Vishing and smishing are phishing attacks that use phone calls and text messages instead of email. Vishing (voice phishing) uses live calls, recorded messages or voicemails; smishing (SMS phishing) uses text messages, often containing a link or a number to call. Both aim to trick people into revealing passwords or one-time codes, approving access, installing software or sending money.
At a glance
- Vishing is phishing by voice call; smishing is phishing by text message.
- Both are forms of social engineering: they mainly manipulate people instead of exploiting software flaws.
- Calls and texts often reach personal phones, outside corporate email filters.
- Common targets include help desks, finance staff and anyone who can reset access or move money.
- Defenses combine training, verification procedures and authentication that resists phishing.
What problem it solves
As terms, vishing and smishing name threats many security programs underweight. Email security has improved, so attackers increasingly use channels with fewer controls. A text that appears to come from a delivery service, a bank or the CEO arrives on a personal phone with no filter in the way. A caller claiming to be from IT support asks an employee to read out an MFA code or approve a login prompt. A caller claiming to be an employee persuades the help desk to reset a password and register a new MFA device.
These attacks work because they create urgency and borrow trust: a familiar name, a spoofed caller ID, inside details gathered from social media or earlier breaches. AI voice tools make convincing impersonation easier, overlapping with deepfake fraud. The result can be account takeover, malware installation or fraudulent payments similar to business email compromise (BEC).
How it works
Vishing. An attacker calls, often spoofing a trusted number, and poses as IT support, a bank, a vendor, an executive or an employee. Typical asks: read out a one-time code, approve an MFA push, install remote access software, confirm account details or move money. Some campaigns start with a text or email asking the target to call a number.
Smishing. A text message impersonates a trusted sender, such as a parcel service, bank, payroll system or executive, and asks the recipient to click a link to a fake login page, call a number or reply with information.
Help desk attacks. Attackers call the IT help desk pretending to be an employee locked out of their account, aiming to get a password reset or new MFA device registered to the attacker.
Defenses usually combine:
- Training: security awareness training that covers calls and texts, with phishing simulations beyond email where available.
- Verification procedures: callbacks to known numbers before resets, payments or banking changes.
- Stronger authentication: phishing-resistant MFA removes codes that can be read out and ties sign-in to the real site, making relayed logins much harder.
- Reporting: an easy way for staff to report suspicious calls and texts.
When it matters for buyers
- When a peer is targeted. Vishing of help desks has been reported in several high-profile breaches; review your reset process.
- When choosing security awareness training. Check whether the program covers voice and text, not just email. Our security awareness training overview covers what to compare.
- When outsourcing the help desk. The provider’s identity checks become your front line against vishing.
- When rolling out MFA. Methods based on codes or push approvals can be talked out of users; phishing-resistant options reduce that risk.
Questions to ask vendors
- Does your training include vishing and smishing scenarios, and can you run simulated calls or texts?
- How does your help desk verify a caller’s identity before resetting passwords or MFA?
- Which MFA methods do you support, and are any phishing-resistant?
- How can staff report suspicious calls and texts, and who responds?
- How do you measure whether training changes behavior?
How it differs from email phishing
Email phishing arrives through a channel most organizations filter, log and can search after the fact. Vishing and smishing use phone networks and personal devices, where corporate filtering and visibility are often limited, and where a live conversation can adapt to the target’s hesitation. The goal and the defense principles are similar: verify independently before acting.
