies: Reassure that it is very fast and no hassle; Convey that it is stressful for the attacker to do the calls and there are several more to call; Establish authority and explain that the task has to be done; Give specific advice tailored to earlier problems encountered; Explain why the task has to be fulfilled and the consequences if not; and Convince that further formal information will be sent later on. These strategies connect through multiple arrows to six follow-up actions: Explain that there is a time constrain; Try to get exchanged to a co-worker; Adhere to the persons guilt of creating more work for the attacker; Give general I T advice without gathered information; Remind that the call is tasked from a managing authority and only the task is being done; and Explain that there is no known alternative and the call is the planed way.

Most common interaction obstacles and persuasion techniques

Close Figure 1.

Some persuasive moves were highly situation-specific. They were not applied in every conversation, but when relevant they had strong local impact. A typical example occurred when recipients hesitated because they did not know how to perform the required task. In these situations, the attacker began by offering general support, such as explaining how to open or navigate a browser. Several recipients verbalized what they were currently seeing on their screens while following the instructions. Through these descriptions, the attacker could infer how the user interface must look and then tailor the guidance more precisely, despite never having direct visual access.

This process reflects adaptive persuasion, in which the attacker continuously modifies the approach based on cues from the target rather than relying on a rigid script (Krombholz et al., 2015; Jones et al., 2021). By using the recipient’s own comments to reconstruct the environment, the caller effectively navigated the workspace vicariously and provided increasingly specific directions. Over time, this reduced uncertainty and helped maintain conversational momentum.

A recurring source of difficulty involved confusion between the organization’s intranet and the external web browser required to reach the prepared site. Clarifying this distinction often enhanced credibility. When the attacker explained where the correct browser could typically be found or how it differed from internal systems, recipients frequently reacted with greater trust. Demonstrating insider familiarity is a well-documented method for strengthening perceived legitimacy in social engineering encounters (Krombholz et al., 2015; Nohlberg, 2008).

Other techniques appeared regularly but rarely produced immediate effects in isolation. Assurances that the procedure would “only take a moment” seldom convinced skeptical recipients on their own. However, when combined with suggestions that the task was unavoidable and would eventually need to be completed, resistance sometimes decreased. This supports earlier findings that persuasion in vishing tends to operate through the accumulation of compatible influence cues rather than single arguments (Jones et al., 2021).

One strategy that seemed particularly effective in the healthcare environment was the use of empathy. The attacker occasionally portrayed themselves as being under pressure from supervisors and obliged to complete the calls. Because healthcare professionals often work within strong norms of compassion and helpfulness, this framing could encourage cooperation. When tied to relatable experiences such as workload or administrative stress, compliance was positioned as assistance rather than risk. Similar dynamics have been discussed in research highlighting how caring cultures may inadvertently increase susceptibility to manipulation (Åhlfeldt, 2008; Nohlberg, 2008).

Finally, among recipients who had not already terminated the call, emphasizing potential negative consequences of noncompliance proved influential. Suggesting that services might fail or that additional work would follow if the verification was not completed often shifted the interaction. Appeals to responsibility and continuity align with mechanisms previously identified as powerful within organizational social engineering contexts (Hatfield, 2018; Krombholz et al., 2015).

Taken together, these observations illustrate how persuasion evolved from scripted delivery into context-sensitive navigation. The attacker learned not only which arguments existed, but when they were likely to resonate. Even specialized tactics, though infrequent, contributed disproportionately to progress once the appropriate situation emerged.

The analysis was carried out thematically, using a step-by-step coding process to identify patterns in both the attacker’s behavior and the responses from targets. The first codes were developed directly from the call logs and field notes. These included categories such as reliance on the script, confident deviation, emotional tone and how the attacker managed situations that escalated.

One key focus was how the attacker learned from failure. The early calls were marked by rigid use of the script and a visible sense of discomfort. In contrast, the later calls showed more improvisation, persuasive language and better control over how the conversation flowed emotionally. These changes supported the idea that an attacker’s skills can improve quickly just through practice, even without formal training.

The study also looked at how reactions from targets influenced the attacker’s behavior. For example, when someone sounded friendly or confused, the attacker often felt encouraged to continue or ask a follow-up question. When someone showed skepticism or pushed back, future calls were often adjusted. In those cases, the attacker used more confident language or simplified the request.

The analysis also traced a pattern of development through the full set of calls. These were informally grouped into three stages: early, middle and late. Each phase showed increased fluency and evolving strategies.

Even though the sample was small, the data offered a rich picture of how attackers learn. It gave insight not only into what they did, but also how they adjusted based on what happened during each call. These observations can help improve how we design defenses that focus on the human side of security.

It is also worth noting that the attacker was one of the researchers. This gave access to personal reflections that added depth to the data, but it may also have introduced bias. To address this, the attacker used the field journal not only as a way to collect data but also to reflect critically on emotional reactions and assumptions. This made it easier to separate passing impressions from real patterns in behavior.

This section presents the main findings from the study and discusses how they were interpreted in relation to the study’s aims.

One of the most important findings from this study was how quickly the simulated attacker, despite having no previous experience, gained both confidence and fluency in making vishing calls. The first attempts were short, hesitant and highly scripted. The attacker relied almost completely on the prepared material and ended calls as soon as there was any sign of doubt or resistance. The pretext often came across as forced, and the attacker described feeling uncomfortable. Notes in the field journal included entries like, “I didn’t sound like I belonged” and “I bailed as soon as they asked something unexpected.”

By the sixth or seventh call, however, a clear change had taken place. The attacker began speaking with more ease, used terminology familiar to the organization and was able to respond to unanticipated questions without losing track of the scenario. One journal entry noted, “I trusted my voice more. I didn’t need to check the script first.” This shift marked a move from following rules to adapting in real time, similar to what experiential learning theory describes as going from deliberate action to intuitive skill (Altrichter et al., 2002).

This kind of development brings up an important risk: Attackers can become convincingly fluent with only a small amount of practice. They do not necessarily improve because they study, but because real conversations offer direct and immediate feedback. Moments of perceived success, such as being believed, not questioned or simply allowed to continue, serve as reinforcement. In that sense, learning is driven more by how the interaction unfolds than by the specific content of what is said. Being treated as a legitimate caller becomes part of the attacker’s learning process.

Over the course of 20 calls, several strategies began to take shape. These patterns were not based on formal training or theory, but emerged and were gradually improved through repeated interactions. Four key techniques stood out:

Relational anchoring: Starting the conversation with a question about shared work tasks, such as “Are you still using the old patient interface?”, helped create a sense of belonging. This approach worked better than direct requests for information.

Reducing mental effort: The most successful calls kept things simple. When the caller avoided technical terms, spoke calmly and gave the target time to respond, the person on the other end of the line remained more relaxed. When the attacker added confusion or rushed the interaction, targets became cautious or disengaged.

Empathy and reducing pressure: Later in the study, the attacker began opening with a brief acknowledgment of the target’s likely workload: “I know it’s hectic right now, this will only take a second.” This helped create rapport and made the conversation feel less intrusive.

Script improvement through repetition: After certain calls, the attacker adjusted parts of the internal script based on what had gone well or poorly. Over time, this led to a more polished way of speaking. The process resembled how real attackers probably refine their tactics through experience.

From the beginning, the attacker used a list of prewritten responses to common challenges, such as “Who are you again?”, “Why do you need this?”, or “Can I call you back?” While these replies were not fully scripted, they had been rehearsed and helped lower the mental load during each call. As the study went on, the attacker updated and expanded this list, improving the wording based on live reactions. This kind of preparation boosted fluency and confidence, and also closely mirrors how skilled social engineers prepare adaptable answers to stay in control.

Although the attacker had no prior training in these tactics, many of the patterns that emerged match principles well known in social engineering literature (Jones et al., 2021; Heartfield and Loukas, 2018). What makes this finding notable is that these methods were discovered without instruction, purely through trial, reflection and feedback. That suggests they are not only effective, but also intuitive for someone who is paying attention and willing to adapt.

Figure 2 shows the fake web interface that the attacker used as part of the scenario in several calls, along with the pop-up message shown to participants. The message, displayed in German, clearly warned that the website was not secure and advised users not to give any personal information. To make the interaction feel routine, the attacker referred to the site as an internal update page and asked the target to check if they had already seen it.

Figure 2.
A website screenshot displays a German security warning above a page containing a personal identification number and navigation text.The upper section contains the heading This page says. Below it is a German text. An O K button appears beside the warning. The lower section contains a website page with LOGO at the upper left. More German text is present as centred text, followed by the number 4658720. Small footer text appears along the bottom edge.

Interface and pop-up of the fake web page

Figure 2.
A website screenshot displays a German security warning above a page containing a personal identification number and navigation text.The upper section contains the heading This page says. Below it is a German text. An O K button appears beside the warning. The lower section contains a website page with LOGO at the upper left. More German text is present as centred text, followed by the number 4658720. Small footer text appears along the bottom edge.

Interface and pop-up of the fake web page

Close Figure 2.

The calls followed a consistent pattern. The attacker introduced themselves as someone from internal IT, saying they were doing a quick check related to a recent update. The scenario was made to sound realistic and low-pressure. The employee was asked to open a website that looked like the organization’s internal system. If the target hesitated, the attacker reassured them with comments like “this will only take a second” and tried to use a familiar tone to reduce suspicion. Once the target opened the site and clicked past the warning message, they were shown a number and asked to read it out loud to confirm access.

Website analytics later showed that at least 36 users visited the fake site, despite only 20 calls being made. This suggests that the link may have been shared internally within the organization. Even though no (actual) sensitive data was collected, and the page itself posed no risk, this raised an important point. If the site had contained malware or had been built to steal data, the effect could have spread well beyond the original targets. Because of general internet traffic and automated systems, it was not possible to know exactly how many of the visits came from humans, but the sharp rise in activity after the calls indicates that these kinds of social engineering setups can spread easily beyond their intended scope.

As the attacker gained more experience, their emotional response changed alongside their conversational skills. In the beginning, they described feeling nervous and uncomfortable, even embarrassed. Over time, that anxiety gave way to confidence and, eventually, a kind of anticipation. The field journal clearly reflected this shift. Early entries focused on self-doubt, while later ones included comments that showed a more strategic mindset and even a sense of enjoyment.

These emotional shifts seemed to create a reinforcing effect. When a call went well, the attacker felt more motivated and more willing to take risks in the next one. This cycle helped explain how attackers can continue to improve even without external rewards or feedback. A single smooth call one day could lead to a more daring approach the day after.

The attacker also started to notice small social signals that helped guide their decisions. For example, if the person on the other end of the call said “okay…” with hesitation, the attacker would often decide not to press further. But if the person laughed nervously, that was taken as an opening to move forward gently. These types of subtle observations are difficult to teach, but once someone begins to notice them, they can become a powerful part of social manipulation.

Figure 3, created by Philipp Schrefel during the study, gives an overview of all the calls made throughout the project. It shows how the calls changed over time in terms of length, outcome and the attacker’s perception of success. The figure helps visualize how the attacker’s skills developed. In the early calls, conversations were shorter and often ended quickly. In later calls, the attacker remained on the line longer and was more successful in keeping the targets engaged. Overall, however, the calls were relatively brief, rarely exceeding 15 min. This timeline illustrates how the attacker gained confidence and adapted their strategy over time.

Figure 3.
A timeline of 20 calls pairs researcher observations with recipient reactions and marks successful and unsuccessful calls and key milestones.A vertical timeline presents 20 calls between columns titled Researcher observation and reactions and Interpretation and reaction of recipients. Call one is successful. R 1 states that the attacker was uncomfortable before and during the call. I 1 states that the recipient ignored pop ups and external numbers. Call two is unsuccessful. R 2 states that the attacker tried to make it seem that a boss had assigned the calls. I 2 states that the recipient referred to normally used I T Sec support methods and regarded email as secure. Call three is successful. R 3 states that the attacker realised humour could leverage data and make calls less stressful. I 3 states that the recipient tried to avoid the work by questioning its necessity. Call four is successful. R 4 states that the attacker began asking recipients to spell their full names because calls provoked no reports. I 4 states that the recipient was scared of losing access to her virtual desktop and complied with all demands. Call five is unsuccessful. R 5 states that the attacker observed that a vishing attack with a spoofed mail might have an immense success rate. I 5 states that the recipient did not hesitate to share personal information but insisted on an email for security reasons. Call six is unsuccessful. R 6 states that the attacker gained insight into the virtual desktop design through constant recipient feedback. I 6 states that the recipient could not comply because of lacking knowledge. Call seven is unsuccessful. R 7 states that the attacker made it appear that a spoofed phone number was used for the vishing attack. I 7 states that the recipient was suspicious of the caller, wanted to check with I T Sec, and called after 2 days but was persuaded that a wrong number had been called. Call eight is unsuccessful. R 8 states that the attacker said the number was on a list and that he did not check numbers beforehand. I 8 states that the recipient said the called number was a non-personal extension and personal numbers should be called. Call nine is successful. R 9 states that the attacker stopped relaying further numbers and said they would be called later, with no further call to that department to provoke a report. I 9 states that the recipient wanted to relay the security numbers of present workers. Call 10 is successful. R 10 states that the attacker conducted an attack on the forwarded person and was successful. I 10 states that the recipient did not know about the calls and forwarded the researcher to the department head. Call 11 is successful. R 11 states that the attacker began determining whether a call would succeed before fully describing the matter. I 11 states that the recipient had no questions or suspicion and immediately relayed all requested information. Call 12 is successful. R 12 states that the attacker used humour to leverage a worrying amount of personal data. I 12 states that the recipient questioned suspicious parts of the reasoning but was easily persuaded with humour. Call 13 is successful. R 13 states that the attacker could guide the recipient through the website without seeing the virtual desktop by using previously acquired knowledge. I 13 states that the recipient said this was not the normally used support method but relayed all information anyway. Call 14 is successful. R 14 states that the attacker prolonged the call even when the test subject was stressed to leverage more personal data. I 14 states that the recipient repeatedly mentioned being stressed but still had time to joke. Call 15 is successful. R 15 states that the attacker began recognising test-subject patterns and how to leverage data quickly. I 15 states that the recipient did not seem to understand what was happening or what the researcher requested but complied. Call 16 is successful. R 16 states that the attacker blocked the number immediately after the call to provoke a report, but no report was filed. I 16 states that the recipient insisted on a call back after asking I T Sec. Call 17 is unsuccessful. R 17 states that the attacker tried humour and sympathy without success. I 17 states that the test subject was non-compliant because of workload and stress. Call 18 is successful. R 18 states that the attacker used time pressure to make the person ignore the pop up. I 18 states that the recipient read the pop up aloud but ignored its warning. Call 19 is successful. R 19 states that the attacker acquired enough information to provide recipients with step-by-step instructions for navigating the virtual desktop. I 19 states that the recipient had difficulty following orders and wanted other present workers to do the same. Call 20 is unsuccessful. Additional notes state Start: December. 04; after call four, more personal data was asked for; by call nine, the attacker could make calls comfortably and without stress; later, the attacker could easily leverage data from calls and make test subjects relay the security code without discomfort; and calls were stopped on December. 20 after an incident reduced a department's efficiency and ethical risks were elaborated.

Timeline of calls conducted in the study and general observations

Figure 3.
A timeline of 20 calls pairs researcher observations with recipient reactions and marks successful and unsuccessful calls and key milestones.A vertical timeline presents 20 calls between columns titled Researcher observation and reactions and Interpretation and reaction of recipients. Call one is successful. R 1 states that the attacker was uncomfortable before and during the call. I 1 states that the recipient ignored pop ups and external numbers. Call two is unsuccessful. R 2 states that the attacker tried to make it seem that a boss had assigned the calls. I 2 states that the recipient referred to normally used I T Sec support methods and regarded email as secure. Call three is successful. R 3 states that the attacker realised humour could leverage data and make calls less stressful. I 3 states that the recipient tried to avoid the work by questioning its necessity. Call four is successful. R 4 states that the attacker began asking recipients to spell their full names because calls provoked no reports. I 4 states that the recipient was scared of losing access to her virtual desktop and complied with all demands. Call five is unsuccessful. R 5 states that the attacker observed that a vishing attack with a spoofed mail might have an immense success rate. I 5 states that the recipient did not hesitate to share personal information but insisted on an email for security reasons. Call six is unsuccessful. R 6 states that the attacker gained insight into the virtual desktop design through constant recipient feedback. I 6 states that the recipient could not comply because of lacking knowledge. Call seven is unsuccessful. R 7 states that the attacker made it appear that a spoofed phone number was used for the vishing attack. I 7 states that the recipient was suspicious of the caller, wanted to check with I T Sec, and called after 2 days but was persuaded that a wrong number had been called. Call eight is unsuccessful. R 8 states that the attacker said the number was on a list and that he did not check numbers beforehand. I 8 states that the recipient said the called number was a non-personal extension and personal numbers should be called. Call nine is successful. R 9 states that the attacker stopped relaying further numbers and said they would be called later, with no further call to that department to provoke a report. I 9 states that the recipient wanted to relay the security numbers of present workers. Call 10 is successful. R 10 states that the attacker conducted an attack on the forwarded person and was successful. I 10 states that the recipient did not know about the calls and forwarded the researcher to the department head. Call 11 is successful. R 11 states that the attacker began determining whether a call would succeed before fully describing the matter. I 11 states that the recipient had no questions or suspicion and immediately relayed all requested information. Call 12 is successful. R 12 states that the attacker used humour to leverage a worrying amount of personal data. I 12 states that the recipient questioned suspicious parts of the reasoning but was easily persuaded with humour. Call 13 is successful. R 13 states that the attacker could guide the recipient through the website without seeing the virtual desktop by using previously acquired knowledge. I 13 states that the recipient said this was not the normally used support method but relayed all information anyway. Call 14 is successful. R 14 states that the attacker prolonged the call even when the test subject was stressed to leverage more personal data. I 14 states that the recipient repeatedly mentioned being stressed but still had time to joke. Call 15 is successful. R 15 states that the attacker began recognising test-subject patterns and how to leverage data quickly. I 15 states that the recipient did not seem to understand what was happening or what the researcher requested but complied. Call 16 is successful. R 16 states that the attacker blocked the number immediately after the call to provoke a report, but no report was filed. I 16 states that the recipient insisted on a call back after asking I T Sec. Call 17 is unsuccessful. R 17 states that the attacker tried humour and sympathy without success. I 17 states that the test subject was non-compliant because of workload and stress. Call 18 is successful. R 18 states that the attacker used time pressure to make the person ignore the pop up. I 18 states that the recipient read the pop up aloud but ignored its warning. Call 19 is successful. R 19 states that the attacker acquired enough information to provide recipients with step-by-step instructions for navigating the virtual desktop. I 19 states that the recipient had difficulty following orders and wanted other present workers to do the same. Call 20 is unsuccessful. Additional notes state Start: December. 04; after call four, more personal data was asked for; by call nine, the attacker could make calls comfortably and without stress; later, the attacker could easily leverage data from calls and make test subjects relay the security code without discomfort; and calls were stopped on December. 20 after an incident reduced a department's efficiency and ethical risks were elaborated.

Timeline of calls conducted in the study and general observations

Close Figure 3.

By placing all 20 calls along this timeline, the figure supports the main conclusion of the study: that it is possible to build social engineering skills through brief, repeated practice. It also shows how outcomes varied, from immediate rejection to transferred calls to full cooperation. These shifts help explain how even small changes in approach made a real difference to the result of each call.

Although the study did not include structured interviews with the people who received the calls, the attacker’s notes and reflections revealed consistent patterns in how targets responded. Most employees were polite, helpful and willing to assist. Very few questioned the caller’s identity, and many offered to transfer the call, take a message or explain internal procedures, all without verifying whether the caller was legitimate. These behaviors reflect the “service mindset paradox” in healthcare, where staff are trained to support rather than to question (Åhlfeldt, 2008). The attacker’s notes support this view. One entry stated, “She sounded unsure but kept helping, like she didn’t want to be rude.” In another call, the target went to check a file while the attacker waited, further increasing exposure.

This pattern aligns with previous research showing that sectors like healthcare, education and customer service are particularly vulnerable to social engineering due to their cooperative culture, low levels of formal hierarchy and strong trust between colleagues (Hatfield, 2018; Krombholz et al., 2015; Åhlfeldt, 2008; Nohlberg, 2008). When roles are assumed without verification, and when time pressure or empathy outweighs caution, organizations become more open to manipulation. No employees reported the calls as suspicious, and no one expressed concern during or after the interaction, suggesting that the scenarios used were seen as routine and unthreatening.

One of the most important findings in this work is that attackers do not necessarily need formal coaching or technical resources to improve. Instead, the social context itself acts as a learning tool. Every response from a target, whether passive, helpful or resistant, gives the attacker feedback. Over time, this leads to the development of a kind of internal rulebook: what to say, what to avoid, when to push forward and when to retreat.

This creates a risky dynamic. In effect, the target becomes the teacher. Through small and often unnoticed social cues, the organization becomes part of the attacker’s learning process. Organizations should consider revising training practices to avoid reinforcing attacker behavior through social cues. Being helpful, vague, or overly tolerant can send signals that attackers learn from and adapt to.

Even though the company lost no data during this study, the attacker still improved significantly. The combination of low resistance, high trust and smooth communication gave space for learning through practice. These findings suggest that it is not enough to train staff to spot suspicious behavior. Organizations must also think about how their everyday communication patterns can either block or encourage social engineering attempts.

This study set out to explore how quickly an untrained individual can develop the ability to carry out vishing attacks. Rather than focusing on the usual discussion of vulnerabilities in the target population, we turned attention to how the attacker learns. The results show that effective social engineering is not necessarily the result of advanced scripts or technical knowledge. Instead, it is often a matter of becoming skilled at interaction, and this ability can develop surprisingly fast through simple repetition and reflection.

The implications are serious and perhaps also not commonly understood. Within just a few hours of active practice, the attacker in moved from uncertain, script-based conversations to confident and persuasive communication. This progression illustrates why social engineering should not be treated as a fixed threat based on known patterns. It should instead be seen as a learning process in which attackers adjust and improve based on social feedback in real time.

These findings are in line with earlier research on deception and persuasion (Jones et al., 2021; Heartfield and Loukas, 2018; Altrichter et al., 2002), but they go a step further by showing that even in low-risk, unsupervised settings, attacker fluency can grow quickly, perhaps more so than many security specialists would imagine. The attacker in our study had no prior training in influence, no expert guidance and no special tools. They relied only on time, curiosity and the willingness to try again. This reflects how many real-world attackers operate, testing different strategies and learning from every attempt.

Just as important is the role of the organizational setting in supporting or enabling this learning. Healthcare, while not uniquely exposed, combines high levels of trust, a service-oriented culture and a communication style that encourages fast responses. These features, which are essential for patient care, can also make the environment more open to manipulation. In several of the calls, it was these helpful and polite responses that allowed the attacker to continue the conversation, redirect it, or increase the pressure. These findings reinforce earlier studies that highlight the unique risks found in healthcare contexts (Hatfield, 2018; Krombholz et al., 2015; Åhlfeldt, 2008).

The study also demonstrates how nonverbal signals and emotional cues play a key role in the attacker’s ability to adapt. Success was not only measured in outcomes, but also felt in the tone of voice, flow of the exchange and control over the situation. Over time, the attacker learned to read hesitation, use pauses and sense when a target might either push back or go along. These skills, once developed, became more useful than any prepared script. They also make the attacker harder to stop, because the danger lies in performance, not just in the content of what is said.

Together, the results point to a need to reconsider how we think about training. Traditional awareness programs tend to focus on recognizing common tactics or warning signs. But if attackers learn fast and adapt through experience, then training needs to keep up. Organizations should promote a culture where polite skepticism is seen as normal, where unexpected requests are verified by default, and where interrupting to ask questions is not only accepted but actively encouraged.

Beyond individual awareness, training should also include organizational design. Who is allowed to call whom? How is authority recognized when contact is unexpected? What processes can be changed to add just enough friction to slow down attackers, without damaging everyday workflows? These design choices might be more effective in the long term than static awareness materials, even though those also play an important role.

While the study was small in scale, its strength lies in presenting a view that is rarely discussed: that of the attacker as someone who learns. In this case, no real data was stolen, and no systems were compromised. Still, the attacker’s growing skill highlights the fact that even attackers with limited resources can become a real threat. As technical protections improve, the human side remains the most adaptable and exposed surface in any organization.

Of course, this study has its limits. The sample size was small, the study took place in a single healthcare institution, and all calls were carried out by one person. This limits how far the findings can be applied. Still, the consistency of the data makes it useful for generating ideas for larger studies and for reflecting on attacker behavior in practice.

Future research should explore how other types of attackers operate, what happens in different sectors, and how defenders might disrupt the learning process. It would also be useful to gather insight from real attackers, through interviews or analysis of known attack campaigns. As part of our continued work, we are looking into new ways of delivering awareness training that can respond more quickly and break the learning loop as it happens.

In the end, what we learned reminds us about a basic but often forgotten truth about social engineering. It is not only about exploiting weaknesses, it is about learning how people behave. For an attacker, every conversation is a chance to learn something new.

The authors would like to thank the participating healthcare organization for making this study possible, as well as the subjects.

Åhlfeldt
,
R.M.
(
2008
), “
Information security in distributed healthcare: Exploring the needs for achieving patient safety and patient privacy
”, PhD dissertation,
Stockholm University
, available at: Link to Information security in distributed healthcare: Exploring the needs for achieving patient safety and patient privacyLink to the cited article.
Altrichter
,
H.
,
Kemmis
,
S.
,
McTaggart
,
R.
and
Zuber-Skerritt
,
O.
(
2002
), “
The concept of action research
”,
The Learning Organization
, Vol.
9
No.
3
, pp.
125
-
131
, doi: .
Ashfaq
,
S.
,
Chandre
,
P.
,
Pathan
,
S.
,
Mande
,
U.
,
Nimbalkar
,
M.
and
Mahalle
,
P.
(
2024
), “Defending against vishing attacks: a comprehensive review for prevention and mitigation techniques”, In:
Roy
,
N.R.
,
Tanwar
,
S.
and
Batra
,
U.
(Eds),
Cyber Security and Digital Forensics. Lecture Notes in Networks and Systems
,
Springer
,
Singapore
, Vol
896
, doi: .
Europol
(
2023
), “
Europol and Eurojust support Czech and Ukrainian police in taking down multi-million euro voice phishing gang
”,
available at:
Link to Europol and Eurojust support Czech and Ukrainian police in taking down multi-million euro voice phishing gangLink to the cited article. (
accessed
May 19, 2025).
Frangopoulos
,
E.D.
,
Eloff
,
M.M.
and
Venter
,
L.M.
(
2010
), “
Psychological considerations in social engineering – the Ψ-wall as defense
”,
IADIS International Journal on Computer Science and Information Systems
, Vol.
5
No.
2
, pp.
1
-
20
.
Hatfield
,
J.M.
(
2018
), “
Social engineering in cybersecurity: the evolution of a concept
”,
Computers and Security
, Vol.
73
, pp.
102
-
113
, doi: .
Heartfield
,
R.
and
Loukas
,
G.
(
2018
), “
Detecting semantic social engineering attacks with the weakest link: implementation and empirical evaluation of a human-as-a-security-sensor framework
”,
Computers and Security
, Vol.
76
, pp.
101
-
127
, doi: .
IBM
(
2023
), “
Cost of a data breach report
”,
available at:
Link to Cost of a data breach reportLink to the cited article (
accessed
May 19, 2025).
Jones
,
K.S.
,
Armstrong
,
M.E.
,
Tornblad
,
M.K.
and
Siami Namin
,
A.
(
2021
), “
How social engineers use persuasion principles during vishing attacks
”,
Information and Computer Security
, Vol.
29
No.
2
, pp.
314
-
331
, doi: .
Kolb
,
D.A.
(
1984
),
Experiential Learning: Experience as the Source of Learning and Development
,
Prentice Hall
,
Englewood Cliffs, NJ
.
Kroll
(
2023
), “
Q3 2023 threat landscape report: social engineering
”,
available at:
Link to Q3 2023 threat landscape report: social engineeringLink to the cited article (
accessed
May 19, 2025).
Krombholz
,
K.
,
Hobel
,
H.
,
Huber
,
M.
and
Weippl
,
E.
(
2015
), “
Advanced social engineering attacks
”,
Journal of Information Security and Applications
, Vol.
22
, pp.
113
-
122
, doi: .
Nalla
,
N.R.
,
Sakthivel
,
S.
and
Shankar
,
R.
(
2022
), “
Low cost VoIP system incorporation with Raspberry Pi
”, In:
2022 6th International Conference on Intelligent Computing and Control Systems (ICICCS)
, doi: .
Nohlberg
,
M.
(
2008
), “
Securing information assets: understanding, measuring and protecting against social engineering attacks
”, PhD dissertation,
Stockholm University
, available at: Link to Securing information assets: Understanding, measuring and protecting against social engineering attacksLink to the cited article
Nohlberg
,
M.
,
Schrefel
,
P.
(
2026
). Learning to deceive: attacker skill acquisition in a vishing simulation study. In:
Furnell
,
S.
and
Clarke
,
N.
(Eds),
Human Aspects of Information Security and Assurance. HAISA 2025.
IFIP Advances in Information and Communication Technology
,
Springer
,
Cham
, Vol
761
, doi: .
Schmitt
,
M.
and
Flechais
,
I.
(
2024
), “
Digital deception: generative artificial intelligence in social engineering and phishing
”,
Artificial Intelligence Review
, Vol.
57
No.
12
, p.
324
, doi: .
Stembert
,
N.
,
Padmos
,
A.
,
Bargh
,
M.S.
,
Choenni
,
S.
and
Jansen
,
F.
(
2015
), “
A study of preventing email (spear) phishing by enabling human intelligence
”, In:
2015 European Intelligence and Security Informatics Conference (EISIC)
, doi: .
Published by Emerald Publishing Limited. This article is published under the Creative Commons Attribution (CC BY 4.0) licence. Anyone may reproduce, distribute, translate and create derivative works of this article (for both commercial and non-commercial purposes), subject to full attribution to the original publication and authors. The full terms of this licence maybe seen at Link to the terms of the CC BY 4.0 licenceLink to the terms of the CC BY 4.0 licence.

or Create an Account

Close subscription notice
Close access options