Skip to content

7 min read

American Corners
Educator-ready reference unit

Phishing, smishing, and vishing

One trick, three doorways

The names sound like three different problems, but they are the same con delivered through three different doorways. In each one an attacker pretends to be someone you trust and pushes you to reveal something or do something quickly. Only the channel changes.

  • Phishing arrives by email.
  • Smishing arrives by SMS or a messaging app (the "sm" is for SMS).
  • Vishing arrives by voice, a phone call (the "v" is for voice).

Learn to read one and you can read all three, because the pressure underneath them is identical.

Phishing: the fake email

A phishing email looks like it comes from a bank, a delivery company, a colleague or a well known service. It asks you to click a link, open an attachment or "confirm" your details on a page that is really the attacker's. The page can be a pixel perfect copy of the real login screen; whatever you type there goes straight to the attacker.

The tell is rarely the logo, which is easy to copy. It is the request: a genuine bank does not email you a link and ask you to log in urgently to avoid being locked out.

Smishing: the fake text

Smishing is the same idea in a text message: a missed parcel that needs a small "redelivery fee", a bank alert about a suspicious payment, a code you are asked to read back. Texts feel more personal and more urgent than email, and the short format hides the usual clues, so people let their guard down. A link in an unexpected text deserves the same suspicion as one in an unexpected email.

Vishing: the fake call

Vishing is a phone call: someone claiming to be your bank's fraud team, a government office, or your own IT support, walking you calmly towards a password, a one time code or a payment. A live voice adds pressure that text cannot, and it is now easy to fake. With voice cloning, a call that sounds exactly like your manager may not be your manager at all. If a call is unexpected and the request is sensitive, the safest move is to hang up and call back on a number you already trust.

The red flags they share

Whatever the channel, the same handful of signs show up again and again:

  • Urgency or a threat: act now or lose access, pay a fine, avoid trouble.
  • An unexpected request for secrets: a password, a full card number, a one time code. Real institutions do not ask for these.
  • A link or attachment you did not expect, especially one that wants you to log in.
  • A sender or number that is slightly off, a misspelled address or a name that does not quite match.
  • A story that skips your normal process, "just this once", "keep it between us".

When you see one, do not reply, click or read anything back. Verify through a separate, trusted channel: contact the organisation using a number or address you already have, not the one in the message.

Put the skill to work

The activity below asks you to commit to a decision before it explains the evidence. You will then inspect the message, revise your plan and apply the rule to a different situation. Your work stays privately in this browser and is recorded separately from the lesson-complete checkbox.

Practice activity · 25-35 min

Decide, inspect, revise

No account and no submission. Your response stays in this browser. Page completion and this practice activity are recorded separately.

Fictional message

From
Shërbimi i Llogarive <ndihma@hyrje-sigurt.example>
Subject
Urgent: confirm your account before 18:00

Hello,

We detected an unusual sign-in to your account. Access will be suspended today unless you confirm your identity.

Open the link below and enter your password and the one-time code sent to your phone.

hyrje-sigurt.example/konfirmo

Account support team

Fictional educational message. It does not represent a real Albanian institution, address or service.

1Commit before feedback

What would you do first? Choose before inspecting the clues.

Initial decision

Check yourself

Social engineering & account safety
Educator guidance · 35 min

Prepare

  • Open the supplied suspicious-message activity and learner sheet
  • Use the supplied fictional scenario by default; adapting it to a familiar local context is optional and must avoid personal data

Materials

  • One learner worksheet per person or pair
  • Facilitator notes
  • Pens; optional projector for the interactive version

Facilitate

  • Do not name the clues before learners commit to a first decision
  • Ask what each clue suggests and what it cannot prove alone
  • Require a verification channel that was known before the message arrived
  • Let learners revise publicly without treating the first answer as failure

Discussion

  • Which clue changed your mind?
  • How can you verify without replying or using the supplied link?

Suggested introduction

Begin with a message that feels urgent. Ask learners to pause before deciding whether it is genuine.

Likely misconception

A polished message is not proof of identity, and one spelling mistake is not proof of fraud.

Expected response

Learners should cite several clues and choose an independent trusted channel to verify.

Adaptation

For younger groups, analyse one clue at a time. For professionals, use a payment or credential-reset scenario.

Extension

Teams rewrite the message so it is safer and then design the verification rule the recipient should follow.

Shorten it

For 20 minutes, use the first decision, three clues (urgency, secret, supplied link), one revision and the reusable rule.

Debrief

  • Which evidence changed your decision?
  • Why is replying not independent verification?
  • What rule still works if the message is polished or the voice sounds familiar?

Group adaptations

Pairs
One learner argues for the first decision; the other challenges the verification route, then they switch roles.
Small groups
Assign evidence finder, skeptic and recorder. Require agreement on one exact verification sentence.
Whole class
Take an anonymous first vote, reveal clues one at a time, then vote again and ask what changed.

Found something unclear, outdated or improvable? Suggest an improvement

Where this lesson comes from

Built from

  • Workshop 6: Social Engineering and the Human Factor (V3.0): phishing, smishing, vishing

alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement