top of page
Search

Phishing, Vishing, SMiShing... what are they?

Don't be reeled in by scammers!
Don't be reeled in by scammers!

There are a lot of terms out there for different kind of communications scames, and many of them sound similar. Here at the Scam Hound, we want to help you recognise the terms and what they mean. Here are a few of the more common examples.


  • Phishing: Chances are you've heard of this one. It usually arrives to you in the form of an email, sent to many accounts and is usually not personalised to you specifically. In essence, it's casting a wide net to see who gets caught. The scammer's plan is for you to download a file and open it, open an attachment or fill in some details, and that data will be used to launch a cyber attack in the future. It may be something as simple as a link to a fake gift card, so if you're unaware that something like that is on its way to you, be suspicious.


  • Vishing: Probably more relevant to your phone, vishing (voice & phishing) is a phone call where a scammer will try to get you to reveal personal information. They may pretend to be a utilities provider, a bank or your mobile phone network provider - anything to get you to confirm sensitive information. They may have a caller ID to make them look more legitimate and may use Aritifical Intelligence to spoof a voice to make it sound like a family member or a friend. The scammer may also be trying to get a sample of your voice on the call to try and use it for a voice identification to get into an account of yours for which they already have details, so if you're unsure of the ligitimacy of the call, say as little as possible.


  • SMiShing: No, that's not a caps lock error - the SMS are capitalised because this is a text message scam. Like phishing and vishing, it's designed to get you to divulge personal sensitive information such as bank account details, credit card numbers or login details. This may be more common that you think - consider when you receive a text message for a delivery, that message could be fake and it's telling you about a delivery that you don't remember or may be mixed among legitimate messages, considering how many things we have delivered to our homes via courier. Be wary when clicking on links.


  • Spear Phishing: As mentioned, phishing casts a wide net with impersonal emails to see who bites - spear phishing is more targeted, aimed at a specific person, company or organisation. It may include details like recent online purchases or website visits.


  • Angler phishing: This targets social media, your Facebook, Instagram, TikTok, X accounts for example. Scammers pretend to be from customer support to get your email, passwords and the like to log into your account, change passwords and lock you out. If a representative contacts you, you may be invited to download something for a video chat - that's malware, and it could give criminals access to your phone.


  • Clone phishing: Does that email address look right? Maybe a capital i has been swapped for a lower case l, or maybe that m is really two n's? That's a scammer trying to imitate a company to get you to click on a modified link to take to to a site they've set up to grab information from yourself. Check email addresses to see if they come from the legitimate website.


  • Evil Twin Phishing: When you're out in public and you need to hook into a public wi-fi network, be careful. Evil twin phishing sees a scammer set up a fake wi-fi option that mimics a real one, allowing hackers to steal personal information from your phone or laptop. It may disable the legitimate network, direct you to a login page for the fake one, and once you input your details, the scammer has your personal data.


  • Quishing: Watch out for the links provided by QR codes, they could be sending you to a criminals fake web page.


  • Whaling: If you're high up in a company, this is for you. Like spear phishing, this is a specific target - however, these scammers are going for the big fish, C-suite members, those with big responsibilities and lots of different accesses within a business computer network. That information could be used by a fraudster further down the line to imitate a vendor or partner and use personalised information on the person or company to ook more legitimate.


If you do get caught out, don't be embarrassed - these scammers have become extremely good over the years at faking legitimacy, and with the rise of AI, it's going to become even trickier. However, there are some things you can do to protect yourself:


  • If the sender has contacted you unsolicited, is trying to hurry you into taking action, requesting personal or confidential information, offering specific weblinks, or simply sounds too good to be true, it could possibly be a scammer. Remain calm, don't be railroaded into making quick decisions. Close the email or text message, or end the call and give yourself time to think about it. Talk to others, it will help to gain some clarity.


  • For workplaces, use trusted anti phishing software to protect your company. Back up information, keep anti-virus and anti-malware software up to date, use multi-factor identification where possible, and encouraged staff members to report anything suspicious, no matter how small or innocuous.

 
 
 

Comments


bottom of page