Phishing, Smishing, and Vishing: Match the Attack Channel
These terms are mostly about the delivery channel: phishing is commonly email, smishing is SMS/text, and vishing is voice.
Quick answer
Phishing uses deceptive messages, commonly email, to trick users. Smishing is phishing through SMS or text messages. Vishing uses voice calls or voicemail. The exam cue is usually the communication channel and the manipulation tactic.
Start with the channel
A fake password reset email is phishing. A fake delivery text is smishing. A phone call pretending to be the bank is vishing.
Security+ questions may add urgency, impersonation, links, attachments, or credential theft. Those are manipulation cues, but the term often depends on the channel.
The related control answer may involve user awareness, reporting, email filtering, MFA, or verification procedures.
- Phishing: deceptive message, commonly email.
- Smishing: SMS/text-message phishing.
- Vishing: voice-based social engineering.
- Spear phishing: targeted phishing against a specific person or group.
Social engineering terms compared
Phishing
Best for
Broad deceptive messages, often email.
Exam cue
Email link, fake login page, attachment, urgent message.
Common mistake
Using it when the scenario specifically says SMS or voice.
Smishing
Best for
Text-message scams.
Exam cue
SMS, text, mobile message, delivery notice link.
Common mistake
Calling it generic phishing when smishing is an option.
Vishing
Best for
Voice-call scams.
Exam cue
Phone call, voicemail, caller impersonation.
Common mistake
Choosing phishing because credentials are requested.
Spear phishing
Best for
Targeted phishing.
Exam cue
Personalized attack against an executive, admin, or specific team.
Common mistake
Missing the targeted nature of the message.
Scenario cues to look for
A user receives a text message claiming a package failed delivery and asking them to click a link.
Answer: Smishing
The attack is delivered through SMS/text.
Why not the distractor: It is not vishing because no voice call is involved.
A caller pretends to be IT and asks for a one-time passcode.
Answer: Vishing
The voice-call channel is the strongest cue.
Why not the distractor: Credential theft can happen through many channels, but the call makes it vishing.
An email to the CFO references a current acquisition and links to a fake login page.
Answer: Spear phishing
The email is targeted and personalized.
Why not the distractor: It is more specific than broad phishing.
Common exam mistakes
Choosing based only on the goal of stealing credentials.
Use the channel and targeting cues to pick the exact term.
Ignoring urgency and impersonation.
Urgency and authority are social engineering clues even when the channel differs.
Forgetting verification procedures.
A secure response often means verify through a trusted separate channel.
Quick practice questions
Answer each question to reveal the explanation. The full app adds tracked results and weak-area review.
Q1.A malicious text message asks a user to click a fake delivery link. What is this called?
Q2.A scammer calls a help desk pretending to be an executive. Which term best fits?
Q3.An email is crafted specifically for one administrator using personal details. Which term is most precise?
Ready to test your knowledge?
Try the free CompTIA Security+ practice test, or use the app for tracked weak-area review.