FBI Warning on Smishing and Vishing: What Organizations Must Know
FBI warnings on smishing and vishing explained: how text and voice phishing scams work, why they bypass email filters, and the controls that reduce organizational risk.
Ozan Ucar, Founder and CEO of Keepnet
The FBI has repeatedly warned that smishing (text message phishing) and vishing (voice phishing) scams are growing, including waves that target both iPhone and Android users with fake toll, delivery, and account alerts. These messages push people to click a link or call a number, then hand over credentials, payment details, or one-time codes. For organizations, the risk is not just personal fraud. The same techniques are used to reach employees, help desks, and finance teams. This guide explains what the FBI flagged, how the scams work, and the controls that reduce the risk.
Key Takeaways
- Smishing and vishing use text and phone calls instead of email, so they slip past filters that only scan inbox traffic.
- The FBI Internet Crime Complaint Center (IC3) recorded 191,561 phishing and spoofing complaints in 2025, the most reported crime type (IC3 2025 report).
- Phone-based social engineering is measurably harder for employees to resist than email. In simulation data, median failure on phone is about 40 percent higher than on email (Verizon 2026 DBIR, p. 50).
- Attackers increasingly move from a text or call into a help desk or finance workflow, as seen in the MGM Resorts case.
- Defense is behavioral and procedural: multi-channel simulation, out-of-band verification, and a help desk policy that never resets access on a phone call alone.
What the FBI Warned About
The FBI and its Internet Crime Complaint Center (IC3) have issued repeated public alerts about smishing and vishing. The pattern is consistent: a text message or phone call impersonates a trusted source, such as a delivery service, a toll authority, a bank, or an internal IT team. Recent smishing waves have targeted both iPhone and Android users with fake unpaid-toll and package-delivery notices that carry a malicious link.
The scale behind these warnings is in the FBI's own reporting. The IC3 2025 annual report recorded 1,008,597 complaints and $20.877 billion in total reported losses, up about 26 percent from 2024. Phishing and spoofing was the single most reported crime type, with 191,561 complaints and $215.8 million in reported losses (FBI IC3, Internet Crime Report 2025).
Source: FBI Internet Crime Complaint Center, Internet Crime Report 2025.
Smishing and Vishing, Briefly
Smishing is phishing delivered by SMS or messaging apps. Vishing is phishing delivered by a phone call or voicemail. Both rely on the same trick as email phishing: create urgency, impersonate authority, and get the target to act before they think.
If you want the full definitions and how these differ from email phishing, see our guides on what vishing is and the vishing, phishing and smishing comparison. This article focuses on the FBI warnings and the organizational response.
Why These Attacks Are Growing
Two things make text and voice attractive to attackers.
First, they avoid the email gateway. Most security spend protects the inbox. A text to a personal phone or a call to a desk line often has no filter in front of it. Smishing volume has been rising sharply, with growth of roughly 30 to 40 percent quarter over quarter reported by the APWG (Anti-Phishing Working Group, Phishing Activity Trends Report, Q4 2025, p. 4).
Second, voice is persuasive. People are trained to be helpful on the phone, and a confident caller with a plausible story is hard to refuse in real time. This shows up in the data. When organizations run phishing simulations across channels, the median failure rate on phone-based tests runs about 40 percent higher than on email (Verizon 2026 DBIR, p. 50).

How a Smishing or Vishing Scam Unfolds
- The hook. A text or call impersonates a delivery company, a toll system, a bank, or an internal IT desk.
- The urgency. There is a fine to pay, a package held, an account locked, or a login to confirm right now.
- The pivot. The victim clicks a link to a fake page or reads out a code, a password, or a payment detail.
- The escalation. For a business target, the attacker uses what they collected to reach a help desk or a finance approval, resetting access or moving money.

The MGM Resorts incident in September 2023 followed this shape. Public reporting describes attackers using a phone call to the IT help desk to reset access, and the company disclosed a material impact in its SEC filing (MGM Resorts, SEC Form 8-K, 2023; attack vector per industry reporting).
What Organizations Should Do
Consumer advice like "do not click unknown links" matters, but organizations need controls that hold up when an employee does get fooled.
- Test the channels attackers actually use. If your awareness program only sends fake emails, it never measures how staff react to a text or a call. Run vishing simulations and smishing simulations alongside email so you can see and close the phone and SMS gap.
- Require out-of-band verification. Any password reset, MFA reset, payment change, or urgent transfer that starts with a call or text must be confirmed through a separate, known channel before anyone acts.
- Give the help desk a hard rule. No account or MFA reset on the strength of a phone call alone. Identity is verified through a defined process, every time.
- Make reporting one tap. Employees should be able to report a suspicious text or call as easily as a suspicious email, and get quick feedback so the behavior sticks.