Smishing and Vishing: The SMS and Phone Scams Targeting Your Business
Smishing is a scam text; vishing is a scam phone call. Both pressure your staff into paying invoices, sharing codes or clicking links. Learn the tells — urgency, unknown numbers, requests for one-time codes — and give your team one simple rule: stop, verify on a trusted number, then act.
When the scam does not arrive by email
Most small businesses have learned to be wary of dodgy emails. But criminals have noticed, and they have moved to channels your team trusts more: the text message and the phone call. These attacks have names — smishing (phishing by SMS text) and vishing (phishing by voice call) — and they are aimed squarely at busy staff who are trying to be helpful.
The method is the same as any phishing email: pretend to be someone you trust, create pressure, and get you to act before you think. Only the delivery has changed. And because a phone call feels more personal and a text feels more urgent, these scams often work better than email ever did.
What smishing looks like
Smishing is a scam text. It usually lands with a link and a reason to click it right now. Common versions hitting UK businesses include:
- Fake delivery notices — “Your parcel is held, pay a £1.45 redelivery fee here.” The fee is bait; the real goal is your card details.
- Bank and card alerts — “Unusual activity detected. Confirm it was you.” The link leads to a fake login page.
- HMRC and tax refunds — “You are owed a rebate of £248.30.” HMRC never texts you a link to claim money.
- Fake staff messages — a text claiming to be the boss: “Are you free? I need you to sort something quickly.” This is often the opening move in an invoice or payment scam.
The giveaway is almost always the link. A real organisation will tell you to log in through their app or website — not tap a shortened link in a text.
What vishing looks like
Vishing is a scam phone call. The caller sounds calm, professional and in a hurry to help you. Typical scripts include:
- The fake fraud team — “We have spotted fraud on your account and need to move your money to a safe account.” No genuine bank will ever ask you to move money to keep it safe.
- The IT support call — “We are your IT provider, we have detected a virus, please install this remote-access tool.” Once installed, they control the machine.
- The code request — “To verify your identity, read me the six-digit code we have just sent you.” That code is a one-time passcode, and reading it out hands them the keys.
- The supplier chase — “Our bank details have changed, can you confirm you have the new ones for the next invoice?”
Criminals can fake the number that shows on your phone, so a call that appears to come from your bank may not be. The displayed name or number proves nothing.
The tells your team should know
Across both smishing and vishing, the warning signs are remarkably consistent:
- Urgency and threat — act now, or your account is closed, your money is lost, your parcel is returned.
- A request for codes, passwords or card details — no legitimate caller needs these.
- A change of payment details — new bank account, new sort code, “just this once.”
- A push to install software or click a link you did not expect.
- An unusual channel — the boss suddenly texting from an unknown number instead of the usual one.
No genuine bank, Microsoft, HMRC or supplier will ever phone or text and ask you to read out a one-time code, move money to a safe account, or install remote-access software.
How your team should respond
The single most effective defence costs nothing and takes thirty seconds. Teach every member of staff one rule: stop, verify, then act.
- Stop. Do not tap the link. Do not read out the code. Do not move any money. Pressure is the scammer’s only tool — removing the rush removes their power.
- Verify on a trusted number. Hang up and phone the organisation back on a number you already have — the one on the back of your card, on a past invoice, or in your saved contacts. Never use the number the caller or text gave you. If a supplier’s bank details have “changed”, confirm it by calling a known contact, never by replying.
- Act only once you are sure. A real request will still be there in five minutes. A scam falls apart the moment you slow down.
Make it explicitly safe for staff to be cautious. Many scams succeed because an employee is worried about looking unhelpful or holding up the boss. A short internal policy that says “you will never be in trouble for verifying a payment or a login” is worth more than any piece of software.
Practical protections to put in place
Alongside training, a few simple controls make a real difference:
- Turn on multi-factor authentication everywhere you can. Even if a scammer captures a password, MFA is a strong second lock — provided nobody reads the code out loud.
- Agree a call-back rule for payments. Any change to bank details or any unusual payment request must be confirmed by phoning a known contact first.
- Report and forward. Forward scam texts to 7726 and report scams to Action Fraud. Reporting helps networks block the numbers for everyone.
- Keep a calm, written playbook so staff know exactly what to do when a suspicious call or text arrives — before it happens, not during the panic.
Where DACROS fits in
Smishing and vishing work because they target people, not just computers. The businesses that shrug these off are usually the ones with a clear, well-rehearsed routine and the right technical controls quietly working in the background. That is exactly the combination we set up for clients across Leeds and Yorkshire — sensible cyber-security and staff training that fits how your team actually works, not a lecture nobody remembers.
If you would like a hand putting simple, jargon-free protections in place, get in touch — a short conversation is often enough to close the gaps that matter most.
Frequently asked questions
What is the difference between smishing and vishing?
Smishing is phishing by SMS text message — a scam text that tries to make you click a link or reply with information. Vishing is phishing by voice — a scam phone call where someone pretends to be your bank, a supplier, HMRC or even a colleague. Both rely on pressure and pretending to be someone you trust.
Should we ever read out a one-time passcode over the phone?
No. A one-time passcode (the six-digit code from a text or app) is for you to type in yourself, never to read aloud. No genuine bank, Microsoft or supplier will ever phone and ask you to read one out. If a caller asks for a code, it is a scam — hang up.
A text says a parcel needs a small delivery fee. Is it real?
Almost certainly not. Fake delivery texts asking for a small fee are one of the most common smishing scams. The goal is to capture your card details on a convincing but fake page. Never pay from a link in a text — go to the courier's official website or app directly.
How do I report a scam text or call in the UK?
Forward suspicious texts to 7726 (free) — it spells 'SPAM' on your keypad. Report scam calls and texts to Action Fraud on 0300 123 2040 or online. If money has moved, contact your bank immediately using the number on the back of your card.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.