What Are Vishing and Smishing?

Also called: Voice phishing and SMS phishing, Phone and text phishing

Related problems: Staff getting calls from people pretending to be IT support; Fake texts claiming to be from our CEO or bank; Help desk tricked into resetting a password or MFA; Our phishing training only covers email

Vishing and smishing are phishing attacks that use phone calls and text messages instead of email. Vishing (voice phishing) uses live calls, recorded messages or voicemails; smishing (SMS phishing) uses text messages, often containing a link or a number to call. Both aim to trick people into revealing passwords or one-time codes, approving access, installing software or sending money.

At a glance

  • Vishing is phishing by voice call; smishing is phishing by text message.
  • Both are forms of social engineering: they mainly manipulate people instead of exploiting software flaws.
  • Calls and texts often reach personal phones, outside corporate email filters.
  • Common targets include help desks, finance staff and anyone who can reset access or move money.
  • Defenses combine training, verification procedures and authentication that resists phishing.

What problem it solves

As terms, vishing and smishing name threats many security programs underweight. Email security has improved, so attackers increasingly use channels with fewer controls. A text that appears to come from a delivery service, a bank or the CEO arrives on a personal phone with no filter in the way. A caller claiming to be from IT support asks an employee to read out an MFA code or approve a login prompt. A caller claiming to be an employee persuades the help desk to reset a password and register a new MFA device.

These attacks work because they create urgency and borrow trust: a familiar name, a spoofed caller ID, inside details gathered from social media or earlier breaches. AI voice tools make convincing impersonation easier, overlapping with deepfake fraud. The result can be account takeover, malware installation or fraudulent payments similar to business email compromise (BEC).

How it works

Vishing. An attacker calls, often spoofing a trusted number, and poses as IT support, a bank, a vendor, an executive or an employee. Typical asks: read out a one-time code, approve an MFA push, install remote access software, confirm account details or move money. Some campaigns start with a text or email asking the target to call a number.

Smishing. A text message impersonates a trusted sender, such as a parcel service, bank, payroll system or executive, and asks the recipient to click a link to a fake login page, call a number or reply with information.

Help desk attacks. Attackers call the IT help desk pretending to be an employee locked out of their account, aiming to get a password reset or new MFA device registered to the attacker.

Defenses usually combine:

  • Training: security awareness training that covers calls and texts, with phishing simulations beyond email where available.
  • Verification procedures: callbacks to known numbers before resets, payments or banking changes.
  • Stronger authentication: phishing-resistant MFA removes codes that can be read out and ties sign-in to the real site, making relayed logins much harder.
  • Reporting: an easy way for staff to report suspicious calls and texts.

When it matters for buyers

  • When a peer is targeted. Vishing of help desks has been reported in several high-profile breaches; review your reset process.
  • When choosing security awareness training. Check whether the program covers voice and text, not just email. Our security awareness training overview covers what to compare.
  • When outsourcing the help desk. The provider’s identity checks become your front line against vishing.
  • When rolling out MFA. Methods based on codes or push approvals can be talked out of users; phishing-resistant options reduce that risk.

Questions to ask vendors

  • Does your training include vishing and smishing scenarios, and can you run simulated calls or texts?
  • How does your help desk verify a caller’s identity before resetting passwords or MFA?
  • Which MFA methods do you support, and are any phishing-resistant?
  • How can staff report suspicious calls and texts, and who responds?
  • How do you measure whether training changes behavior?

How it differs from email phishing

Email phishing arrives through a channel most organizations filter, log and can search after the fact. Vishing and smishing use phone networks and personal devices, where corporate filtering and visibility are often limited, and where a live conversation can adapt to the target’s hesitation. The goal and the defense principles are similar: verify independently before acting.

Frequently Asked Questions

What is the difference between vishing and smishing?
Vishing uses voice calls, including voicemails and calls from spoofed numbers. Smishing uses text messages, typically with a link or a number to call. Both are forms of phishing that use channels other than email.
Why are attackers using phone and text instead of email?
Email filters catch many phishing emails, while calls and texts to personal phones often bypass corporate security tools. People also tend to trust a live voice or a short text more and respond faster.
Can caller ID be trusted?
Not on its own. Caller ID and sender names can be spoofed, so a call or text that appears to come from your bank, IT department or CEO may not. Verify by calling back on a number you already know.
How do we protect the help desk from vishing?
Set strict identity checks for password and MFA resets, such as a callback to a number on file, manager approval or verification through an existing authenticated channel. Avoid checks based on information an attacker could find, like employee ID or date of birth.
Does security awareness training cover vishing and smishing?
Many programs do, and some offer simulated calls and texts as well as phishing emails. Check what your provider includes, as some programs focus mainly on email.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.