What Is The Difference Between Phishing, Smishing & Vishing? 

Promotion

According to recent statistics, an internet user falls victim to cybercrime every 37 seconds. And since we’re spending more of our lives online, the problem only looks set to worsen. From 2020 to 2021, for example, cybercrime increased by 40 percent. This is likely due to more people using personal electronic devices for work and being online more during the COVID-19 lockdowns. 

Online scammers carry out identity fraud in various ways. From scam calls to fraudulent emails, and everything in between. Once they have your sensitive data, they can then steal your money, take out loans in your name, sell your credentials on the Dark Web, and impersonate you to commit crimes in other ways. 

With the increased threat of cybercrime, we are constantly being reminded to stay vigilant and aware of how fraudsters operate. The more we understand scams, the better equipped we are to avoid becoming victims. 

When being warned about cybercrime, you may have heard the terms "phishing", "smashing", and “vishing”. They sound similar, but you may be wondering whether they mean the same thing. Keep reading to find out. 

Are Phishing, Smishing and Vishing the same? 

Phishing, smishing and vishing are all types of identity fraud whereby scammers contact you in an attempt to steal your personal details or financial information. The fraudster pretends to be a trusted company or organisation, encouraging the recipient to voluntarily hand over confidential data or follow a link that installs malware like viruses, spyware, ransomware or adware on their device. 

The way you are targeted differs depending on which method the scammer uses. Phishing attacks are made over email, smishing is carried out via text messages, and vishing takes place over the phone. 

In this article, we’ll explain these terms in more detail, give tips on how to protect yourself against cyber attacks and advise on what to do if you do become a victim. 

What is Phishing? 

Phishing is a method of cyber fraud that’s carried out over email. The email will usually contain a malicious link that takes the recipient to what appears to be a legitimate website asking them to input sensitive data like usernames and passwords or financial information like bank details. This data will then be sent directly to the fraudsters, with the victim only becoming aware of what’s happened once it is too late. 

Often, fraudsters will duplicate the website of an official department or trusted brand to trick — or scare — people into thinking it is the real thing. The scammer may claim that the recipient’s account is locked and ask them to re-enter their login details on the fake site. 

Phishing attacks are usually designed with one or more of the following goals in mind: 

  • To inject malware 
  • To gain access to confidential information 
  • To receive money via a bank transfer or similar 

Cybercriminals are known for sending generic emails to a vast amount of people in the hope that some will be fooled. In marketing, this is known as the “Spray and Pray” method. 

What is Smishing? 

Smishing — or SMS phishing — is done over text or messaging apps and, again, will usually contain a malicious link from a company that seems legitimate. Smishing messages that pose as delivery companies, government bodies and banks are most common because these organisations often communicate with their customers via text message. When the fraudulent link is clicked on, victims will be taken to a form that is designed to either steal their data or download malware to their devices. Often, the link will be a shortened URL (which is harder to recognise as fake) urging recipients to take immediate action in the form of paying a postage fee for a parcel which is to be delivered, claiming a prize within a specific time period or verifying their identity because their financial details have been compromised.  

It is the urgency of these messages that makes these scam messages so effective. Additionally, they can be more successful than phishing and vishing scams because text messages feel more informal and personal (and therefore more trustworthy). Plus, mobile phones don’t tend to be as well protected as computers. 

What is Vishing? 

Phishing that’s done over the telephone is called vishing, because it is “voice” phishing.  

Again, the scammer will pretend to be from a legitimate organisation urging immediate action in order to acquire personal data from individuals, such as their bank details or login information, to gain access to their accounts. 

In the past, fraudulent phone calls were relatively easy to spot as they would be from an unknown number, and the caller would ask for bank details or money right away. Today, fraudsters are using increasingly sophisticated techniques to obtain the information they want. For example, a sophisticated phishing attack may start with a scam email and follow up with a vishing call from a fake caller ID to make the scene appear more convincing. Some may even record the call and prompt you to say the word “Yes” so they can use the recording to impersonate you on another phone call to authorise payments or access your bank accounts. 

How to Protect Yourself from Cyber Attacks 

As well as trying to trick individuals with these scams, cybercriminals target businesses too. This means everyone should take measures to protect themselves from cyber fraud. 

As mentioned, being aware of the techniques scammers use can make you less likely to fall victim. With that in mind, some of the signs to look out for include:  

  • A threatening or urgent tone -  An email, text message or phone call that urges you to take immediate action. 
  • Unexpected messages or phone calls - Especially if they sound too good to be true or try to intimidate you. 
  • An unknown sender or caller - If you don’t recognise the brand or organisation that’s contacted you, it may be a scam. 
  • A request for personal or financial information - For example, bank account details, credit card numbers or login details. 
  • Links - These may look like they come from a legitimate company, but they could be malicious links, especially if they look strange (for example, words broken up with dots or ending with something other than .com, .co.uk or .org). 
  • Errors - While more sophisticated scams appear convincing, others can be identified by spelling errors and grammatical mistakes 

If you are unsure about whether a phone call or message is a scam, you may find the following tips helpful: 

  • Instead of clicking on links you’ve been sent, visit the website via a search engine or by typing in the address of the organisation 
  • Refuse requests to modify your login details or other settings 
  • If you recognise the organisation, call them on their official phone number and ask them to verify that it was them who contacted you 
  • Don’t answer calls or text messages from numbers you don’t recognise, as doing so confirms that the number is in use and could increase the amount of scam calls you get 
  • Never reveal personal or financial information to someone who contacts you unexpectedly 
  • Type the details of the call or text into a search engine to see whether others have reported it as a scam 

Additionally, it is wise to install anti-phishing software to block malicious emails. 

What to do if you are the Victim of Cyber Fraud 

If you are unfortunate enough to fall victim to a scam, it is important that you do the following: 

  1. Block or suspend the account that’s been compromised 
  2. Report the scam to your bank or the police 
  3. Report the scam to a fraud prevention body like ActionFraud or the National Cyber Security Centre (NCSC). 

Summary 

Phishing, smishing and vishing are all types of identity fraud, whereby scammers posing as businesses, banks, official bodies, or charities contact you in an attempt to steal your personal details or financial information. The fraudster encourages the recipient to voluntarily hand over confidential data or follow a link that installs malware like viruses, spyware, ransomware or adware on their device. 

The way you are targeted differs depending on which method the scammer uses, which nowadays can include a phone call, email or via text message, so it's vital to have a good understanding of how these scams work. 

You Might Also Read:

What Is Email Spoofing & How to Protect Your Organization:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« What The Latest Cybersecurity Trends Mean For Your SME 
Which Sectors Are Top Targets For Cyber Crime? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

WizNucleus

WizNucleus

WizNucleus develops, markets and supports a software platform (Cyberwiz-Pro) that enables Critical Infrastructure enterprises to ensure the future state of their cybersecurity and remain compliant.

ExpressVPN

ExpressVPN

ExpressVPN is a Virtual Private Network services provider offering secure encrypted access to the internet.

Dracoon

Dracoon

DRACOON is market leader in the German-speaking region for secure enterprise file sharing.

Netsecurity AS

Netsecurity AS

Netsecurity is a Norwegian owned company focused and specialised within IT security and cybersecurity-as-a service.

In-Sec-M

In-Sec-M

In-Sec-M is a non-profit organization that brings together companies, learning and research institutions, and government actors to increase competitiveness of the Canadian cybersecurity industry.

Fortress Information Security

Fortress Information Security

Fortress Information Security is one of the largest cyber security providers of supply chain risk management and vulnerability risk management in the US.

OurCrowd

OurCrowd

OurCrowd is a leading equity crowdfunding platform for investing in global startups.

Qualcomm Technologies

Qualcomm Technologies

Qualcomm invents breakthrough technologies that transform how the world connects, computes and communicates.

Stealth Software Technologies

Stealth Software Technologies

Stealth Software Technologies is focused on the generation of research and software products focused on applied cryptography and cybersecurity.

Avancer Corporation

Avancer Corporation

Avancer Corporation is a multi-system integrator focusing on Identity and Access Management (IAM) Technology. Founded in 2004.

ViewQwest

ViewQwest

ViewQwest is a regional telecommunications & information technology services company. We specialize in providing Connectivity, Managed Network, Managed SD-WAN, and Managed Security solutions.

Vaultinum

Vaultinum

Vaultinum are a trusted independent third party specialized in the protection and audit of digital assets.

DruvStar

DruvStar

DruvStar provides B2B cybersecurity around threat management to strengthen businesses across attack vectors.

Ceeyu

Ceeyu

Ceeyu is an all-in-one cybersecurity ratings and third party risk management platform.

PingSafe

PingSafe

PingSafe is creating the next-generation cloud security platform powered by attackers' intelligence, providing coverage for vulnerabilities that traditional security solutions would otherwise overlook

C/side (cside)

C/side (cside)

At c/side, we're creating the ultimate delivery, performance and detection mechanism for browser-side fetched 3rd party Javascript.