It’s Not Just Email Anymore: Scam Texts and Phone Calls Are Hitting Small Businesses 

« Back to Knowledge Center

Would Your Team Recognize a Scam If It Came Through a Text or Phone Call? 

An employee gets a text that appears to be from the owner asking them to handle an urgent payment. Another receives a call from someone claiming there’s a problem with the company’s Microsoft account. Someone else gets a text from a vendor asking them to review an updated invoice. None of these messages arrive by email, but they can be just as dangerous as traditional phishing. 

Cybercriminals are increasingly using text messages and phone calls to impersonate executives, vendors, financial institutions, IT providers, and other trusted contacts. These attacks are known as smishing and vishing, and they rely on one thing every business has: people who communicate quickly throughout the workday. 

What Is Smishing in Cyber Security? 

Smishing is phishing conducted through SMS or text messages. Instead of sending a fraudulent email, an attacker sends a text designed to convince someone to click a malicious link, provide login credentials, share sensitive information, or take another action. 

A smishing message might look like: 

  • A manager asking an employee to process an urgent payment 
  • A bank warning that a business account has been locked 
  • A vendor sending updated payment information 
  • A delivery service reporting a problem with a shipment 
  • An IT provider asking someone to verify their account 

These messages often create urgency or concern so the recipient acts before stopping to verify the request. 

What Is Vishing? 

Vishing, short for “voice phishing,” uses phone calls or voice messages instead of texts or emails. 

The caller may claim to represent your bank, software provider, government agency, vendor, or even someone within your organization. They may ask an employee to provide account information, share a verification code, transfer money, or grant remote access to a company device. 

Don’t assume caller ID makes a call legitimate. Cybercriminals can spoof phone numbers to make a call appear to come from a familiar company or local number. Some vishing attacks also begin with an email or text that directs the employee to call a fraudulent number, allowing attackers to move the conversation to a channel where traditional email security tools have less visibility. 

Why Smishing and Vishing Can Be So Convincing 

Most employees have heard about phishing emails. They may be less likely to question a text message or phone call, especially when it appears to come from someone they know. Smishing and vishing rely heavily on social engineering by creating believable situations and then pressure the recipient to respond quickly. 

Common warning signs include: 

  • Unexpected requests for passwords, MFA codes, or financial information 
  • Urgent payment or account-change requests 
  • Links from unfamiliar phone numbers 
  • Calls requesting remote access to a business device 
  • Requests to bypass normal approval procedures 
  • Threats that an account will be suspended or closed 
  • Pressure not to verify the request with someone else 

Attackers may even know your employee’s name, job title, company, or vendor relationships. However, much of that information can be found online or obtained through previous data breaches. Those details don’t make the caller or sender legitimate. 

How to Protect Your Business from Smishing and Vishing 

Technology is an important part of cybersecurity, but these attacks are specifically designed to manipulate people. Employee awareness and clear security procedures are critical. 

Train Employees Beyond Email Phishing 

Cybersecurity awareness training should cover suspicious texts, calls, and voicemails in addition to email. Employees should understand that phishing can happen through any communication channel and know the warning signs before they encounter a real attack. 

Verify Unexpected Requests 

If someone asks for money, passwords, account changes, MFA codes, or sensitive information, verify the request through a separate, trusted channel. 

Don’t call the number included in a suspicious text or voicemail. Use a phone number you already have, visit the company’s official website, or contact the person through an established internal channel. 

Protect Accounts with MFA 

Multi-factor authentication adds another layer of protection if an employee’s password is compromised. Employees should also know that MFA codes need to be protected. An unexpected caller or texter asking for a verification code should immediately raise a red flag. 

Create a Clear Reporting Process 

Your employees shouldn’t have to decide on their own what to do with a suspicious message. 

Create a simple process: 

  1. Don’t click, respond, or provide information. 
  1. Verify the request through a trusted channel. 
  1. Report the message or call to your IT team or managed service provider. 
  1. Block and report suspicious numbers when appropriate. 

Blocking unwanted numbers can help stop spam texts, but employee training is what helps prevent a targeted scam from becoming a cybersecurity incident. 

Frequently Asked Questions 

What is the difference between phishing, smishing, and vishing? 

All three use social engineering to trick people into sharing sensitive information, clicking malicious links, or giving attackers access to accounts or systems. The primary difference is the communication method. 

  • Phishing typically uses email. 
  • Smishing uses SMS or text messages. 
  • Vishing uses phone calls or voice messages. 

How can I tell if a business text message is a scam? 

Be cautious of unexpected links, requests for sensitive information, urgent payment requests, unfamiliar numbers, and messages asking you to bypass normal procedures. When in doubt, verify the request independently before responding. 

How do I stop spam texts? 

Most smartphones allow users to block and report suspicious numbers. However, businesses should also train employees not to click links or respond to unexpected messages and to report suspicious texts internally. 

Can scammers fake a phone number? 

Yes. Caller ID can be spoofed, making a call appear to come from a familiar company, organization, or local number. Always verify sensitive requests independently, even when the caller ID looks legitimate. 

Phishing Doesn’t Stop at the Inbox 

Your employees may know not to click a suspicious email, but would they recognize the same scam if it arrived as a text from the “CEO” or a phone call from “Microsoft support”? 

Cybercriminals will use whatever channel gives them the best opportunity to gain someone’s trust. 

We help small and mid-sized businesses prepare their teams for today’s cybersecurity threats through employee security awareness training, proactive monitoring, and managed cybersecurity solutions. 

If you’re not sure whether your employees are prepared to recognize phishing outside of email, now is a great time to find out. 

Schedule an IT assessment with ITSecureNow to identify potential security gaps and build a cybersecurity strategy that protects your people, systems, and data.