Real-World Attack Scenarios

Voice and SMS Attacks — The Human Side of Social Engineering

Learn how attackers use voice calls and SMS messages to build trust and extract information quickly.

In this lesson, you will learn to:

  • Recognize common vishing and smishing tactics, and describe at least two verification techniques you can use when you receive unexpected calls or SMS.

Voice and SMS Attacks — The Human Side of Social Engineering

This lesson covers vishing (voice phishing) and smishing (SMS phishing). You’ll learn how attackers impersonate trusted entities over the phone and through text, and practice techniques to verify identity in real time.

The Human Voice and the Trust It Creates

A phone call feels personal. When someone speaks to you with a confident, professional tone, it’s natural to trust them. Attackers know this, and they use voice calls — vishing — to bypass the skepticism you might apply to an email. They can spoof phone numbers to look like they’re calling from your bank, your IT department, or even a colleague.

SMS attacks, or smishing, work similarly. A text message feels more intimate than email, and urgency works even better on mobile because people are often distracted when reading texts.

How to protect yourself:

  • If you get an unexpected call asking for sensitive information, hang up and call back using a number you know is legitimate (like the one on your bank card or official website).
  • For SMS messages, treat them like email — don’t click links from unknown numbers, and verify through a separate channel.
  • Remember: legitimate organizations will never ask for passwords, PINs, or full account numbers over the phone or via text.