Vishing (voice phishing) and smishing (SMS phishing) move social engineering off email and onto the phone — and that shift matters, because phone calls and text messages carry a sense of urgency and authenticity that email filters and staff scepticism have partly eroded. Some of the most damaging breaches of recent years began not with a malicious attachment but with a convincing phone call to a help desk.
We test these channels as part of our social engineering engagements, and the uncomfortable finding is consistent: technical MFA controls are often undone by human processes around them.
What Vishing and Smishing Actually Look Like
Vishing is a phone call built on a pretext — a story that makes the request sound routine. An attacker might call posing as:
- An employee who's locked out and needs a password or MFA reset
- IT support 'resolving a ticket', walking a victim into approving a prompt or reading out a code
- A senior executive applying time pressure to a finance or admin staffer
- A vendor or supplier confirming payment details
Smishing is the same idea over SMS: a text with a malicious link or a request to call a number. Common lures are parcel-delivery failures, bank fraud alerts, toll notices, and 'your account will be suspended' messages. SMS is effective because links are hard to inspect on a phone, sender IDs are trivially spoofed, and people read texts within minutes.
Both work because they exploit helpfulness and urgency — the same instincts that make good employees good at their jobs.
Help-Desk and MFA-Reset Abuse
The help desk is a high-value target because its entire purpose is to help people regain access — which is exactly what an attacker wants. A caller who knows an employee's name, manager, and a plausible reason for being locked out can often talk an agent into:
- Resetting a password
- Removing or re-enrolling an MFA device
- Adding a new phone number to an account
That last step is the prize. If an attacker can register their own device as a victim's MFA method, they own the account regardless of how strong the original authentication was. Several major intrusions have hinged on precisely this: a phone call to a help desk that ended with the attacker's device enrolled as trusted.
The root problem is identity verification. If your help desk verifies identity using information an attacker can find through OSINT and reconnaissance — date of birth, employee ID, manager's name, the last four digits of something — then your verification isn't verification, it's a quiz an attacker has already got the answers to.
MFA Fatigue and Prompt Bombing
Even without touching the help desk, attackers who already have a password can attack push-based MFA directly. MFA fatigue (or prompt bombing) means triggering login prompts repeatedly — dozens of times, often late at night — until the victim approves one to make the notifications stop, or approves absent-mindedly assuming it's a glitch.
A vishing call frequently accompanies it: 'Hi, it's IT, we're pushing a system update, you'll get a prompt — just approve it.' The combination of a plausible voice and relentless prompts breaks down a lot of people's resistance.
The defence is technical and specific:
- Move to number-matching MFA, where the user types a number shown on the login screen rather than just tapping approve
- Better still, adopt phishing-resistant MFA — FIDO2 security keys or passkeys — which can't be approved for a login the user didn't initiate
- Alert on and rate-limit repeated push denials, which are a strong compromise signal
Hardening the Process, Not Just the People
Awareness training helps, but you cannot train your way out of a broken process. The durable fixes are procedural:
- Strong identity verification for account recovery. Use a method an attacker can't research or socially engineer — a call-back to a number on record, a manager approval through a separate channel, or an in-person/video check for high-privilege accounts.
- A callback culture. Any request to change payment details, reset access, or move money gets verified by calling the person back on a known-good number — never the number the caller provides.
- Phishing-resistant MFA for staff, and especially for administrators and finance.
- A clear, blameless reporting path so a staff member who approved a prompt or read out a code reports it in minutes, not after the damage compounds.
- Tested help-desk scripts that make verification mandatory and give agents explicit permission to say 'I need to call you back' without fear of a bad customer-service score.
The last point is cultural: help-desk agents are often measured on speed and satisfaction, which are in direct tension with security. Until it's genuinely acceptable for an agent to slow down and verify, they'll keep optimising for the metric they're judged on.
We pair phone and SMS testing with email phishing simulations so you get a complete picture of your social engineering exposure across every channel an attacker would actually use.
FAQ
How is vishing different from smishing?
Vishing is phishing over a voice call; smishing is phishing over SMS. Both use pretexts and urgency, but vishing adds a live human who can adapt in real time, which makes it especially effective against help desks.
Does MFA stop these attacks?
MFA raises the bar but doesn't close the door. Attackers target the processes around MFA — help-desk resets, device re-enrolment — and push-based MFA is vulnerable to fatigue attacks. Phishing-resistant MFA like FIDO2 keys closes most of the gap.
Can you test our help desk safely?
Yes. We run controlled vishing and smishing engagements against agreed targets under a clear rule of engagement, with pretexts signed off in advance and results reported without naming individuals.
If you want to know whether your help desk would hand over an account to a confident caller, get in touch. We'll scope a social engineering engagement in a free call and send a fixed quote within one business day.
Need cybersecurity expertise?
Drop your email and we'll be in touch within one business day.