Unphish
Unphish Unphish

Understanding Smishing and Vishing: Phishing that Moves Beyond Traditional Channels

vishing and smishing

When most people think of phishing, they probably think of a suspicious email or a fake website designed to steal their information. But phishing doesn’t just stop there. Scammers are increasingly reaching people through the devices and channels they use every day, including text messages and phone calls.

And these attempts are far from uncommon. In a 2025 survey of 9,397 adults in the US, Pew Research Center found that 68% said they receive scam phone calls at least once a week, while 61% said the same about scam text messages. For some, it is even more frequent, with 31% reporting scam calls and 20% reporting scam texts at least once a day.

When phishing takes place through these channels, it is commonly referred to as smishing when delivered through SMS or text messages and vishing when carried out through voice calls. While the method of contact may be different, both rely on the same basic principle of convincing someone that they are communicating with a person or organisation they trust.

What is smishing?

Smishing is a form of phishing carried out through SMS or text messages. Instead of arriving in an email inbox, the scam appears directly on a person’s phone, often impersonating a business, bank, government agency or another organisation they are likely to recognise and trust.

These messages are usually designed to encourage an immediate response. A recipient might be told that there has been unusual activity on their account, a payment has failed, a parcel cannot be delivered or urgent action is required. The message may then direct them to a link that leads to a phishing website or provide a phone number for them to call.

Scamwatch warns that scam texts commonly impersonate trusted organisations and use urgency to encourage people to click links, which can lead to fake websites designed to steal personal or financial information.

A typical smishing attempt might look something like this.

example of smishing scam

While the message itself is simple, there can be more happening behind it. The scammer is borrowing the trust of a familiar brand, creating a reason to act quickly and directing the recipient towards infrastructure they control. Once there, the victim may be asked to enter login credentials, payment details or other sensitive information.

In Australia, changes are also being introduced to make SMS impersonation more difficult. The SMS Sender ID Register became mandatory on 1 July 2026, requiring organisations that use branded sender IDs to register them. Messages using an unregistered sender ID are relabelled as “Unverified”, helping recipients distinguish registered senders from messages that may be impersonating them.

What is vishing?

Vishing, short for voice phishing, is a form of social engineering carried out over the phone. Rather than directing someone to a fake website, the scammer speaks directly with the victim while pretending to be someone they trust, such as their bank, a government agency, telecommunications provider or another legitimate organisation.

Phone scams remain a major problem in Australia. According to Scamwatch, one in three reported scams happen by phone. During these calls, scammers may claim there is suspicious activity on an account, that money needs to be moved for security reasons or that they need information such as banking details, passwords or one-time codes.

Vishing also does not always begin with an unexpected incoming call. In some cases, scammers place fraudulent phone numbers online and wait for the victim to make contact themselves. A person looking for help may come across the number on an impersonating social media account, phishing page or other online content and believe they are contacting the legitimate organisation.

Our Threat Operations team at Unphish has recently observed this type of activity, with toll-free and international phone numbers appearing across impersonating social media accounts and phishing pages. In some cases, these pages have been designed to direct people to call a number for assistance with flight bookings.

This can make the interaction particularly convincing because the victim believes they have found and contacted the organisation themselves, rather than receiving an unsolicited call.

Smishing and vishing can be part of the same campaign

Smishing and vishing are often discussed as separate threats, but in practice they can be used together as part of the same campaign. A text message may direct someone to call a phone number, a phone conversation may lead them to a phishing website, or a fake support page may encourage the victim to initiate the call themselves.

A simple example could look like this.

1
SMS received

A message claims there has been a suspicious transaction and asks the recipient to call a number immediately.

2
Victim calls the “fraud team”

The number provided in the message connects them with someone pretending to represent the bank.

3
Caller creates urgency

The victim is told their account is at risk and that action is needed straight away.

4
Victim is asked for sensitive information

This could include login details, banking information or a one-time verification code.

Scamwatch warns that scam texts can direct people to call a supplied phone number, while phone scammers may then ask for information such as banking details, passwords or one-time codes. This is why the individual SMS, phone number, domain or support page should not always be treated as separate incidents. They may all form part of the same wider campaign.

Smishing and vishing are still evolving

Smishing and vishing are not new forms of phishing, but the way they are being used continues to change.

The APWG recorded 853,244 phishing attacks in the fourth quarter of 2025. While overall phishing volumes were down compared with the previous quarter, APWG reported that SMS-based fraud detections increased by around 30 to 40% quarter-on-quarter. SMS remains attractive to attackers as it gives them a way to reach people directly on their phones and outside traditional email security controls.

Vishing is evolving too, particularly with the use of artificial intelligence. Scamwatch warns that scammers are using AI to make scams more convincing, including creating fake audio and cloning voices from only a few seconds of recorded material. These cloned voices can then be used to impersonate friends, family members or other trusted people.

For organisations, that risk can extend beyond personal impersonation. The Australian Signals Directorate notes that malicious actors may use AI voice cloning or deepfake technology when impersonating staff or executives, including in attempts to obtain sensitive information or request actions such as password resets or access changes.

The FBI has also warned about real campaigns combining smishing and AI-generated voice messages. In 2025, it reported malicious actors impersonating senior US officials using text messages and AI-generated voice messages to establish trust before attempting to gain access to personal accounts or move conversations onto other platforms.

This is an important shift because voice-based phishing no longer has to rely on a prerecorded message or a scammer simply following a script. With AI, voice impersonation can become more convincing and interactive, allowing the approach to change as the conversation develops and making it harder for the person on the other end to recognise that something is off.

The message or call is only part of the threat

A smishing message or vishing call may be the first thing a victim sees, but it is often only one part of a wider campaign. Behind it can sit phone numbers, sender IDs, phishing domains, fake websites, redirect infrastructure, hosting providers and impersonating social media accounts.

This is why disrupting one asset does not necessarily stop the activity. Taking down a phishing page may remove one part of the attack, but the same campaign can continue through another domain, phone number or account.

Unphish’s campaign clustering

(Unphish’s campaign clustering)

At Unphish, the focus is on looking beyond the individual referral and understanding the wider infrastructure around it. By analysing related indicators and identifying connections between threats, Campaign Clustering & Intelligence can help show when separate messages, calls, domains or accounts are actually part of the same campaign.

From there, the goal is to move from detection through to disruption. Unphish can investigate reported SMS and voice abuse, gather supporting evidence, identify related infrastructure, coordinate enforcement against the assets enabling the campaign and continue monitoring for reappearance.

Detect
Investigate
Disrupt
Understand

Learn more about how Unphish detects, investigates and disrupts smishing and vishing campaigns.

About Unphish

Protect Your Brand with Unphish

Unphish is a threat detection and disruption platform built to identify and take down phishingscams, and digital impersonation at scale. We combine intelligence-led detection with automated enforcement to help organisations protect their brand, customers, and digital ecosystem.

See Unphish in Action

Detect, Validate, and Take Down Threats Automatically

Unphish combines intelligence-led detection with automated enforcement so you can protect your brand, customers, and digital ecosystem without the manual effort.

Create your account