Por Equipo NoCall

What is vishing: how to spot phone scams in Spain

Vishing (voice + phishing) is one of the most dangerous and common phone scams in Spain. Criminals pretend to be your bank, Correos, or Social Security to steal personal data and money. The NoCall community has flagged more than 30.956 numbers linked to spam and scams, with 0 reports today alone.

30.956
Números de spam detetados
0
Denúncias da comunidade
0
Denúncias hoje

How does vishing work?

Vishing is a form of social engineering. Scammers research victims beforehand (data breaches, social media, or bought marketing lists) and call with partly real information to win your trust. The goal is to get data they do not have yet: passwords, SMS verification codes, or card details.

They often use caller ID spoofing so your phone shows your bank's real number. That makes the scam especially hard to spot.

Common vishing tactics in Spain

Fake bank call

They say there is a suspicious charge or unauthorised access to your account. They ask you to "verify your identity" with your password, PIN, or SMS code. In reality they use that code to authorise a transfer from your account.

Example: "Hello, we are calling from the security department of [bank]. We detected a suspicious transaction of €1,200. To cancel it, we need you to confirm the code we just sent by SMS."

Fake Social Security / tax authority

They impersonate Social Security or the tax agency. They mention a pending refund or a problem with your benefit and ask for bank details to "process the refund" or "regularise your situation".

Example: "We inform you that you have a €325 refund pending from Social Security. To process it, we need your bank account number."

Correos / parcel scam

They say a parcel is held at customs and you must pay a fee. They send a link or ask for card details by phone. Correos does not collect fees that way over the phone.

Fake tech support

They claim your router, PC, or internet line has a problem. They want you to install remote-access software or give access to online banking. Movistar, Vodafone, and other carriers do not call customers like this out of the blue.

"Relative in trouble" call

Someone pretends to be your child from a new number, saying they lost their phone and need money urgently. Always verify by calling your relative on a number you already trust.

How to protect yourself from vishing

1. Be wary of urgency

Scammers create pressure so you cannot think clearly. No legitimate process requires an instant phone decision. If they rush you, treat it as a red flag.

2. Never give sensitive data by phone

Your bank will never ask for passwords, PINs, SMS codes, or full card details by phone. No public body will ask for banking data that way either. If they do, it is vishing.

3. Hang up and call back yourself

If you have doubts, hang up and call the organisation's official number (from its website or your card). Do not use the number they gave you on the call or the number on your screen — it may be spoofed.

4. Check the number on NoCall

Search our database with more than 30.956 identified numbers. If the number was already reported as a scam, you will see it right away.

5. Turn on automatic blocking

With the NoCall app, numbers reported as vishing by the community can be blocked automatically on your phone — you may not even receive the call.

Protect yourself from vishing with NoCall

Automatically block numbers linked to phone scams before they reach you.

Download NoCall

If you fell for vishing

  1. Contact your bank immediately. Block compromised cards and accounts. Ask to reverse any fraudulent transactions.
  2. Change your passwords. If you shared online-banking or other credentials, change them at once from a trusted device.
  3. Report to the police. Go to a Policía Nacional station or Guardia Civil post with details: caller number, time, what they said, and what you shared.
  4. Call 017 (INCIBE). Spain's national cybersecurity helpline is free and confidential and can guide you on next steps.
  5. Report the number on NoCall. Your report helps protect others who might get the same call.

Check a suspicious number

Did you get a suspicious vishing call? See whether the number was already reported:

Perguntas frequentes

O que é o vishing?+

O vishing (voz + phishing) é uma fraude telefónica em que os criminosos ligam fingindo ser uma organização de confiança — como o seu banco, os Correos ou a Segurança Social — para roubar dados pessoais, palavras-passe ou dados bancários.

Como posso detetar uma chamada de vishing?+

Os sinais de alerta comuns são: urgência falsa (“a sua conta vai ser bloqueada”), pedidos de dados sensíveis (palavras-passe, PIN, códigos SMS), ameaças ou pressão para agir rápido, e pedidos para instalar apps ou fazer transferências. Nenhum banco ou organismo oficial pede dados confidenciais por telefone.

O que devo fazer se caí num vishing?+

Contacte o seu banco imediatamente para bloquear contas e cartões comprometidos. Mude quaisquer palavras-passe que tenha partilhado. Denuncie à Polícia Nacional ou à Guardia Civil. Ligue para o 017 (INCIBE) para aconselhamento gratuito de cibersegurança. Denuncie o número na NoCall para ajudar a proteger os outros.

O meu banco pode ligar-me e pedir os meus dados?+

Não. Nenhum banco pedirá alguma vez palavras-passe, PINs, códigos de verificação SMS ou dados completos do cartão por telefone. Se receber uma chamada dessas, é uma fraude. Desligue e ligue você mesmo para o número oficial do seu banco.

Pesquise um número de telefone ou um nome de empresa (Iberdrola, Vivo e Claro...) para verificar se foi denunciado como spam.

O que é o vishing: como detetar fraudes telefónicas em Espanha | NoCall