Three Scams, One Goal

Cybercriminals use a variety of channels to trick people into handing over sensitive information — passwords, Social Security numbers, bank account credentials, and more. Three of the most common attack types share the same manipulative goal but reach victims in distinctly different ways: phishing (email), smishing (SMS text), and vishing (voice calls).

Understanding what makes each method unique is the first step toward recognizing and refusing them. These scams are all forms of social engineering — psychological manipulation rather than brute-force hacking.

Primary channel — Phishing Email
Primary channel — Smishing SMS text message
Primary channel — Vishing Voice phone call
Common goal of all three Steal credentials, money, or personal data
Reporting smishing texts (US) Forward to 7726 (SPAM) (FTC consumer guidance)
Reporting vishing and fraud (US) ReportFraud.ftc.gov (Federal Trade Commission)

Phishing: The Email Trap

Phishing is the delivery of a deceptive message via email, designed to impersonate a trusted entity — a bank, a government agency, a retailer, or even a coworker. The goal is to get the recipient to click a malicious link, download an infected attachment, or enter credentials on a fake website.

Phishing emails often display several warning signs:

  • A sender address that looks close to a legitimate domain but contains subtle misspellings (e.g., support@paypa1.com)
  • Urgent language pressing the recipient to act immediately
  • Links that don't match the displayed text when hovered over
  • Generic greetings like "Dear Customer" instead of your name

Spear phishing is a targeted variant where attackers research a specific individual or organization to craft a highly personalized message, making it far more convincing than a generic blast.

Phishing

A cyberattack delivered via email that impersonates a trusted source to steal sensitive information or install malware. It typically involves fraudulent links or attachments.

Smishing

A phishing attack carried out through SMS text messages. Victims are lured to click malicious links or call fraudulent numbers.

Vishing

Voice-based phishing conducted over phone calls. Attackers impersonate banks, government agencies, or support services to extract personal or financial information.

Caller ID Spoofing

A technique that allows a caller to disguise their real phone number and display a different, often trusted number on the recipient's caller ID.

Spear Phishing

A highly targeted form of phishing where the attacker customizes the message using personal details about the victim to make it more convincing.

Multi-Factor Authentication (MFA)

A security process requiring users to verify their identity through two or more methods — such as a password plus a one-time code — before gaining access to an account.

Smishing: Scams via Text Message

Smishing (SMS + phishing) delivers fraudulent messages through text. Attackers exploit the fact that many people open texts more quickly and less critically than emails. Common smishing scenarios include fake package delivery notices, bank fraud alerts, and prize notifications — all containing a link or a number to call.

What makes smishing particularly effective:

  • Mobile screens often hide the full URL, making fake links harder to inspect
  • Texts feel more personal and immediate than email
  • Spam filters for SMS are less robust than email security tools

A message reading "Your USPS package is on hold. Confirm your address: " is a classic smishing template. The link typically leads to a credential-harvesting page or prompts a malware download.

~3.4B

Phishing emails sent daily worldwide

Industry estimates from cybersecurity research organizations consistently place daily phishing email volume in the billions.

98%

Of SMS messages are opened by recipients

Cited widely in mobile marketing and cybersecurity contexts, highlighting why smishing is an attractive attack vector.

1 in 3

Americans targeted by phone scams each year

According to the Federal Trade Commission's consumer sentinel data on fraud reports.

Vishing: Voice-Based Deception

Vishing (voice + phishing) uses phone calls to impersonate trusted callers — the IRS, Social Security Administration, a bank's fraud department, or tech support. Attackers rely on real-time conversation to build pressure and urgency in ways text can't replicate.

Common vishing tactics include:

  • Caller ID spoofing: Making the call appear to come from a legitimate number
  • Robocalls with callbacks: An automated message urges you to call back a fraudulent number
  • Live agents using scripts: A human caller poses as an authority figure and escalates pressure when challenged

A key red flag: legitimate government agencies like the IRS generally do not initiate contact by phone to demand immediate payment. If a caller pressures you for wire transfers, gift cards, or cryptocurrency, treat it as a scam regardless of how convincing the caller sounds.

Government Agencies Rarely Call First

The IRS, Social Security Administration, and Medicare generally do not initiate contact by phone to demand immediate payments or threaten arrest. If you receive such a call, it is almost certainly a scam. Hang up and contact the agency directly through their official website to verify any claimed issue with your account.

How to Protect Yourself Across All Three

While each channel has its own characteristics, the defensive principles overlap considerably:

  1. Pause before acting. Urgency is a manipulation tool. Genuine institutions give you time to verify.
  2. Verify independently. If an email, text, or call claims to be from your bank, hang up or close the message and contact the institution directly using the number on their official website or the back of your card.
  3. Never click unverified links. Type URLs directly into your browser rather than following links in unsolicited messages.
  4. Use multi-factor authentication (MFA). Even if credentials are compromised, MFA adds a second barrier attackers must overcome.
  5. Report scam attempts. Forward phishing emails to reportphishing@apwg.org and smishing texts to 7726 (SPAM). Report vishing calls to the FTC at ReportFraud.ftc.gov.

Staying informed about evolving tactics is equally important. Scam methods adapt quickly, and awareness is a durable defense.

tool

FTC Report Fraud Portal

The Federal Trade Commission's official portal for reporting phishing, smishing, vishing, and other consumer fraud in the United States.

community

Anti-Phishing Working Group (APWG)

An international coalition that tracks and combats phishing. Consumers can forward phishing emails to reportphishing@apwg.org to contribute to active threat intelligence.

guide

CISA: Avoiding Social Engineering and Phishing

The Cybersecurity and Infrastructure Security Agency publishes free guidance on recognizing and defending against phishing and related social engineering attacks.

Share

Technology Editorial Team · Contributor

Technology Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.