Phishing, Smishing, Vishing

 

🔐 PHISHING, SMISHING & VISHING

These are types of Social Engineering Attacks used to steal sensitive information like passwords, OTPs, banking details, and personal data.


1️⃣ PHISHING

Definition

Phishing is a cyber attack where attackers send fake emails or messages pretending to be a trusted organization to steal sensitive information.

The word “Phishing” comes from the word “Fishing” — attackers “fish” for information.


How Phishing Works

  1. Attacker sends fake email.

  2. Email looks like it is from a bank, company, or government.

  3. Victim clicks the link.

  4. Fake website opens.

  5. Victim enters login details.

  6. Information is stolen.


Common Targets

  • Bank accounts

  • Email accounts

  • Social media accounts

  • Online shopping accounts


Types of Phishing

• Email Phishing

Fake email pretending to be from trusted organization.

• Spear Phishing

Targeted phishing attack on specific person or company.

• Clone Phishing

Copy of a real email but with malicious link.

• Whaling

Phishing attack targeting high-level executives.


Signs of Phishing Email

  • Urgent message (“Account will be blocked”)

  • Grammar mistakes

  • Unknown sender address

  • Suspicious links

  • Asking for password or OTP


Prevention

  • Do not click unknown links

  • Verify sender email address

  • Enable two-factor authentication

  • Use spam filter


2️⃣ SMISHING

Definition

Smishing (SMS Phishing) is a phishing attack conducted through SMS (text messages).

“Smishing” = SMS + Phishing


How Smishing Works

  1. Victim receives SMS.

  2. Message contains urgent or attractive offer.

  3. Message includes malicious link.

  4. Victim clicks link.

  5. Fake website collects information.


Common Examples

  • “Your bank account is blocked. Click here.”

  • “You won ₹50,000 lottery.”

  • “Update KYC immediately.”

  • Fake courier delivery message


Dangers of Smishing

  • Banking fraud

  • Identity theft

  • Malware installation


Prevention

  • Do not click unknown SMS links

  • Verify message with official website

  • Block suspicious numbers

  • Report to telecom provider


3️⃣ VISHING

Definition

Vishing (Voice Phishing) is a fraud attack where attackers use phone calls to trick victims into revealing sensitive information.

“Vishing” = Voice + Phishing


How Vishing Works

  1. Attacker calls victim.

  2. Pretends to be bank officer, police, or company staff.

  3. Creates urgency or fear.

  4. Asks for OTP, PIN, or account details.

  5. Uses information for fraud.


Common Vishing Scams

  • Fake bank verification call

  • Fake income tax department call

  • Fake police threat call

  • Fake customer care support


Techniques Used in Vishing

  • Caller ID spoofing

  • Fear tactics

  • Urgent action demand

  • Authority pressure


Prevention

  • Never share OTP or PIN on call

  • Banks never ask for password

  • Disconnect suspicious calls

  • Verify by calling official number


🔥 Comparison Table

FeaturePhishingSmishingVishing
MediumEmailSMSPhone Call
Communication TypeWrittenText MessageVoice
Link IncludedYesYesSometimes
Common TargetLogin credentialsBanking detailsOTP & PIN
Urgency UsedYesYesYes

🎯 Key Differences

  • Phishing uses email.

  • Smishing uses SMS.

  • Vishing uses phone calls.

All three aim to steal confidential information.


🛡 General Protection Tips

  • Think before clicking

  • Verify before trusting

  • Never share OTP

  • Use strong passwords

  • Enable two-factor authentication

  • Keep phone and system updated

Comments

Popular posts from this blog

Introduction to Computer

History of Computer

Computer Generation