Phishing, Smishing, Vishing
🔐 PHISHING, SMISHING & VISHING
These are types of Social Engineering Attacks used to steal sensitive information like passwords, OTPs, banking details, and personal data.
1️⃣ PHISHING
Definition
Phishing is a cyber attack where attackers send fake emails or messages pretending to be a trusted organization to steal sensitive information.
The word “Phishing” comes from the word “Fishing” — attackers “fish” for information.
How Phishing Works
-
Attacker sends fake email.
-
Email looks like it is from a bank, company, or government.
-
Victim clicks the link.
-
Fake website opens.
-
Victim enters login details.
-
Information is stolen.
Common Targets
-
Bank accounts
-
Email accounts
-
Social media accounts
-
Online shopping accounts
Types of Phishing
• Email Phishing
Fake email pretending to be from trusted organization.
• Spear Phishing
Targeted phishing attack on specific person or company.
• Clone Phishing
Copy of a real email but with malicious link.
• Whaling
Phishing attack targeting high-level executives.
Signs of Phishing Email
-
Urgent message (“Account will be blocked”)
-
Grammar mistakes
-
Unknown sender address
-
Suspicious links
-
Asking for password or OTP
Prevention
-
Do not click unknown links
-
Verify sender email address
-
Enable two-factor authentication
-
Use spam filter
2️⃣ SMISHING
Definition
Smishing (SMS Phishing) is a phishing attack conducted through SMS (text messages).
“Smishing” = SMS + Phishing
How Smishing Works
-
Victim receives SMS.
-
Message contains urgent or attractive offer.
-
Message includes malicious link.
-
Victim clicks link.
-
Fake website collects information.
Common Examples
-
“Your bank account is blocked. Click here.”
-
“You won ₹50,000 lottery.”
-
“Update KYC immediately.”
-
Fake courier delivery message
Dangers of Smishing
-
Banking fraud
-
Identity theft
-
Malware installation
Prevention
-
Do not click unknown SMS links
-
Verify message with official website
-
Block suspicious numbers
-
Report to telecom provider
3️⃣ VISHING
Definition
Vishing (Voice Phishing) is a fraud attack where attackers use phone calls to trick victims into revealing sensitive information.
“Vishing” = Voice + Phishing
How Vishing Works
-
Attacker calls victim.
-
Pretends to be bank officer, police, or company staff.
-
Creates urgency or fear.
-
Asks for OTP, PIN, or account details.
-
Uses information for fraud.
Common Vishing Scams
-
Fake bank verification call
-
Fake income tax department call
-
Fake police threat call
-
Fake customer care support
Techniques Used in Vishing
-
Caller ID spoofing
-
Fear tactics
-
Urgent action demand
-
Authority pressure
Prevention
-
Never share OTP or PIN on call
-
Banks never ask for password
-
Disconnect suspicious calls
-
Verify by calling official number
🔥 Comparison Table
| Feature | Phishing | Smishing | Vishing |
|---|---|---|---|
| Medium | SMS | Phone Call | |
| Communication Type | Written | Text Message | Voice |
| Link Included | Yes | Yes | Sometimes |
| Common Target | Login credentials | Banking details | OTP & PIN |
| Urgency Used | Yes | Yes | Yes |
🎯 Key Differences
-
Phishing uses email.
-
Smishing uses SMS.
-
Vishing uses phone calls.
All three aim to steal confidential information.
🛡 General Protection Tips
-
Think before clicking
-
Verify before trusting
-
Never share OTP
-
Use strong passwords
-
Enable two-factor authentication
-
Keep phone and system updated
Comments
Post a Comment