3. Beyond email
Smishing, vishing and quishing
Email filters have improved, so attackers increasingly go where the filters are weaker: your phone.
Smishing (SMS phishing)
Phishing by text message. Common lures include missed delivery notices with a "reschedule" link, bank fraud alerts asking you to "verify" activity, fake toll or parking penalties, and the "Hi Mum, I've lost my phone, this is my new number" family emergency scam. Texts are effective because they feel personal and immediate, links are hard to inspect on a small screen, and people read texts within minutes.
Treat links in unexpected texts exactly like links in unexpected emails: do not tap them. Go direct to the courier's or bank's official website or app instead. In the UK you can report scam texts by forwarding them free of charge to 7726, which is covered fully in Section 4.
Vishing (voice phishing)
Phishing by phone call. Attackers impersonate bank fraud teams, the police, HMRC, Microsoft support, or your own IT department. Caller ID can be spoofed to display a genuine number, so the number on screen proves nothing.
Two rules protect you. First, your bank, the police, or any legitimate body will never ask you to move money to a "safe account", read out full passwords or MFA codes, or install remote access software during an unexpected call. Any of those requests means the call is a scam. Second, if a call worries you, hang up and call the organisation back on a number you found yourself, from their website or the back of your card, never a number the caller gives you.
Quishing (QR code phishing)
QR codes are just links wearing a disguise: the destination is invisible until you scan. Attackers exploit this by putting malicious codes in emails and posters, and by pasting stickers over genuine codes on parking meters, restaurant tables, and charging points. Codes in emails have the added advantage, for the attacker, of moving you to your phone, away from corporate security controls.
Before scanning, ask whether the code makes sense in context, check for sticker tampering in public places, and look at the address your phone previews before opening it. If a scanned page asks for login details or payment, stop and go direct instead.
› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting
Putting it into practice