Phishing, smishing, and vishing are all social engineering attacks that try to trick you into revealing credentials, personal information, or money — but they use different channels and different psychological tactics. Knowing the difference between them is the first step to recognizing and resisting each one.
Phishing: Email-Based Attacks
Channel: Email
Phishing is the broadest term and the one that started it all. Attackers send fraudulent emails impersonating trusted organizations — banks, tech companies, government agencies, employers. The goal is to get you to click a link that leads to a credential-harvesting page, download a malicious attachment, or respond with sensitive information.
Why it works: Email is a professional communication channel. We’re conditioned to treat official-looking emails with credibility, especially from brands we recognize and trust. The volume — billions of phishing emails sent daily — means even low success rates yield millions of victims.
Variants:
- Spear phishing — Targeted attacks against specific individuals using personal information about the victim to create convincing lures. Much higher success rate than mass phishing.
- Whaling — Spear phishing specifically targeting executives and high-value individuals.
- Business Email Compromise (BEC) — Compromising a real business email account to use legitimately in fraud, rather than just impersonating it.
Smishing: SMS Text Message Attacks
Channel: SMS text messages
Smishing (SMS + phishing) uses text messages rather than email. The format is typically brief and urgent: “Your bank account has been locked. Click here to verify: [shortened URL]” or “USPS: Your package has a problem. Update your delivery info: [link].”
Why it works: SMS has a much higher open rate than email — most people open text messages within minutes. There’s also less spam filtering on SMS. People are less suspicious of text messages from seemingly official sources, and shortened URLs in texts make it harder to evaluate the destination before clicking.
Common smishing scenarios:
- Bank or credit card fraud alerts
- Package delivery problems (USPS, FedEx, UPS)
- Winning a prize or receiving a payment
- Vaccine appointment or contact tracing style scams
- Two-factor authentication spoofing (“There’s a problem with your 2FA setup”)
Vishing: Voice Call Attacks
Channel: Phone calls (voice)
Vishing (voice + phishing) uses phone calls to impersonate technical support, banks, government agencies, or utility companies. The attacker calls you (or tricks you into calling a fake number) and uses social engineering to extract information or instruct you to take actions that compromise your security.
Why it works: Real-time conversation creates pressure. It’s harder to pause and evaluate claims when a caller is waiting for your response. Attackers also use spoofed caller IDs that display the genuine number of the organization they’re impersonating — your phone shows “IRS” or “Bank of America” even though it’s a scammer.
Common vishing scenarios:
- Fake tech support (“We’ve detected a virus on your computer”)
- IRS/tax authority calls threatening arrest for unpaid taxes
- Bank fraud departments asking you to “verify” your card number or PIN
- Social Security Administration calls about suspended benefits
- Calls claiming you’ve won something and need to pay a fee to claim it
Quishing: QR Code Phishing
Channel: QR codes
Quishing is the newest variant, using malicious QR codes instead of clickable links. Because QR codes can’t be visually inspected the way a URL can before scanning, they bypass one of the most reliable phishing defenses entirely. Common vectors include fake parking ticket notices with a QR code for “payment,” fraudulent stickers placed over legitimate QR codes on restaurant menus or parking meters, and emails containing a QR code specifically to evade email link-scanning filters (which typically scan text-based URLs, not embedded images).
Why it works: Most people have no habit of scrutinizing a QR code destination before scanning, because the format is relatively new and phone cameras auto-scan on focus. The destination URL is completely hidden until after you’ve already scanned it.
Sample Messages: What Each Attack Actually Looks Like
| Channel | Example Message |
|---|---|
| Phishing (email) | “Subject: Unusual sign-in activity detected. Verify your identity within 24 hours or your account will be suspended.” |
| Smishing (SMS) | “USPS: We could not deliver your package. Update your info here: usps-info.xyz/track” |
| Vishing (call) | “This is the fraud department at [Your Bank]. We’ve flagged a suspicious $2,400 charge — can you confirm your card number to cancel it?” |
| Quishing (QR) | A sticker over a parking meter’s real QR code, leading to a fake “PayByPhone” clone site requesting card details |
Key Differences at a Glance
- Phishing — Email, higher volume, often automated, less personalized
- Smishing — SMS, high open rates, brief and urgent, often uses shortened links
- Vishing — Phone calls, real-time pressure, spoofed caller ID, harder to verify
- Quishing — QR codes, destination hidden until scanned, bypasses link-based filters
Why Attackers Increasingly Combine Channels
Modern scams often chain multiple channels together specifically because it increases believability. A common pattern: an SMS arrives first (“Your package couldn’t be delivered”), and if the target doesn’t respond, a follow-up phone call arrives claiming to be from the same shipping company “confirming” the earlier text. Each channel reinforces the other’s credibility, making a target who might catch a single-channel red flag less likely to question a coordinated, multi-touch approach. This is sometimes called a “combo attack” or “multi-channel social engineering,” and it’s becoming standard practice in more sophisticated fraud operations, particularly ones involving fake tech support or financial fraud.
Reporting Each Channel
Each channel has a dedicated reporting path: forward phishing emails to your provider’s “report phishing” tool or to [email protected]; forward smishing texts to 7726 (SPAM) in the US, which routes them to your carrier’s fraud team; report vishing calls to the FTC at reportfraud.ftc.gov and to your phone carrier; and report quishing by alerting the property owner (restaurant, parking authority) if it involves a tampered physical QR code sticker. See our full guide on reporting phishing emails and websites for the complete list of reporting channels and what happens after you report.
Why These Attacks Cost More Than People Expect
The financial and time cost of falling for any of these four attack types is rarely limited to the initial transaction. A successful vishing attack that captures a bank card number typically leads to hours spent disputing charges, replacing the card, and updating autopay details across every service linked to it. A smishing attack that captures a delivery account login can expose saved addresses and order history, useful for follow-up targeted scams. And a phishing email that compromises a work account can trigger an incident response process that consumes far more organizational time than the few seconds it took to click the original link. The visible cost (a fraudulent charge, a locked account) is usually the smallest part of the total cost.
Testing Your Own Recognition Skills
Because these four channels rely on different sensory cues — reading an email, reading a text, hearing a voice, or scanning an image — building resistance to one doesn’t automatically build resistance to the others. It’s worth deliberately thinking through how you’d react to each: would you notice a spoofed caller ID if your bank’s real number appeared on your screen mid-afternoon? Would you pause before scanning a QR code taped to a parking meter? Walking through these scenarios in a calm moment, rather than encountering them cold under pressure, is what actually builds the reflex to pause and verify.
Universal Defenses Against All Four
The tactics differ but the defenses converge:
- Never provide information in response to unsolicited contact — hang up, don’t click, don’t scan. If it seems legitimate, contact the organization directly using the number on their official website.
- Caller ID cannot be trusted — spoofing is trivial and common. A call showing your bank’s number may not be your bank.
- Urgency is a manipulation technique — legitimate organizations give you time to verify.
- QR codes should be treated like unknown links — if a preview URL appears after scanning, evaluate it before tapping through, exactly as you would a text link.
- Use the Phishing Link Scanner to analyze any URLs received via text, email, or revealed by a QR code before visiting them.
Frequently Asked Questions
Q: Which of these attack types is most common today?
A: Email phishing still accounts for the largest overall volume, but smishing has grown fastest in recent years as SMS open rates remain far higher than email and spam filtering on text messages is comparatively weak.
Q: Can my phone carrier actually stop smishing texts?
A: Carriers filter a portion of known spam and scam numbers, but attackers rotate numbers constantly, so filtering catches known patterns rather than preventing all attempts. Forwarding smishing texts to 7726 helps carriers improve their filters over time.
Q: Is it safe to scan a QR code in a public place like a restaurant?
A: Generally yes for menus you expect, but check that the code isn’t a sticker placed over the original, especially on parking meters and payment kiosks, which are common quishing targets. If your phone shows a URL preview before opening, read it before proceeding.
Q: Why do vishing calls feel more convincing than phishing emails?
A: Real-time conversation removes your ability to pause, research, and verify at your own pace, and spoofed caller ID adds a false sense of legitimacy before the conversation even begins.
Q: If I get a suspicious call, is it safe to call back the number that called me?
A: No — call back using a number you look up independently (the back of your card, the company’s official website), never the number the caller provided or that appears in caller ID, since both can be spoofed.
Related Reading
- How to Tell If a Link Is Phishing Before You Click
- 5 Real Phishing Email Examples and Their Tells
- Clicked a Phishing Link? What to Do Right Now
- How to Report a Phishing Email or Website
- Try our free Phishing Link Scanner →
About This Article
Written and reviewed by the Sites Security Services editorial team. Our content is researched using AI-assisted tools and reviewed for accuracy before publication. We are committed to practical, jargon-free cybersecurity guidance for everyday internet users — with no products to sell and no data stored after your session.
Learn about our editorial standards →