At this point, just about everyone has heard of phishing, where fraudulent emails are sent in an attempt to steal personal information, passwords, credit card numbers, and beyond.
But have you ever heard of vishing or smishing?
Similar to phishing, vishing and smishing are showing up more consistently as cybercriminals try to find new and unique ways to take advantage of people. It is crucial that you educate yourself on these topics to ensure you never become a victim of these attacks.
Learn about the differences between vishing vs smishing, their similarities, and ways you can prevent yourself from falling prey to one of these cybercrimes.
What is Vishing?
Vishing is the practice of making phone calls and fraudulently claiming to be a trusted organization while attempting to gather bank information, credit card numbers, and other personal details.
The word vishing is a combination of voice and phishing since these attacks occur over the phone.
In many cases, the cybercriminals who use vishing attacks use fear and other psychological tactics that trick individuals into providing them with their sensitive personal information. These social engineering practices are time-tested as they consistently convince people that they’re at risk of either losing money or could even be facing jail time.
The key thing these attackers do is make their victims feel helpless and that they have no choice but to follow the steps that are laid out for them.
Some of these cybercriminals will be calm and collected, claiming that they are there to help the individual on the other side of the call. But in other instances, vishing attackers will be aggressive and threaten the victim.
Vishing Examples
There are multiple types of vishing to be aware of so that you can separate real phone calls from fake ones.
Call from a bank
A common vishing example is when an attacker calls claiming to be from the victim’s bank or another financial institution. The fraudster will likely claim there is an issue with the person’s account and will request personal details in an attempt to verify their identity.
Contact from investment companies
Similar to bank scams, another type of vishing may come in the form of a call from the individual’s company they use for investing. The caller will often make outlandish claims about investment opportunities that sound too good to be true with time limits to cause a sense of urgency.
Billing from service providers
Ranging from phone companies and internet providers to home utility services, vishing fraudsters may call and state that a person’s account is at risk of being disconnected due to lack of payment.
Social security or health insurance scams
One of the most common vishing examples is when a fraudster calls claiming to be a government official and says the person’s social security number has been suspended. In other cases, the scammer will try to gather health insurance information so they can use the victim’s benefits.
How to Avoid Vishing Attacks
There are plenty of steps you can take so you never become the victim of a vishing attack.
1. Never share your personal information with someone who calls you
It is never safe to assume the person calling you is who they say they are (unless of course it’s a family member or friend). If someone who reaches out to you asks for your personal information, let them know that you’ll call them back at their general customer service number. Any trusted company will have their updated contact information clearly shown on their website.
2. Verify the caller’s identity
On occasion, you may get a call from an organization that will need to verify your information before providing you with the details they have. If this is the case, you can use another phone to call the company and request to speak with the person you’re speaking with as a way to verify their identity.
3. Don’t provide login information over the phone
If your login details, passwords, or other info need to be changed or updated, this can be done online using email or the company’s website. Refuse to give your login to anyone who asks for it over the phone.
What is Smishing?
Smishing is when fraudulent text messages are sent from individuals claiming to be reputable organizations in an attempt to take their credit card information, login details, or other personal info.
The word smishing is a blend of SMS and phishing because these cybercrimes take place through smartphone text messaging.
It has been proven that people are more trusting of a text message than they are of a phone call or email so fraudsters are taking full advantage of it. There is much less awareness of smishing, which makes it easier for these attackers to trick people with messages that sound like they’re from a large company.
According to a study by Gartner, text message response rates are as high as 45%, as opposed to email response rates as low as 6%.
Smishing Examples
The links and phone numbers that are shared in smishing attacks are the main things to watch out for.
Credit card messages
Someone could receive a text message from a credit card company like Capital One that claims the person needs to check their online account status for unusual activity. The link will then take the victim to a fake website that looks similar to Capital One’s page. If the individual puts their login information into the website, it is instantly sent to the scammer so they can use it to steal the credit card details.
Locked bank account
This smishing example would come from a well-known bank such as Chase or Wells Fargo. Similar to the credit card scam, they’ll either link to a fake website or give you a phone number to call where the fraudsters will try to steal your username and password.
Claim your free prize
Who doesn’t like to win something? Smishing scammers will try to establish a high level of excitement by sending a text message that claims a person has won a grand prize. These fraudulent texts come through in an attempt to steal information while claiming they need it to verify your identity before you can be sent the winnings.
How to Avoid Smishing Attacks
Follow these steps to make sure you never end up as the victim of a smishing scam.
1. Don’t respond to people you don’t know
If you don’t recognize a person’s name or phone number, simply ignore the message or delete it. Some smishing attackers will attempt to gather information just by asking for your name or other details.
2. Only click on links from trusted sources
Always verify where a text message came from before clicking on a link that is sent to you. Even when you get a text from a friend, ensure they intended to share it with you.
3. Don’t download third-party apps
You should only ever download apps from reputable sources like the Apple Appstore or the Google Play store.
4. Avoid fake websites
Make sure you double-check links and the websites they send you to when receiving them through SMS messages. Smishing scams will often send you to fake websites with domain names that are different from the company’s real site.
Avoid Vishing and Smishing Attacks By Following Proper Practices
As with all types of cyber-attacks, understanding vishing and smishing is essential to keeping yourself and your personal information safe from would-be attackers. Avoid becoming the next victim by staying up-to-date on current scams and other cybercrimes.
Here at Makios, our blog shares news and updates about recent trends, cybersecurity awareness, and other important details.
and keep up with this industry!