—Phishing is the practice of eliciting a person’s confidential information such as the name, date of birth or credit card details. Typically, the phishers combine some technologies and simple social engineering stratagems to persuade the victims into voluntarily disclose sensitive data. Phishing based on e-mail and Web technologies is certainly the most popular form. It has indeed received ample attention and some mitigation measures have been implemented. Notably, spam and phishing e-mail filters, blacklists. In this paper we describe our study on vishing (voice phishing), a form of attack where the scammers exploit the phone channel rather than sending e-mails and cloning trustworthy websites. We show that vishing, albeit less known, is a relevant form of phishing recently on the raise. We detail our analysis of a real-world database of vishing attacks reported by victims through a publicly-available web application that we build for this purpose. Our preliminary analysis revea...