Summary
Indy Mellink’s core message is that voice phishing remains highly effective when it is grounded in human psychology, operational preparation, and persistence—and AI voice agents are beginning to change the economics of that work by removing labor bottlenecks. Speaking as a social engineer with a background in neuroscience, forensic psychology, and security operations, she frames the session as practical red-team experience rather than an academic study. Her work focuses on “hacking humans” for enterprise and government clients through voice phishing, phishing, deepfake scenarios, and physical penetration testing.
She first outlines the current threat landscape: traditional vishing still works, including attacks that use phishing kits, registered domains, passkey enrollment lures, and phone calls to push victims through account takeover flows. Attackers are also moving into multi-channel operations, where first contact, access, and data theft can happen quickly; she cites an example where attackers achieved first contact, access, and full data theft in under an hour, and on average within a single business day. She also describes a personal example: a calendar invite injected into her own calendar with no link, only a callback number, creating urgency around an alleged auto-payment and leading into a remote-access-tool refund scam.
Mellink then breaks down human-to-human vishing as a disciplined process. After OSINT, the operator needs a crash course in the target organization: how employees communicate, which tools they use, what normal requests look like, and what level of knowledge would seem suspicious. A credible persona needs a plausible role, a trigger event, urgency, and prepared responses for challenges such as department verification or mismatched phone numbers. She illustrates this with her first recorded vishing call, where she succeeded by giving a target a password to enter, then logging in while the target satisfied MFA. She also emphasizes the failures: targets noticing weak knowledge, excessive questioning, process mismatches, gender-based assumptions, anger, or simply being unhackable.
The strongest practical warning is that success does not require fooling everyone. Across thousands of calls per year, she says human-to-human vishing sees almost a 30% compromise rate, while her engagements have achieved a 100% success rate in gaining initial access because only one person needs to comply. She then transitions to AI-agent vishing, defining it as a true autonomous calling agent rather than voice conversion. Operationally, she says agents promise automated reconnaissance, script generation, deployment, persistence, retries, parallelization, scale, and consistency—meaning attackers or testers can place more attempts without the same limits of human fatigue, work hours, or improvisation.
Key Topics
5 key topics from Indy Mellink at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Build organization-specific context before attempting or defending vishing scenarios.
- Prepare objection-handling paths for identity, process, and phone-number challenges.
- Train service desks to challenge urgent access requests consistently.
- Treat callback numbers and calendar-invite lures as phishing indicators.
- Plan defenses for scalable AI-agent vishing, not only human callers.
“I have a 100% success rate of gaining initial access because the truth is all I need is one.”

Indy Mellink
Social engineer/hacker•Doppel
Up Next


Next in agenda
PQCmigration in practice: learnings from 7 organizations


Also on social engineering
A Room With a View

Also on social engineering
The hype is killing kittens, but not that grumpy old cat
Edwin van Andel