Keepnet – AI-powered human risk management platform logo
Menu
HOME > blog > fbi warning on smishing and vishing

FBI Warning on Smishing and Vishing: What Organizations Must Know

FBI warnings on smishing and vishing explained: how text and voice phishing scams work, why they bypass email filters, and the controls that reduce organizational risk.

Ozan Ucar, Founder and CEO of Keepnet

FBI warning on smishing and vishing scams

The FBI has repeatedly warned that smishing (text message phishing) and vishing (voice phishing) scams are growing, including waves that target both iPhone and Android users with fake toll, delivery, and account alerts. These messages push people to click a link or call a number, then hand over credentials, payment details, or one-time codes. For organizations, the risk is not just personal fraud. The same techniques are used to reach employees, help desks, and finance teams. This guide explains what the FBI flagged, how the scams work, and the controls that reduce the risk.

Key Takeaways

  • Smishing and vishing use text and phone calls instead of email, so they slip past filters that only scan inbox traffic.
  • The FBI Internet Crime Complaint Center (IC3) recorded 191,561 phishing and spoofing complaints in 2025, the most reported crime type (IC3 2025 report).
  • Phone-based social engineering is measurably harder for employees to resist than email. In simulation data, median failure on phone is about 40 percent higher than on email (Verizon 2026 DBIR, p. 50).
  • Attackers increasingly move from a text or call into a help desk or finance workflow, as seen in the MGM Resorts case.
  • Defense is behavioral and procedural: multi-channel simulation, out-of-band verification, and a help desk policy that never resets access on a phone call alone.

What the FBI Warned About

The FBI and its Internet Crime Complaint Center (IC3) have issued repeated public alerts about smishing and vishing. The pattern is consistent: a text message or phone call impersonates a trusted source, such as a delivery service, a toll authority, a bank, or an internal IT team. Recent smishing waves have targeted both iPhone and Android users with fake unpaid-toll and package-delivery notices that carry a malicious link.

The scale behind these warnings is in the FBI's own reporting. The IC3 2025 annual report recorded 1,008,597 complaints and $20.877 billion in total reported losses, up about 26 percent from 2024. Phishing and spoofing was the single most reported crime type, with 191,561 complaints and $215.8 million in reported losses (FBI IC3, Internet Crime Report 2025).

Source: FBI Internet Crime Complaint Center, Internet Crime Report 2025.

Smishing and Vishing, Briefly

Smishing is phishing delivered by SMS or messaging apps. Vishing is phishing delivered by a phone call or voicemail. Both rely on the same trick as email phishing: create urgency, impersonate authority, and get the target to act before they think.

If you want the full definitions and how these differ from email phishing, see our guides on what vishing is and the vishing, phishing and smishing comparison. This article focuses on the FBI warnings and the organizational response.

Why These Attacks Are Growing

Two things make text and voice attractive to attackers.

First, they avoid the email gateway. Most security spend protects the inbox. A text to a personal phone or a call to a desk line often has no filter in front of it. Smishing volume has been rising sharply, with growth of roughly 30 to 40 percent quarter over quarter reported by the APWG (Anti-Phishing Working Group, Phishing Activity Trends Report, Q4 2025, p. 4).

Second, voice is persuasive. People are trained to be helpful on the phone, and a confident caller with a plausible story is hard to refuse in real time. This shows up in the data. When organizations run phishing simulations across channels, the median failure rate on phone-based tests runs about 40 percent higher than on email (Verizon 2026 DBIR, p. 50).

Bar chart comparing phishing simulation failure rates, phone about 40 percent higher than email
Phone-based simulations fail about 40 percent more often than email. Source: Verizon 2026 DBIR, p. 50.

How a Smishing or Vishing Scam Unfolds

  • The hook. A text or call impersonates a delivery company, a toll system, a bank, or an internal IT desk.
  • The urgency. There is a fine to pay, a package held, an account locked, or a login to confirm right now.
  • The pivot. The victim clicks a link to a fake page or reads out a code, a password, or a payment detail.
  • The escalation. For a business target, the attacker uses what they collected to reach a help desk or a finance approval, resetting access or moving money.
How a smishing or vishing scam unfolds in four steps, the hook, the urgency, the pivot and the escalation
The four steps attackers follow, from the first message to a help desk or finance takeover.

The MGM Resorts incident in September 2023 followed this shape. Public reporting describes attackers using a phone call to the IT help desk to reset access, and the company disclosed a material impact in its SEC filing (MGM Resorts, SEC Form 8-K, 2023; attack vector per industry reporting).

What Organizations Should Do

Consumer advice like "do not click unknown links" matters, but organizations need controls that hold up when an employee does get fooled.

  • Test the channels attackers actually use. If your awareness program only sends fake emails, it never measures how staff react to a text or a call. Run vishing simulations and smishing simulations alongside email so you can see and close the phone and SMS gap.
  • Require out-of-band verification. Any password reset, MFA reset, payment change, or urgent transfer that starts with a call or text must be confirmed through a separate, known channel before anyone acts.
  • Give the help desk a hard rule. No account or MFA reset on the strength of a phone call alone. Identity is verified through a defined process, every time.
  • Make reporting one tap. Employees should be able to report a suspicious text or call as easily as a suspicious email, and get quick feedback so the behavior sticks.

SHARE ON

twitter
linkedin
facebook

See how employees respond to a real vishing or smishing test

You'll learn how to:
tickRun vishing and smishing simulations alongside email so you can see the phone and SMS gap.
tickIdentify which teams and roles fail voice and text tests, then assign targeted training.
tickTrack behavior change over time and report human risk to leadership.

Frequently Asked Questions

What is the difference between smishing and vishing?

arrow down

Smishing is phishing sent by text message. Vishing is phishing carried out by a phone call or voicemail. Both aim to get the target to reveal information or take an action, and both sit outside the email channel that most filters protect.

Why does the FBI keep warning about smishing and vishing?

arrow down

Because the volume and losses are large and rising. The FBI IC3 2025 report logged 191,561 phishing and spoofing complaints, the most reported crime type that year (FBI IC3, Internet Crime Report 2025).

Are iPhone users safe from smishing?

arrow down

No. Recent smishing waves have targeted both iPhone and Android users with fake toll and delivery messages. The device does not stop a convincing text that relies on the user to click or reply.

How can a company defend against vishing and smishing?

arrow down

Test staff with voice and SMS simulations, not just email, require out-of-band verification for sensitive requests, and enforce a help desk policy that never resets access on a phone call alone.

Can these attacks lead to a full breach?

arrow down

Yes. A single text or call can give an attacker the credential or code needed to reach a help desk or finance workflow, which is how several major incidents began.