Three Channels, One Goal

Scammers don't limit themselves to a single approach. They exploit whichever communication channel is most likely to catch you off guard — your email inbox, your SMS messages, or a live phone call. These three attack types have distinct names that reflect how they reach you:

  • Phishing — delivered by email
  • Smishing — delivered by SMS text message
  • Vishing — delivered by voice call

All three are forms of social engineering: manipulation tactics designed to make you act quickly without stopping to think. Understanding how each one works is the first step toward recognising them. For a broader overview of how scams follow predictable patterns across platforms, see Recognising a Scam Before It Costs You.

Phishing

A cyberattack delivered via email that impersonates a trusted source to trick recipients into revealing personal data or clicking malicious links.

Smishing

A phishing attack carried out through SMS text messages, often using fake delivery notifications or urgent account alerts to lure victims.

Vishing

A social engineering attack conducted over a voice call, where a real or automated caller impersonates a bank, authority, or tech-support service.

Social Engineering

Psychological manipulation that tricks people into performing actions or revealing confidential information, rather than exploiting technical vulnerabilities.

Caller ID Spoofing

A technique that allows attackers to display a false phone number on the recipient's screen, making a fraudulent call appear to come from a legitimate source.

Spear Phishing

A targeted variant of phishing that uses personal details — such as the victim's name or employer — to make the fraudulent message appear more credible.

Phishing, Smishing, and Vishing: Side-by-Side

Each attack type has its own delivery mechanism and typical red flags. The table below summarises the key differences.

Delivery channel Phishing: email | Smishing: SMS | Vishing: voice call
Common impersonation targets Banks, parcel carriers, government agencies, tech companies
Caller ID can be faked Yes — a call displaying a real bank number may not originate from that bank
Key warning sign (all three) Unexpected urgency, requests for credentials or payment
Targeted variant name Spear phishing / spear smishing / spear vishing

Phishing (Email)

Phishing emails impersonate trusted organisations — banks, parcel carriers, government agencies, or popular services. They typically include a link to a fake website that looks legitimate, where you are asked to enter login credentials, payment details, or personal information. Red flags include mismatched sender addresses (the display name looks right, but the actual address does not), generic greetings like "Dear Customer," urgent language threatening account suspension, and URLs that differ slightly from the real domain (e.g. "paypa1.com" instead of "paypal.com").

Smishing (SMS)

Smishing messages arrive as ordinary texts, often claiming to be from a delivery service, your bank, or a government body. Because SMS feels more personal and immediate than email, people tend to act faster. Links in smishing texts often lead to mobile-optimised fake pages. A common example in Germany involves fake parcel-tracking messages asking you to pay a small customs fee — the "fee" page captures your card details. Red flags: unexpected texts about deliveries or accounts you don't recognise, short or disguised links (bit.ly-style), and requests to call a number or visit a site urgently.

Vishing (Voice Call)

Vishing uses live or automated phone calls. A caller may claim to be from your bank's fraud department, a tech-support team, or even a government authority. They create pressure — warning of imminent account freezes or legal action — to stop you thinking critically. Caller ID can be spoofed to display a real institution's number. Red flags: unsolicited calls asking you to confirm account numbers or PINs, pressure not to hang up, requests to install remote-access software, or demands to pay using gift cards or wire transfers.

Why These Attacks Work

Each channel exploits a different cognitive habit. Email feels official and document-like, lending authority to fake notices. SMS is tied to our phones — a device we associate with trusted personal contacts — creating a false sense of intimacy. A voice call introduces a real-time human element, making it harder to pause and assess the situation before responding.

Spoofed Numbers Are Not Proof of Identity

Seeing a familiar or official-looking phone number on your screen does not confirm who is really calling. Caller ID spoofing technology allows anyone to display an arbitrary number. If you receive an unsolicited call from someone claiming to represent your bank, hang up and call the number printed on the back of your bank card directly. The same caution applies to SMS — sender IDs can also be manipulated.

Attackers also use personalisation to increase credibility. Information gathered from data breaches or social media — your name, employer, or recent purchase — can make a message feel uncomfortably specific and therefore trustworthy. This targeted variant is sometimes called spear phishing (email), spear smishing (SMS), or spear vishing (call).

Practical Steps to Protect Yourself

Awareness is your strongest defence. Apply these habits across all three channels:

  1. Never click links in unexpected messages. Navigate directly to the organisation's website by typing the address yourself, or use a saved bookmark.
  2. Verify the sender independently. Call the organisation using a number from their official website — not one provided in the suspicious message.
  3. Refuse urgency. Legitimate organisations do not demand immediate action under threat of penalty. Pause, breathe, and verify.
  4. Don't share credentials or PINs over any channel. Your bank will never ask for your full password or PIN by email, text, or phone.
  5. Enable strong account protection. Two-factor authentication adds a layer that protects your accounts even if credentials are stolen — though be aware that SMS-based codes can themselves be intercepted.

For a full set of device-level security habits, see Keeping Your Smartphone Secure Without Becoming a Tech Expert and the comprehensive guide Online Safety from End to End.

guide

Bundesnetzagentur (Federal Network Agency) — Spam & Scam Reporting

Germany's Federal Network Agency accepts reports of unsolicited calls, spam SMS, and other telecommunications abuse. Reporting helps authorities track patterns and take action against repeat offenders.

guide

Verbraucherzentrale — Digital Scam Warnings

The German consumer advice centre publishes regularly updated warnings about active phishing, smishing, and vishing campaigns circulating in Germany, in plain accessible language.