Cybersecurity

Vishing and Smishing: Phone and Text Scams Targeting Businesses

Recognize voice phishing and SMS phishing attacks against employees and build simple verification habits.

Reviewed October 11, 2026 3 minute read Reviewed by Meta IT Pro
Vishing and Smishing: Phone and Text Scams Targeting Businesses — Cybersecurity illustration from Meta IT Pro
Part of the Cybersecurity Learning Center

Vishing uses phone calls and voicemails, and smishing uses text messages, to trick people into sharing information, approving access, or sending money. They often bypass email security entirely.

Key takeaways

What to know before you act

  • Phone and text attacks bypass email filters and feel more personal, which makes them effective.
  • Help desks are a prime target: attackers impersonate employees to get passwords or MFA reset.
  • Calling back on a known number is the single most effective defense.

Why it matters

What business leaders should understand

Attackers impersonate banks, IT support, executives, and vendors by phone and text because those channels feel personal and urgent. Help desks and finance teams are frequent targets.

The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.

Common vishing and smishing scenarios

Attackers often combine channels—sending a text first, then calling, or following up a phishing email with a phone call to make it seem legitimate.

  • Fake IT support calling to 'fix' a problem and asking for an MFA code or remote access.
  • Texts about unpaid tolls, package deliveries, or locked bank accounts with links.
  • An 'employee' calling the help desk to reset a password or register a new phone for MFA.
  • A 'vendor' calling accounts payable to update banking details.
  • Executive impersonation via text asking for gift cards or an urgent favor.

Building verification into daily work

Train everyone to treat unsolicited calls and texts asking for credentials, codes, or payments as suspicious. Legitimate IT staff and banks will not ask for your MFA code.

Give the help desk a clear identity-verification procedure before resetting passwords or MFA—for example, a callback to the number in the HR system or confirmation from the employee's manager. Make it easy to report suspicious calls and texts so IT can warn others.

  • Hang up and call back using a number from your records.
  • Never read an MFA code or approve a prompt for someone else.
  • Do not tap links in unexpected texts; navigate to the site directly.
  • Forward scam texts to 7726 (SPAM) and report them to IT.

Practical action plan

Steps your business can take

01

Never share passwords, MFA codes, or remote access with an unsolicited caller.

02

Hang up and call back using a number you already trust.

03

Verify identity before resetting passwords or MFA by phone.

04

Report suspicious calls and texts to IT so others can be warned.

Recommended next steps

Continue from this article.

These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.

Warning signs

Do not ignore these indicators

  • A caller claims to be IT and asks for an MFA code
  • Texts about account problems, deliveries, or unpaid tolls with links
  • Pressure to act immediately or keep the request confidential

Frequently asked questions

Common questions, answered.

What is the difference between vishing and smishing?

Vishing is voice phishing by phone; smishing is phishing by text message.

Will IT support ever ask for my MFA code?

No. Legitimate IT staff should never ask you to read an MFA code or approve a prompt for them.

How do I report a scam text?

Forward it to 7726 (SPAM) and report it to your IT team.

How Meta IT Pro can help

Related services and practical next steps

Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.

Authoritative references

Sources and further reading

These primary sources support the guidance in this article and provide additional technical or consumer information.

Need help with your IT solution?

Get practical guidance from a local IT and cybersecurity team.

Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.