Three Channels, One Goal: Stealing Your Information

Scammers don't need sophisticated software to steal your identity or drain your bank account. More often, they rely on a carefully crafted message — delivered by email, text, or phone — to trick you into handing over the information yourself. This manipulation-first approach has a name: social engineering. And three of its most common forms are phishing, smishing, and vishing.

Primary delivery channels Email (phishing), SMS text (smishing), phone call (vishing)
Core manipulation technique Urgency, authority, and fear to prompt quick, unguarded action
Most impersonated entities Banks, IRS, Social Security Administration, delivery services, tech support
Payment methods scammers prefer Gift cards, wire transfers, cryptocurrency — all difficult to reverse
Where to report phishing emails reportphishing@apwg.org (Anti-Phishing Working Group)
Where to report smishing texts Forward to 7726 (SPAM) on most U.S. carriers

Understanding how each tactic works is the first step to recognizing it in real time. These attacks succeed not because victims are careless, but because the messages are designed to feel urgent and legitimate. As explored in our article on social engineering tactics, the human element is almost always the weakest link — not the technology.

Phishing: The Original Email Con

Phishing uses fraudulent emails that impersonate trusted organizations — banks, government agencies, shipping companies, or popular online services. The goal is to get you to click a malicious link, open a dangerous attachment, or enter your credentials into a fake website that looks nearly identical to the real one.

Common phishing warning signs:

  • A sender address that's slightly misspelled (e.g., support@paypa1.com instead of paypal.com)
  • Urgent language: "Your account will be suspended in 24 hours"
  • Generic greetings like "Dear Customer" instead of your name
  • Links that don't match the organization's real domain when you hover over them
  • Requests for passwords, Social Security numbers, or payment details via email

Legitimate organizations virtually never ask for sensitive credentials through email. If a message creates pressure to act immediately, treat that urgency itself as a red flag.

Smishing: Scams Delivered by Text

Smishing (SMS + phishing) follows the same playbook but arrives as a text message. Because people tend to trust texts more than emails — and because texts are harder to filter with spam tools — smishing has become increasingly common. Typical smishing messages claim to be from delivery services, your bank, or government agencies like the IRS or Social Security Administration.

Typical smishing scenarios:

  • "Your package could not be delivered. Confirm your address here: "
  • "Unusual activity detected on your account. Verify now to avoid suspension."
  • "You have a pending tax refund. Claim it at: "

Never tap a link in an unsolicited text. If the message appears to be from a real company, navigate directly to that company's official website by typing the address yourself, or call the number printed on the back of your card or on your official statement.

Smishing and Travel: A Growing Risk

Travelers are particularly vulnerable to smishing because they expect messages about bookings, deliveries, and payments. Scammers exploit this by sending fake alerts that mimic hotel confirmations or package delivery notifications. If you're on the road, our guide to protecting your finances while traveling covers additional precautions worth reviewing before your next trip.

Vishing: Voice Calls as a Weapon

Vishing (voice + phishing) uses phone calls — sometimes with robocall technology or AI-generated voices — to impersonate authority figures. Common personas include IRS agents, Medicare representatives, bank fraud departments, and tech support staff. Callers often spoof their caller ID to display a number that looks official.

Vishing red flags:

  • Unsolicited calls claiming your account has been compromised
  • Requests to verify personal information you "already provided" as a security check
  • Demands for payment via gift cards, wire transfer, or cryptocurrency
  • Threats of immediate arrest or account closure to create panic

The IRS, Social Security Administration, and Medicare do not demand immediate payment over the phone or threaten arrest. If you receive a suspicious call, hang up and contact the agency directly using a number from their official website.

Once you can recognize these threats, layering on stronger account security makes a real difference. Our guide on authenticator apps versus SMS codes explains why some two-factor authentication methods are more resistant to interception than others.

What to Do If You Think You've Been Targeted

If you suspect you've received a phishing email, smishing text, or vishing call, take these steps:

  1. Don't engage further. Don't reply, click links, call back an unknown number, or provide any information.
  2. Report it. Forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org. Report smishing to your carrier by forwarding texts to 7726 (SPAM). Report fraud calls to the FTC at reportfraud.ftc.gov.
  3. Change your credentials if you clicked a link or entered any information, and enable two-factor authentication on affected accounts.
  4. Monitor your accounts for unusual activity and consider placing a fraud alert with the major credit bureaus.

It's also worth reviewing the common online safety myths that can give people a false sense of security — because being skeptical and informed remains your most reliable defense against scammers who constantly refine their approach.