Attack type comparisons

Vishing vs smishing: what is the difference?

Vishing is a live voice call, so the attacker improvises against the target in real time. Smishing is a text message that works at volume. Vishing converts better per attempt; smishing reaches far more people per campaign.

Vishing needs a human on the line for every attempt, which caps how many targets a campaign can reach but makes each attempt much more persuasive. Smishing costs almost nothing per message, so it is run against very large lists with a low response rate.

They are increasingly used together, because a text establishes a plausible reason for the call that follows.

Documented cases

  • The Retool breach of 2023 is the best single illustration and cost $15M. A text message about a payroll issue was followed by a phone call using a cloned voice of a real colleague. Neither step would have been as effective alone.
  • On the vishing side, the Clorox and Cognizant breach at $380M and the MGM Resorts breach at $100M both turned on a single phone call to a service desk.
  • On the smishing side, the toll-road smishing wave shows the volume model, running across at least six US toll operators with a small-value lure designed to be paid without thought.

The control that breaks both

  • For text: never follow a link in an unexpected message, and reach the organisation through an address or app you already trust.
  • For voice: verify out of band by calling a number you sourced yourself.
  • Because Retool showed a one-time code can be talked out of someone, phishing-resistant MFA using hardware keys is the control that holds when the human check fails.