About this module
Phishing is not confined to email. This lesson covers smishing and vishing: text-message and phone-call attacks that exploit the trust people place in their phones. Smishing pushes a link and tries to make the learner tap before thinking. Vishing uses caller ID spoofing, scripted pressure, and false authority, often with a real voice on the line. Phone-based fraud losses topped $12 billion in 2023, so the habit needs to be simple: pause, question the source, hang up when needed, and verify through an official channel you found yourself.
Key takeaways
Cybercriminals have discovered that your smartphone is one of their most effective tools. In this module we explore smishing and vishing — two phone-based attacks you need to recognize.
Email is no longer the only battlefield. Attackers have expanded their reach to text messages and phone calls, exploiting the trust people naturally place in their mobile devices.
Smishing is S.M.S. phishing. An attacker sends a text that appears to come from a trusted source and lures you into clicking a link or handing over sensitive data without realizing it.
A smishing message creates urgency — act now or lose access. The embedded link redirects you to a counterfeit site that captures whatever you type, from passwords to payment details.
Train yourself to pause before tapping any link in a text.
Look for these three warning signs: unexpected sender, mismatched U.R.L., and high-pressure urgency designed to short-circuit your judgment.
Vishing stands for voice phishing. A caller pretends to be someone you trust — your bank, the I.R.S., or your own I.T. team — using social pressure and scripted urgency to get what they want.
Caller I.D. spoofing makes any number appear on your screen. The attacker then layers on urgency and authority, pushing you to act before your rational mind can catch up with what is actually happening.
The F.T.C. reported more than twelve billion dollars lost to phone-based fraud in 2023. These attacks succeed because they feel personal — a real voice on the line triggers trust in ways email simply cannot.
Legitimate institutions will never ask for your password, M.F.A. code, or full card number over the phone.
If a caller asks for any of these, treat it as a red flag and end the call immediately.
When in doubt, hang up. Then independently look up the organization's official contact number — never redial the number that called you — and call back to confirm whether the request was real.
If you suspect a smishing or vishing attempt, disengage immediately and report it to your I.T. security team. If you already clicked a link or shared credentials, escalate right away — speed limits the damage.
Every unexpected call or text is an opportunity for an attacker. Build the habit of pausing, questioning the source, and verifying through an independent channel before you take any action at all.



