Scams · guide

What do vishing and smishing refer to?

By Alberto Gulotta · Updated · 15 min read

Vishing and smishing refer to phishing that arrives by telephone and by text message. They are names for the delivery route, not for different attacks, and there is exactly one reason to know them: the route decides what you can do about it afterwards.

The definitions below are a public body’s rather than a vendor’s, and the reporting routes are the Federal Trade Commission’s. All sources were read in full on 10 September 2026.

Three words for one attack, named after the channel it arrives on Phishing, smishing and vishing are not three different attacks. They are one attack named after the way it reaches you: an email, a text message, or a telephone call. The Cybersecurity and Infrastructure Security Agency does not use the second and third words at all, and describes phishing messages as arriving in the form of an email, a text, a direct message on social media or a phone call. The goal is identical in every case: to get you to hand over information or press something. ONE ATTACK, THREE DELIVERY ROUTES Phishing an email Smishing a text message Vishing a phone call or voicemail The same request, every time: hand over information, or press something The federal cyber agency uses none of the second two words. It calls all of it phishing. AI Tools Primer · figure
The channel list is CISA’s wording. The two coinages are defined here as the United States Postal Service defines them on its own scams page. Figure drawn by AI Tools Primer.

What the two words refer to

Both are contractions, and both name the delivery route rather than the trick. The United States Postal Service defines them on its own scams page, which is worth preferring to a vendor’s glossary because it is a public body describing attacks aimed at its own customers.

Smishing is phishing by text message. The Postal Service calls it “a form of phishing” and “an unsolicited SMS (text) message”, and describes the shape: “Victims will typically receive a deceptive text message that is intended to lure the recipient into providing their personal or financial information.” It adds the detail that makes these messages convincing: “These scams often attempt to impersonate a government agency, bank, or other company to lend legitimacy to their claims.”

Vishing is phishing by telephone. Again from the same page: “Vishing, short for voice phishing, is an identity fraud scam utilizing a phone call or voicemail.” The caller impersonates somebody and tries to extract login details, personal details or card numbers, and the page notes the pressure that usually comes with it — impersonators “may attempt to coerce you with threats of arrest or some other punishment”.

So: same attack, same goal, different pipe. Phishing is the general word and the other two are it, arriving by text and by voice.

The agencies mostly do not bother with the words

This is worth knowing before you memorise a glossary. The Cybersecurity and Infrastructure Security Agency is the United States government’s own cyber-defence body, and its public page on recognising phishing uses neither “smishing” nor “vishing”. Not once. It describes one thing and lists where it arrives: phishing messages “usually come in the form of an email, text, direct message on social media or phone call”.

That is not an oversight, and it is the shape of the honest answer to the question. The coinages are useful shorthand for talking about the channel, and they are close to useless as categories of threat, because knowing that a message is “smishing” rather than “phishing” tells you nothing about what it wants or how dangerous it is.

They earn their keep in exactly one place, and it is not the definition. It is what happens next.

Why the word matters: three channels, three different things you can do The Federal Trade Commission gives a different reporting route for each channel. A phishing email is forwarded to the Anti-Phishing Working Group at an email address. A phishing text is forwarded to the short code 7726, which helps the mobile network block similar messages. A phone call has nothing to forward at all, because there is no object left over once you have hung up. The attempt itself is reported to the FTC in all three cases. THE SAME ATTACK, AND THREE DIFFERENT THINGS TO DO WITH IT Email forward it to the Anti-Phishing Working Group Text message forward it to short code 7726, which is your own network Phone call nothing to forward. Hang up, then ring back And in all three cases, the attempt goes to the FTC ReportFraud.ftc.gov. That is the part that does not change with the channel, which is why the words are worth knowing at all. AI Tools Primer · figure
All three routes are the Federal Trade Commission’s own, from its pages on phishing and on spam text messages. Figure drawn by AI Tools Primer.

Why the channel matters: three routes, and only one of them is empty

The Federal Trade Commission gives reporting instructions by channel, and reading them side by side is the moment the vocabulary becomes useful. In its own sentence: “If you got a phishing email, forward it to the Anti-Phishing Working Group at reportphishing@apwg.org. If you got a phishing text message, forward it to SPAM (7726). Report the phishing attempt to the FTC at ReportFraud.ftc.gov.”

An email has somewhere to go. It is forwarded whole, headers and all, to an address that collects them.

A text has somewhere to go too, and it is your own network. The FTC’s page on spam texts sets out “three ways to report it” and puts the forwarding first: “Copy the message and forward it to 7726 (SPAM). This helps your wireless provider spot and block similar messages in the future.” Note who benefits: the report goes to the carrier that could stop the next one, not to a filing cabinet.

And a call has nowhere to go at all. Once you hang up there is no object: no header to inspect, no message to forward, nothing to copy. That absence is the entire practical content of the word “vishing”, and it is why the advice for a suspicious call is so much blunter than the advice for a suspicious email.

What the two of them look like in practice

The lures are dull and repetitive, which is the useful thing about them. The Postal Service lists the ones it sees most: “your account has been suspended”, “there is suspicious activity on your account”, “there is a problem with your shipping address” and “there is a package waiting for you at the Post Office”.

All four are the same sentence underneath. Something of yours is in trouble, the trouble is urgent, and the fix is one press away. That structure — a problem you did not know about, plus a deadline, plus a single button — is more reliable as a warning sign than any amount of studying the sender, because it is the part the attacker cannot remove without losing the attack.

The delivery one has become the most common of the lot, and it deserves its own reading because the honest version of the advice is not “the post office never texts”: it does, on a code you have to write to first. On the voice side, the same script delivered by a synthesised voice is a different page again.

The call is the odd one, and knowing why is the useful part An email and a text message both leave an object behind that can be examined and forwarded. A telephone call leaves nothing: there is no header to read, nothing to forward, and the number on the screen was chosen by the caller, because the Federal Communications Commission defines spoofing as deliberately falsifying the information transmitted to your caller ID display. So the only move that works on a call is to end it and dial back on a number you picked yourself. WHAT EACH CHANNEL LEAVES BEHIND FOR YOU TO EXAMINE Email and text an object that stays: an address, a link, something to forward and something to read twice A phone call nothing stays. No header, nothing to forward, and a number the caller chose to display So on a call there is nothing to inspect, and inspecting is the wrong instinct Hang up. Ring back on a number from your card, your app, or your own address book. AI Tools Primer · figure
The definition of spoofing is the Federal Communications Commission’s. Figure drawn by AI Tools Primer.

What to do about a call, since there is nothing to examine

On email and text there is at least an object to look closer at. On a call there is not, and the one piece of evidence a call appears to offer is manufactured by the person calling: the Federal Communications Commission defines it in one sentence. “Spoofing is when a caller deliberately falsifies the information transmitted to your caller ID display to disguise their identity.”

So the number showing your bank’s name is not weak evidence that it is your bank. It is no evidence at all, and why the screen proves nothing is a page of its own. What remains is a rule that needs no judgement: end the call, and start a new one on a number you chose — from the back of the card, from the app, from a statement, from your own address book. If the first call was real, nothing is lost by ringing back. If it was not, the second call reaches the actual organisation and the attempt collapses without your having had to spot anything.

Two things not to do, both of which feel productive. Do not press a key to be taken off a list, because on an automated call answering at all confirms the number reaches somebody. And do not use a number the caller gives you for “verification”; the FTC’s instruction is direct: “Never use the number the caller gave you”.

What to do, by channel, and all of it free

The first line is the same in all three cases. The rest is what the words are for.

Do not act inside the message No links, no attachments, no numbers the message supplies, no codes read out to anybody.
If it was an email: forward it whole To the Anti-Phishing Working Group at reportphishing@apwg.org, which is the address the FTC names.
If it was a text: forward it to short code 7726 The FTC: this “helps your wireless provider spot and block similar messages in the future”. Then report it as junk in the messaging app.
If it was a call: hang up and dial back yourself There is nothing to forward. Use a number from the card, the app or the statement, and never one the caller gave you.
Report the attempt in all three cases ReportFraud.ftc.gov. It is the same destination whichever pipe the attack came down.

Not covered here. This is not a glossary of every word ending in -ishing. The rest of them name narrower slices of the same attack and none of them changes what you do, so adding them would make the page longer and no more useful.

Where this sits. The three words are the vocabulary of phishing and scam calls as a whole. If what arrived was a code you did not ask for, a text from a short code is its own question. If it claimed to be a delivery, the parcel text has an honest version of the rule. If the caller sounded like somebody you know, a cloned voice is a separate matter, and if an account has already been reached, the deadlines start at once.

Where to start

Four ways into this page.

“Just tell me what the words mean.”
Both, from a public source — what the words mean
“Does the distinction actually matter?”
In one place, and it is not the definition — why the channel matters
“A call is happening right now.”
There is nothing to examine, so — the call
“What do these look like?”
The four lures, and the structure under them — what they look like

One word each

The three channels have a page apiece, because the useful part of each is the thing you do rather than the name.

After a message got through

If something was pressed, typed or read out, these are the pages that matter next.

Questions people also ask

What do vishing and smishing mean?

Both name the channel rather than the trick. Smishing is phishing that arrives as a text message; vishing, in the Postal Service’s words, is “short for voice phishing… an identity fraud scam utilizing a phone call or voicemail”. The attack and the goal are the same in each case.

What is the main difference between vishing and smishing?

Only the pipe: voice against text. The difference that matters is what you can do afterwards — a text can be forwarded to your network, and a call leaves nothing behind to forward at all.

Is smishing a type of phishing?

Yes. The Postal Service calls smishing “a form of phishing”, and the federal cyber agency does not use the word at all: it describes one attack that arrives “in the form of an email, text, direct message on social media or phone call”.

How do I report a phishing text message?

The FTC gives three ways, and puts forwarding first: “Copy the message and forward it to 7726 (SPAM). This helps your wireless provider spot and block similar messages in the future.” Then report it as junk in the messaging app, and report the attempt at ReportFraud.ftc.gov.

What should I do about a vishing call?

End it and ring back on a number you chose yourself, from the card, the app or a statement. There is nothing on a call to inspect: the number displayed is chosen by the caller, and the FTC’s rule is “Never use the number the caller gave you”.

Are there other words like these?

Several, and they add nothing operationally. Knowing that a message arrived by text rather than by email changes what you can do with it; a further name for a sub-variety of the same attack does not.

Not covered here. It does not rank the three by danger. They are one attack with three delivery routes, and the route says nothing about how much is at stake.

It does not reproduce the text of a scam message in a form anybody could reuse, and it never suggests replying to one.

And the reporting routes are United States ones. The reasoning holds anywhere; the addresses and the short code do not. What holds instead is simple: the two definitions come from a government page rather than from a company selling protection, the absence of both words from the federal cyber agency’s own guidance was checked by reading it in full, and every reporting route is quoted from the Federal Trade Commission with the date it was read.

Sources

  1. United States Postal Service — Scams & Scheme Alerts: the definitions of smishing as a form of phishing delivered by unsolicited SMS and of vishing as voice phishing by telephone call or voicemail, the four lures seen most often, and the note that impersonators may threaten arrest — faq.usps.com, read 10 September 2026.
  2. Federal Trade Commission — How to recognize and avoid phishing scams: the three reporting routes, one for an email, one for a text message and one for the attempt itself — consumer.ftc.gov, read 10 September 2026.
  3. Federal Trade Commission — How to recognize and report spam text messages: the three ways to report a text, and what forwarding to the short code does for the wireless provider — consumer.ftc.gov, read 10 September 2026.
  4. Cybersecurity and Infrastructure Security Agency — Recognize and Report Phishing: the description of phishing messages arriving as an email, a text, a direct message or a phone call, and the absence of both coinages from the page, checked by reading it in full — www.cisa.gov, read 10 September 2026.
  5. Federal Communications Commission — Caller ID Spoofing: the definition of spoofing as deliberately falsifying the information transmitted to a caller ID display — www.fcc.gov, read 10 September 2026.
  6. Federal Trade Commission — What’s a verification code and why would someone ask me for it? (March 2024): the instruction never to use a number the caller supplied, which is what is left once the display has stopped being evidence — consumer.ftc.gov, read 10 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 10 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.