Vishing is a live voice call, so the attacker improvises against the target in real time. Smishing is a text message that works at volume. Vishing converts better per attempt; smishing reaches far more people per campaign.
Vishing needs a human on the line for every attempt, which caps how many targets a campaign can reach but makes each attempt much more persuasive. Smishing costs almost nothing per message, so it is run against very large lists with a low response rate.
They are increasingly used together, because a text establishes a plausible reason for the call that follows.
Documented cases
- The Retool breach of 2023 is the best single illustration and cost $15M. A text message about a payroll issue was followed by a phone call using a cloned voice of a real colleague. Neither step would have been as effective alone.
- On the vishing side, the Clorox and Cognizant breach at $380M and the MGM Resorts breach at $100M both turned on a single phone call to a service desk.
- On the smishing side, the toll-road smishing wave shows the volume model, running across at least six US toll operators with a small-value lure designed to be paid without thought.
The control that breaks both
- For text: never follow a link in an unexpected message, and reach the organisation through an address or app you already trust.
- For voice: verify out of band by calling a number you sourced yourself.
- Because Retool showed a one-time code can be talked out of someone, phishing-resistant MFA using hardware keys is the control that holds when the human check fails.
Related