Vishing and Smishing
Phone and SMS attacks.
Vishing and Smishing is a free Cyber Security Academy lesson on CoddyKit — lesson 3 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cyber Security Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Beyond Email Phishing
Phishing is not limited to email. Attackers also use phone calls and text messages to reach victims.
These channels feel personal and immediate, which makes them effective.
What Is Vishing
Vishing is voice phishing, an attack carried out over a phone call.
The attacker uses a convincing voice and story to pressure the victim into revealing information or making a payment.
Common Vishing Scripts
Typical vishing calls pretend to be:
- Your bank's fraud department
- Tax authorities demanding payment
- Tech support claiming your PC has a virus
Caller: 'This is your bank.
We blocked a suspicious charge.
Please read me the code we just texted you.'Caller ID Spoofing
Attackers can fake the number that shows on your phone. This is called caller ID spoofing.
A call that appears to come from your bank's real number can still be fraudulent. Never trust caller ID alone.
What Is Smishing
Smishing is SMS phishing, an attack delivered through text messages.
A short message contains a malicious link or asks you to call a fraudulent number.
SMS: 'Your package could not be delivered.
Update your address: http://track-parcel.co/x9'Common Smishing Themes
Smishing texts often pretend to be about:
- Failed package deliveries
- Bank alerts and locked cards
- Prize wins or refunds
- Two-factor codes you did not request
The One-Time Code Trap
A dangerous trick: the attacker triggers a real login on your account, then calls or texts asking you to share the verification code.
Giving up that code lets them log in as you. Never share a one-time code with anyone.
Pressure and Secrecy
Vishing and smishing rely on emotion.
- Fear - 'You owe money and will be arrested'
- Secrecy - 'Do not tell anyone'
Legitimate organizations never demand secrecy or instant payment.
Hang Up and Call Back
The safest response to a suspicious call is to hang up.
Then call the organization back using the official number from their website or the back of your card, not the number that called you.
Do Not Tap Links
For suspicious texts:
- Do not tap the link
- Do not call the number in the message
- Delete and report the message as spam
Open apps directly instead of following text links.
Report the Attack
Reporting helps protect others.
Many countries let you forward scam texts to a national spam reporting number, and most banks have a fraud hotline for reporting suspicious calls.
Quick Check
Test your knowledge of phone and SMS attacks.
Recap
You learned about voice and SMS phishing:
- Vishing uses phone calls; smishing uses texts
- Caller ID can be spoofed
- Never share one-time codes or tap unknown links
Hang up, verify, and report.
Frequently asked questions
Is the “Vishing and Smishing” lesson free?
Yes — the full text of “Vishing and Smishing” is free to read here on the web, and the Cyber Security Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cyber Security Academy course, upgrade to CoddyKit PRO.
What will I learn in “Vishing and Smishing”?
Phone and SMS attacks. You practise Cyber Security Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Cyber Security Academy?
No prior experience is required. Cyber Security Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 3 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Vishing and Smishing” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Cyber Security Academy lesson?
Yes. Every Cyber Security Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Social Engineering Tactics
- Recognizing Phishing
- Vishing and Smishing
- Building Security Awareness