Skip to main content
Phishing Scams

Phishing Isn't Just Email: Smishing, Vishing, and Quishing Explained

Phishing scams aren't just email anymore. Smishing, vishing, and quishing are on the rise. Learn how to spot and stop them before they cost you.

Here's a number that should make you pause: 193,407. That's how many phishing and spoofing complaints the FBI's IC3 received in 2024 (FBI IC3 2024 Internet Crime Report). And that's just the ones reported. Phishing is the most common cybercrime, and it's not going away. But here's the thing: most phishing attacks are preventable if you know what to look for. This isn't about being paranoid—it's about being prepared.

What is phishing, really?

Phishing is a social engineering attack where criminals impersonate a trusted entity to trick you into revealing sensitive information or taking a harmful action. The classic example is an email that looks like it's from your bank, asking you to "verify" your account. But phishing isn't just email anymore. There's smishing (SMS text messages), vishing (voice calls), and even quishing (malicious QR codes) (CISA Secure Our World). The goal is always the same: get you to click a link, download an attachment, or hand over credentials. And it works. Verizon's 2024 Data Breach Investigations Report found that 68% of data breaches involve a human element—someone falling for a phish (Verizon 2024 DBIR).

Is phishing really that dangerous?

Yes. Phishing is the entry point for most ransomware attacks. Attackers use phishing to gain a foothold, then deploy malware that encrypts your files and demands payment (CISA StopRansomware Guide). Ransomware complaints rose 9% in 2024, and it remains the most pervasive threat to critical infrastructure (FBI IC3 2024 Internet Crime Report). But it's not just ransomware. Phishing leads to identity theft, financial fraud, and business email compromise—which alone cost victims $2.77 billion in 2024 (FBI IC3 2024 Internet Crime Report). So no, it's not just a nuisance. It's a serious threat.

What are the most common phishing tricks I should know?

You've probably seen the Nigerian prince email. But modern phishing is more sophisticated. Here are the big ones:

Email phishing: The classic. Look for misspelled sender addresses, urgent language, and suspicious links. Hover over a link before clicking—if the URL doesn't match the supposed sender, don't click (CISA Secure Our World).

Smishing: Text messages that claim to be from your bank or a delivery service. They often contain a link that installs malware or a fake login page.

Vishing: Voice calls from scammers posing as tech support or your bank. They'll ask for your password or a one-time code. Hang up and call back on a known number.

Quishing: QR codes that lead to malicious websites. You scan a code in a parking garage or restaurant, and suddenly you're on a phishing page (CISA Secure Our World).

Does multi-factor authentication (MFA) stop phishing?

Yes, but not all MFA is equal. SMS codes can be intercepted via SIM swapping, a social engineering attack where criminals convince your carrier to port your number to their SIM (CISA Implementing Phishing-Resistant MFA). Authenticator apps are better, but they can still be phished if you enter the code on a fake site. The gold standard is phishing-resistant MFA, like hardware security keys (FIDO2) or passkeys (CISA Implementing Phishing-Resistant MFA). These use cryptography to ensure you're logging into the real site. Microsoft says that enabling MFA can block over 99.9% of account compromise attacks (Microsoft Security Blog MFA). That's a no-brainer.

I clicked a suspicious link. What should I do now?

First, don't panic. Disconnect from the network and run a full malware scan. Change your passwords immediately, especially for email and financial accounts. If you used the same password anywhere else, change those too—password reuse is how credential stuffing works (Microsoft Security Blog MFA). Check if your email has been in a breach using a service like Have I Been Pwned (Have I Been Pwned About). Finally, report the incident to the FBI's IC3 at www.ic3.gov (FBI IC3 2024 Internet Crime Report).

Quick tip: If you get an urgent email from your "CEO" asking for gift cards, it's a scam. Always verify through a different channel.

MFA comparison: Which one should you use?

Method Phishing resistance Convenience Recommendation
SMS codes Low (SIM swapping) High Last resort
Authenticator app Medium (can be phished) Medium Use if no better option
Hardware key (FIDO2) High Low (carry a key) Gold standard
Passkey High High (biometrics) Best for consumers

Bottom line

Phishing is the most common cybercrime because it works. But you can make it stop. Use phishing-resistant MFA, like a hardware key or passkey, on your most important accounts. Slow down and check URLs and sender addresses. And if something feels off, it probably is. That one pause could save you from losing thousands of dollars.

Sources

  • CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
  • FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  • Verizon (2024 Data Breach Investigations Report) - https://www.verizon.com/about/news/2024-data-breach-investigations-report-vulnerability-exploitation-boom
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
  • Have I Been Pwned (About) - https://haveibeenpwned.com/About

Share this article:

Comments (0)

No comments yet. Be the first to comment!