Smishing is phishing conducted over SMS/text messages; vishing is phishing conducted over voice calls. Both move the classic email con to channels with weaker filtering and higher implicit trust — your phone.

Side by side

SmishingVishing
ChannelSMS / messaging appsPhone or VoIP call
Typical lureDelivery notices, bank alerts, MFA prompts with a linkImpersonated bank, IT desk, or executive making a live request
Key weaponMalicious links, credential pagesReal-time pressure; increasingly AI voice cloning
Filtering maturityLowNearly none
Enterprise riskCredential theft, MFA fatigueDirect payment fraud (CEO fraud, wire redirection)

How attackers combine them

Modern campaigns chain the channels: a smishing text ("Your account is locked — our fraud team will call you") primes the victim, then the vishing call arrives from a spoofed number to harvest credentials or push a payment. The text manufactures expectation; the voice supplies pressure.

Defenses

For smishing: never act on links in unexpected texts; go to the app or site directly. For vishing: never act on payment or credential requests made in an inbound call; verify via callback to a number on file. For organizations: make that callback mandatory and logged for any payment-affecting request — see the full vishing guide.