logo

Vishing & Smishing

Category:

Social Engineering

Summary:

How voice (vishing) and SMS (smishing) social engineering pressure targets into handing over credentials, MFA codes, or access — and how to test and defend.

Vishing and smishing are phishing over the phone and text message instead of email — a caller impersonating IT support or a bank, or an SMS with a link to a fake login portal. Voice and SMS dodge email filtering entirely and carry a sense of urgency that’s hard to replicate in writing, making them especially potent for MFA-code theft and help-desk manipulation. Both are close kin of pretexting and business email compromise, which often share the same fabricated backstory.

Common Techniques

  • IT/help-desk impersonation — a caller poses as internal support to talk a target through a password reset or remote-access install.
  • MFA-code interception — “read me the code we just sent you” turns a legitimate one-time passcode into a handover.
  • SIM-swap-enabled resets — a hijacked phone number intercepts SMS codes and account-recovery texts directly.
  • Smishing links to AiTM portals — a text message drives the target to a proxy login page that steals credentials and session cookies.
  • Caller-ID spoofing — the display name and number are forged to match a trusted bank, vendor, or internal extension.
  • Deepfake voice — synthesized audio of an executive’s voice adds pressure to a rushed, urgent request.

Want to save time on reporting?

Let PentestPad generate, track, and export your reports - automatically.

logo-cta

Testing

Within authorized scope, a scripted call and SMS campaign targets a sample of staff, measuring who discloses information, who stops to verify the caller’s identity, and who reports the attempt. Track outcomes per target rather than just an aggregate success rate — the gap between “clicked” and “reported” is often where the real signal is. Log every attempt, response, and any disclosed data in the pentest report as you go.

Remediation

Roll out phishing-resistant MFA (FIDO2 / passkeys) so a read-aloud code has nothing to unlock. Require help-desk callback verification and stronger identity-proofing before any password reset or account change. Mandate out-of-band confirmation for sensitive requests — a second channel the attacker doesn’t control. Train staff on these specific pretexts and make reporting a suspicious call or text effortless.