Three Channels, One Goal: Steal Your Information

Scammers don't limit themselves to one medium. Today's fraud attempts arrive via email, text message, and phone call — each with its own name and its own set of red flags. Understanding how each delivery method works makes them far easier to identify before any damage is done.

The underlying goal is always the same: get you to hand over credentials, financial details, or personal identifying information. What changes is the channel and the psychological pressure tactic used to push you toward acting fast. As the social engineering tactics behind these scams make clear, the threat is manipulation — not sophisticated code.

Phishing: The Email Impersonator

Phishing refers to fraudulent emails designed to look like they come from a trusted source — a bank, government agency, shipping carrier, or familiar retailer. The email typically urges immediate action: verify your account, confirm a delivery, or claim a refund.

What to look for

  • Sender address mismatches: The display name may say "IRS" or "PayPal," but hover over the address and you'll often see a garbled or unrelated domain.
  • Generic greetings: "Dear Customer" instead of your actual name is a common tell in mass phishing campaigns.
  • Urgent or threatening language: Phrases like "Your account will be suspended" are designed to short-circuit careful thinking.
  • Suspicious links: URLs that look almost right — one transposed letter, an extra hyphen — redirect to credential-harvesting sites.

Before clicking anything in an unexpected email, go directly to the organization's official website by typing the address yourself. See also how to protect your payment information if you encounter phishing attempts during checkout.

Smishing: Fraud via Text Message

Smishing (SMS + phishing) uses text messages to deliver the same deceptive payload. Because many people apply less scrutiny to texts than to emails, smishing can be especially effective.

Common smishing scenarios

  • Fake package delivery alerts claiming your shipment is held and you must pay a small fee.
  • Spoofed bank alerts warning of unusual account activity with a link to "verify" your identity.
  • Toll-payment scams — a growing category flagged by the FBI — claiming you owe a small outstanding balance.

Phishing

A cyberattack delivered via email in which scammers impersonate legitimate organizations to trick recipients into revealing personal or financial information.

Smishing

A form of phishing conducted through SMS text messages. The name combines 'SMS' and 'phishing.'

Vishing

Voice-based phishing carried out over phone calls, often using caller ID spoofing to appear as a trusted institution.

Caller ID Spoofing

A technique that allows callers to display a fake name or number on the recipient's phone, making fraudulent calls appear legitimate.

Multi-Factor Authentication (MFA)

A login security method that requires at least two forms of verification — such as a password plus a one-time code — before granting account access.

Credential Harvesting

The practice of tricking users into entering their usernames and passwords on fake websites so scammers can capture and misuse that data.

A key rule: legitimate companies and agencies rarely ask you to click a link in a text message to resolve an urgent issue. If a text prompts action, find the organization's official contact information independently and reach out that way instead.

Vishing: The Fraudulent Phone Call

Vishing (voice + phishing) involves live or automated phone calls from scammers posing as the IRS, Social Security Administration, tech support departments, or financial institutions. Caller ID spoofing allows them to display a convincing local or official-looking number.

Red flags during a call

  • Immediate pressure to act: "You'll be arrested if you don't pay now."
  • Requests for payment via gift cards, wire transfer, or cryptocurrency — methods no real government agency uses.
  • Requests to remotely access your computer to "fix" a problem.
  • Threats that hang up if you try to verify independently.

Government Agencies Will Not Call Demanding Immediate Payment

The IRS, Social Security Administration, and Medicare do not call to demand immediate payment or threaten arrest over the phone. If you receive such a call, hang up. You can verify any real correspondence by contacting the agency directly through its official website or publicly listed phone number.

The security habits that feel safe but aren't is worth reviewing here — because answering unknown calls and trusting caller ID are two common misconceptions about phone safety.

Habits That Reduce Your Exposure

No single tool eliminates the risk, but a few consistent habits significantly narrow your vulnerability across all three attack types.

  • Pause before acting. Urgency is a manipulation tool. A genuine organization will give you time to verify.
  • Go direct. Never use contact information provided in a suspicious message. Look up phone numbers and URLs independently.
  • Use multi-factor authentication (MFA) on accounts where it's available. Even if a password is stolen, MFA adds a meaningful barrier.
  • Report what you see. Forward phishing emails to reportphishing@apwg.org or the FTC at reportfraud.ftc.gov. Smishing texts can be forwarded to 7726 (SPAM).

These habits protect you whether the attack arrives in your inbox, via text, or on your phone. For a broader look at how scammers exploit online behavior, see how social engineering exploits human trust.

This article is for general informational and educational purposes only. If you believe you have been a victim of fraud, contact the FTC at reportfraud.ftc.gov or your financial institution directly.