Common scenarios
Texts about a parcel delivery, a blocked bank card or an unpaid fine that link to a fake website. Calls from fake bank staff asking to confirm a code, or from fake IT support asking an employee to install a remote access tool or approve an MFA request. Messages that seem to come from the CEO asking for an urgent transfer, a variant of BEC.
Why they work
Phones feel more personal and less monitored than email, links are harder to inspect on a small screen, and caller ID and SMS sender names can be spoofed. AI voice cloning can now imitate a known person's voice from a short recording, which makes vishing more convincing.
How to reduce the risk
Never share codes or approve MFA requests that you did not start yourself, and prefer MFA that resists phishing. Verify any unusual request by calling back on a known number, not the one provided. Set clear rules for payments and changes of bank details. Include smishing and vishing in security awareness training, since most programmes focus only on email. In Spain, INCIBE offers advice through its 017 helpline.
Related attacks
Both are variants of phishing and are often combined with email in the same campaign, for example an email followed by a call to make it look legitimate.




