Glossary
Smishing and vishing are phishing attacks carried out through other channels: smishing uses SMS text messages, and vishing uses voice calls, to manipulate victims into revealing information, credentials, or authorizing fraud. They apply the same social-engineering playbook as email phishing but exploit the greater trust and immediacy people often give to texts and phone calls.
People tend to be more guarded about email than about a text or a call, which is exactly why these channels work. A text feels personal; a phone call feels urgent and human.
Smishing messages impersonate banks, delivery companies, government agencies, or well-known brands, typically creating urgency ("suspicious activity detected," "your package couldn’t be delivered") and including a malicious link or a number to call. The link leads to a credential-harvesting site or a malware download. SMS is fertile ground because links are hard to inspect on mobile, messages feel immediate, and spoofing sender IDs is easy.
Vishing uses phone calls (live or automated) to manipulate victims. A caller might impersonate the victim’s bank warning of fraud, "tech support" claiming the device is compromised, or an authority figure demanding action. Vishing often works hand-in-hand with other attacks: a smishing text prompts the victim to call a number, or a vishing call talks the victim through installing remote-access software or reading out a one-time code. The live, human pressure is what makes it effective.
Generative AI has made vishing markedly more dangerous. Attackers can now clone a voice (a bank official, an executive, even a family member) from a short audio sample, lending terrifying credibility to a call. This both defeats voice-authentication systems and supercharges impersonation scams, and it’s a key reason voiceprint-based security is increasingly unreliable and phone-channel verification needs stronger, possession-based methods.
Defense mirrors other social-engineering countermeasures. Don’t rely on victims to spot ever-more-convincing fakes; instead, remove what these attacks steal (phishing-resistant authentication so a revealed code is useless), verify sensitive requests through trusted channels rather than acting on an inbound text or call, harden the call center against social engineering with strong possession-based verification, and use device and behavioral signals to catch downstream fraud. For consumers, the enduring rule (a legitimate bank won’t call or text asking you to move money or read out a code) still helps, but technical defenses carry the load.
What is smishing?
Phishing carried out via SMS text messages, using urgency and malicious links to steal credentials or data.
What is vishing?
Phishing carried out via voice calls, manipulating victims into revealing information or authorizing fraud.
How does AI make vishing worse?
Voice cloning lets attackers convincingly impersonate banks, executives, or family members, defeating voice authentication and boosting scams.
How do you protect against smishing and vishing?
Phishing-resistant authentication, verifying requests through trusted channels, hardened call-center verification, and behavioral detection.
Why are text and phone attacks effective?
People tend to trust texts and calls more than email, links are hard to inspect on mobile, and live calls apply urgent human pressure.
Do smishing and vishing work together?
Often yes: a smishing text may prompt the victim to call a number, or a vishing call may talk them through installing malware or reading a code.
Related: Phishing · Spear Phishing · Voice Authentication · Social Engineering · SIM Swapping