GlossarySecurity awareness

Smishing and vishing

Short answer

Smishing is phishing by text message (SMS or messaging apps), and vishing is phishing by phone call or voice message. Both use urgency and impersonation of a bank, a delivery company, IT support or an executive to get people to share credentials or codes, or to make payments.

Common scenarios

Texts about a parcel delivery, a blocked bank card or an unpaid fine that link to a fake website. Calls from fake bank staff asking to confirm a code, or from fake IT support asking an employee to install a remote access tool or approve an MFA request. Messages that seem to come from the CEO asking for an urgent transfer, a variant of BEC.

Why they work

Phones feel more personal and less monitored than email, links are harder to inspect on a small screen, and caller ID and SMS sender names can be spoofed. AI voice cloning can now imitate a known person's voice from a short recording, which makes vishing more convincing.

How to reduce the risk

Never share codes or approve MFA requests that you did not start yourself, and prefer MFA that resists phishing. Verify any unusual request by calling back on a known number, not the one provided. Set clear rules for payments and changes of bank details. Include smishing and vishing in security awareness training, since most programmes focus only on email. In Spain, INCIBE offers advice through its 017 helpline.

Related attacks

Both are variants of phishing and are often combined with email in the same campaign, for example an email followed by a call to make it look legitimate.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub