7 min read
Phishing, smishing, and vishing
One trick, three doorways
The names sound like three different problems, but they are the same con delivered through three different doorways. In each one an attacker pretends to be someone you trust and pushes you to reveal something or do something quickly. Only the channel changes.
- Phishing arrives by email.
- Smishing arrives by SMS or a messaging app (the "sm" is for SMS).
- Vishing arrives by voice, a phone call (the "v" is for voice).
Learn to read one and you can read all three, because the pressure underneath them is identical.
Phishing: the fake email
A phishing email looks like it comes from a bank, a delivery company, a colleague or a well known service. It asks you to click a link, open an attachment or "confirm" your details on a page that is really the attacker's. The page can be a pixel perfect copy of the real login screen; whatever you type there goes straight to the attacker.
The tell is rarely the logo, which is easy to copy. It is the request: a genuine bank does not email you a link and ask you to log in urgently to avoid being locked out.
Smishing: the fake text
Smishing is the same idea in a text message: a missed parcel that needs a small "redelivery fee", a bank alert about a suspicious payment, a code you are asked to read back. Texts feel more personal and more urgent than email, and the short format hides the usual clues, so people let their guard down. A link in an unexpected text deserves the same suspicion as one in an unexpected email.
Vishing: the fake call
Vishing is a phone call: someone claiming to be your bank's fraud team, a government office, or your own IT support, walking you calmly towards a password, a one time code or a payment. A live voice adds pressure that text cannot, and it is now easy to fake. With voice cloning, a call that sounds exactly like your manager may not be your manager at all. If a call is unexpected and the request is sensitive, the safest move is to hang up and call back on a number you already trust.
The red flags they share
Whatever the channel, the same handful of signs show up again and again:
- Urgency or a threat: act now or lose access, pay a fine, avoid trouble.
- An unexpected request for secrets: a password, a full card number, a one time code. Real institutions do not ask for these.
- A link or attachment you did not expect, especially one that wants you to log in.
- A sender or number that is slightly off, a misspelled address or a name that does not quite match.
- A story that skips your normal process, "just this once", "keep it between us".
When you see one, do not reply, click or read anything back. Verify through a separate, trusted channel: contact the organisation using a number or address you already have, not the one in the message.
Put the skill to work
The activity below asks you to commit to a decision before it explains the evidence. You will then inspect the message, revise your plan and apply the rule to a different situation. Your work stays privately in this browser and is recorded separately from the lesson-complete checkbox.
Practice activity · 25-35 min
Decide, inspect, revise
No account and no submission. Your response stays in this browser. Page completion and this practice activity are recorded separately.
Fictional message
- From
- Shërbimi i Llogarive <ndihma@hyrje-sigurt.example>
- Subject
- Urgent: confirm your account before 18:00
Hello,
We detected an unusual sign-in to your account. Access will be suspended today unless you confirm your identity.
Open the link below and enter your password and the one-time code sent to your phone.
hyrje-sigurt.example/konfirmo
Account support team
Fictional educational message. It does not represent a real Albanian institution, address or service.
1Commit before feedback
What would you do first? Choose before inspecting the clues.
Check yourself
Educator guidance · 35 min
Prepare
- • Open the supplied suspicious-message activity and learner sheet
- • Use the supplied fictional scenario by default; adapting it to a familiar local context is optional and must avoid personal data
Materials
- • One learner worksheet per person or pair
- • Facilitator notes
- • Pens; optional projector for the interactive version
Facilitate
- • Do not name the clues before learners commit to a first decision
- • Ask what each clue suggests and what it cannot prove alone
- • Require a verification channel that was known before the message arrived
- • Let learners revise publicly without treating the first answer as failure
Discussion
- • Which clue changed your mind?
- • How can you verify without replying or using the supplied link?
Suggested introduction
Begin with a message that feels urgent. Ask learners to pause before deciding whether it is genuine.
Likely misconception
A polished message is not proof of identity, and one spelling mistake is not proof of fraud.
Expected response
Learners should cite several clues and choose an independent trusted channel to verify.
Adaptation
For younger groups, analyse one clue at a time. For professionals, use a payment or credential-reset scenario.
Extension
Teams rewrite the message so it is safer and then design the verification rule the recipient should follow.
Shorten it
For 20 minutes, use the first decision, three clues (urgency, secret, supplied link), one revision and the reusable rule.
Debrief
- • Which evidence changed your decision?
- • Why is replying not independent verification?
- • What rule still works if the message is polished or the voice sounds familiar?
Group adaptations
- Pairs
- One learner argues for the first decision; the other challenges the verification route, then they switch roles.
- Small groups
- Assign evidence finder, skeptic and recorder. Require agreement on one exact verification sentence.
- Whole class
- Take an anonymous first vote, reveal clues one at a time, then vote again and ask what changed.
Found something unclear, outdated or improvable? Suggest an improvement
Where this lesson comes from
Built from
- Workshop 6: Social Engineering and the Human Factor (V3.0): phishing, smishing, vishing
alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.
shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.
Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.
DisclaimerFound something unclear, outdated or improvable? Suggest an improvement