Quick answer
Smishing is a scam text message; vishing is a scam phone call. Both push you to act fast — a fake delivery, a "bank fraud team", or "IT support" who need you to do something right now. The rule that beats them both: never act on an unexpected text or call. Stop, and contact the organisation yourself on a number you look up independently.
SMISHING — SCAM TEXTS
The cons that arrive by SMS.
A short, urgent text with a link is the whole trick. The usual suspects:
- ▸ A fake parcel redelivery. "We missed you — pay a small fee to reschedule your delivery." The fee is tiny on purpose, so you don't stop to think before handing over your card details.
- ▸ A bank alert. "Suspicious transaction detected — tap here to confirm or cancel." The link leads to a fake login page that harvests your details.
- ▸ ATO or myGov threats. Messages claiming you owe money, have a refund waiting, or that your account is suspended — designed to panic you into clicking.
- ▸ Toll or fine notices. "You have an unpaid toll" or "outstanding fine" — with a link to "pay now" before extra charges apply.
- ▸ The "hi, it's the CEO, are you free?" text. A friendly opener that seems to come from your boss, which quickly turns into an urgent request to buy gift cards.
VISHING — SCAM CALLS
The cons that come by phone.
A real voice puts people on the spot in a way an email never can. Watch for:
- ▸ Fake "Microsoft" or "IT support". A caller claims your computer is infected and offers to "fix" it — really they want remote access to your device.
- ▸ A "bank fraud team". They warn your account is under attack and tell you to move your money to a "safe account" — which of course belongs to them.
- ▸ A spoofed internal or supplier number. The call appears to come from a colleague or a company you deal with, asking you to change payment details or approve something urgently.
A newer twist: AI voice cloning is making some of these frighteningly convincing. A few seconds of someone's voice — from a voicemail or a video online — can be enough to fake a call that sounds just like your boss or a family member.
WHY THEY WORK
Harder to check, easy to fake.
Texts and calls slip past our guard for a few reasons:
- ▸ Urgency and authority. A deadline, a threat or a figure of authority (your bank, the ATO, your CEO) pushes you to act before you think.
- ▸ A real-looking sender or caller ID. Phone numbers and text sender names are trivially spoofed, so a familiar number or a company name in the sender field proves nothing.
- ▸ They're harder to pause and inspect. An email sits in your inbox where you can check the details. A text or a live call feels like it demands an answer right now — which is exactly what the scammer is counting on.
HOW TO RESPOND
Slow down and verify.
- Don't tap links in unexpected textsIf a message is a surprise — a delivery, a fine, a bank alert — don't tap the link. Go directly to the organisation's app or website yourself instead.
- Never give away passwords, codes or access to someone who called youNo password, MFA code, PIN or remote access to your device — ever — to a person who contacted you out of the blue.
- Hang up and call back on an official numberEnd the call, then ring the organisation on a number you look up yourself — from the bank's website, or the back of your card. Don't use a number the caller gives you.
- Verify any "internal" request through a known channelIf a text or call seems to come from a colleague or your boss, confirm it through a channel you already trust — a quick call to their known number, or a message in your normal work chat.
- Report itTell your IT or security team so they can warn others, and report scams to Scamwatch (scamwatch.gov.au) so the wider community is protected too.
A simple rule of thumb. Legitimate banks and IT teams will never ring and ask for your password, full PIN, MFA codes, or remote access to "protect" you. That request is the scam.