Vishing uses phone calls and voicemails, and smishing uses text messages, to trick people into sharing information, approving access, or sending money. They often bypass email security entirely.
Key takeaways
What to know before you act
- Phone and text attacks bypass email filters and feel more personal, which makes them effective.
- Help desks are a prime target: attackers impersonate employees to get passwords or MFA reset.
- Calling back on a known number is the single most effective defense.
Why it matters
What business leaders should understand
Attackers impersonate banks, IT support, executives, and vendors by phone and text because those channels feel personal and urgent. Help desks and finance teams are frequent targets.
The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.
Learn how Meta IT Pro can help with cybersecurity services and security awareness training.
Related reading: What is social engineering? and Deepfake and AI voice scams.
Common vishing and smishing scenarios
Attackers often combine channels—sending a text first, then calling, or following up a phishing email with a phone call to make it seem legitimate.
- Fake IT support calling to 'fix' a problem and asking for an MFA code or remote access.
- Texts about unpaid tolls, package deliveries, or locked bank accounts with links.
- An 'employee' calling the help desk to reset a password or register a new phone for MFA.
- A 'vendor' calling accounts payable to update banking details.
- Executive impersonation via text asking for gift cards or an urgent favor.
Building verification into daily work
Train everyone to treat unsolicited calls and texts asking for credentials, codes, or payments as suspicious. Legitimate IT staff and banks will not ask for your MFA code.
Give the help desk a clear identity-verification procedure before resetting passwords or MFA—for example, a callback to the number in the HR system or confirmation from the employee's manager. Make it easy to report suspicious calls and texts so IT can warn others.
- Hang up and call back using a number from your records.
- Never read an MFA code or approve a prompt for someone else.
- Do not tap links in unexpected texts; navigate to the site directly.
- Forward scam texts to 7726 (SPAM) and report them to IT.
Practical action plan
Steps your business can take
Never share passwords, MFA codes, or remote access with an unsolicited caller.
Hang up and call back using a number you already trust.
Verify identity before resetting passwords or MFA by phone.
Report suspicious calls and texts to IT so others can be warned.
Recommended next steps
Continue from this article.
These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.
Related guide
What is social engineering?
Understand the tactics behind phone and text scams.
Explore nextRelated guide
Deepfake and AI voice scams
Prepare for cloned voices in phone-based fraud.
Explore nextRelated guide
QR code phishing
Recognize another way attackers move victims to their phones.
Explore nextWarning signs
Do not ignore these indicators
- A caller claims to be IT and asks for an MFA code
- Texts about account problems, deliveries, or unpaid tolls with links
- Pressure to act immediately or keep the request confidential
Frequently asked questions
Common questions, answered.
What is the difference between vishing and smishing?
Vishing is voice phishing by phone; smishing is phishing by text message.
Will IT support ever ask for my MFA code?
No. Legitimate IT staff should never ask you to read an MFA code or approve a prompt for them.
How do I report a scam text?
Forward it to 7726 (SPAM) and report it to your IT team.
How Meta IT Pro can help
Related services and practical next steps
Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.
Authoritative references
Sources and further reading
These primary sources support the guidance in this article and provide additional technical or consumer information.
Federal Trade Commission
Phone Scams
FTC guidance on recognizing phone scams and what to do about them.
Federal Trade Commission
How To Recognize and Report Spam Text Messages
FTC guidance on spotting, filtering, and reporting scam text messages.
Cybersecurity and Infrastructure Security Agency
Avoiding Social Engineering and Phishing Attacks
CISA's explanation of social engineering tactics and practical ways to avoid becoming a victim.
Need help with your IT solution?
Get practical guidance from a local IT and cybersecurity team.
Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.
