Vishing and Smishing Attacks: Real-World Examples and How to Defend Against Them
Vishing surged 442% in 2024. Real vishing and smishing attack examples — MGM, toll scams, callback phishing — and a practical defense playbook.

In September 2023, an attacker phoned the IT help desk of MGM Resorts, impersonated an employee found on LinkedIn, and talked their way into a password reset. The ten-minute call led to a company-wide outage — slot machines, room keys, reservation systems — and roughly $100 million in lost earnings, as MGM disclosed to regulators.
No malware. No zero-day. No email. Just a voice on a phone.
That is the uncomfortable reality behind two of the fastest-growing attack techniques in social engineering: vishing (voice phishing) and smishing (SMS phishing). While security teams spent a decade hardening email, attackers quietly moved to the two channels almost nobody filters: phone calls and text messages.
Why phone and text bypass everything you have built
The two are close cousins. Vishing runs over a voice call, with caller-ID spoofing and AI voice generation letting an attacker be IT support, a bank, a vendor or your CFO. Smishing runs over SMS and messaging apps, where a single line — "your package is delayed", "unpaid toll", "suspicious bank charge" — carries the link.
They work for the same three reasons:
- No filtering layer. Your secure email gateway never sees a phone call or a text. The message lands directly on the employee's personal device, unscanned.
- Compressed decision time. A live caller creates real-time pressure that an email cannot. There is no "hover over the link" moment on a phone call.
- Mobile UI hides the evidence. On a small screen, truncated URLs, missing sender details, and app-like phishing pages are far harder to inspect than on a desktop.
The numbers: a channel shift, measured
| Statistic | Figure | Source |
|---|---|---|
| Growth in vishing attacks, H1 → H2 2024 | +442% | CrowdStrike 2025 Global Threat Report |
| Initial-access attacks that are malware-free | 79% | CrowdStrike 2025 Global Threat Report |
| U.S. consumer losses to text scams, 2024 | $470 million (5× the 2020 figure) | FTC, April 2025 |
| Total reported U.S. cybercrime losses, 2025 | $20.9 billion | FBI IC3 2025 Annual Report |
| Breaches involving the human element | 62% | Verizon DBIR 2026 |
The pattern behind these numbers is consistent: as malware-based intrusion gets harder, attackers log in instead of breaking in — and vishing and smishing are how they get the login.
Attackers didn't get better at beating your firewall. They got better at calling your help desk.
Real-world attack examples
1. The help-desk vishing call (MGM Resorts, 2023)
The blueprint of the MGM attack is now standard practice for groups like Scattered Spider: research an employee on LinkedIn, call the internal help desk, impersonate that employee, and request a password and MFA reset. Once inside, the attackers escalated to identity infrastructure and deployed ransomware. The entire initial access phase was a phone call — which is why help-desk identity verification is now one of the highest-leverage controls in this category.
2. The toll-road smishing wave (2024–2025)
Starting in March 2024, U.S. drivers began receiving texts about a small "outstanding toll" (typically around $12) with a warning of a $50 late fee. The FBI's Internet Crime Complaint Center logged over 2,000 complaints in the first month alone, and the campaign kept mutating through 2025, state by state, brand by brand. The lure works because the amount is trivially small — victims pay to make the annoyance go away, handing over card details in the process. The same kit is easily re-skinned as package-delivery or bank-alert texts, which the FTC lists among the top text scams by losses.
3. The smishing-to-vishing chain (Retool, 2023)
Attackers sent SMS messages to employees of software company Retool, posing as the IT team resolving a payroll issue. One employee clicked and logged in. The attackers then called that employee, using an AI-generated deepfake of a colleague's actual voice, and extracted the one extra piece they needed: an MFA code. Because an authenticator app was syncing codes to the cloud, one code compromised the whole account. Retool's own post-incident write-up is one of the most instructive public accounts of a hybrid smishing + vishing attack.
4. Callback phishing
A growing hybrid inverts the flow: the victim receives an email or text about a bogus charge ("your $399 subscription has renewed") with a support number to call. The victim initiates the call — which defeats caller-ID suspicion entirely — and the "agent" walks them into installing remote-access software. No link, no attachment, nothing for a filter to catch.
How to defend your organization
Technology alone will not solve a channel your technology cannot see. Effective defense combines procedure, technical controls, and measured human readiness.
1. Harden the help desk first. Require strict identity verification before any credential or MFA reset: callback to a number on file, manager confirmation, or video verification for sensitive accounts. Assume caller ID is forged. This single procedure would have blocked the MGM-style attack.
2. Deploy phishing-resistant MFA. Push notifications and SMS codes are exactly what vishers harvest. FIDO2 security keys and passkeys cannot be read out loud over the phone, and disabling cloud sync for authenticator apps removes the failure mode that sank Retool.
3. Create out-of-band verification rules for money and access. Any request to change payment details, buy gift cards, share codes, or install software — regardless of channel — gets verified through a second, known-good channel before action. Write it down as policy, and have executives publicly commit to it so urgency-based pretexts lose their power.
4. Make reporting effortless. Employees should have a one-tap way to report suspicious texts and calls, and reports should be praised even when they're false alarms. The FBI specifically asks organizations and individuals to report smishing to IC3, including sender numbers and URLs.
5. Simulate the channels attackers actually use. If your awareness program only tests email, you are measuring the one channel attackers are leaving. Run voice and SMS phishing simulations alongside email campaigns, and track outcomes per employee and per channel. Feeding those results into a Human Risk Score shows you exactly which teams are vulnerable to a phone-based pretext versus a malicious link — so training lands where the risk actually is.
6. Brief high-risk roles separately. Finance, executive assistants, IT support, and anyone with payment or reset authority face targeted, researched attacks — not bulk spam. Give them scenario-based briefings built from the real examples above, and include them in every simulation cycle.
The bigger picture
Vishing and smishing aren't isolated tricks; they are symptoms of the broader shift documented in our social engineering statistics roundup: attackers now target people because people are the least-instrumented part of the enterprise. Treating that exposure as a measurable, improvable risk — rather than an annual training checkbox — is the core idea behind human risk management.
The organizations that handle this well share one habit: they measure. They know their employees' response rates to simulated calls and texts, they watch those numbers fall quarter over quarter, and their help desks treat every reset request as untrusted until verified. None of that requires predicting the next lure — toll fees today, something else tomorrow. It requires knowing, with data, that your people and procedures hold when the phone rings.
Frequently asked questions
What is the difference between vishing and smishing?
Both are phishing variants that bypass email. Vishing (voice phishing) uses phone calls — a live attacker or an AI-generated voice persuades the target to hand over credentials, approve access, or move money. Smishing (SMS phishing) uses text messages containing malicious links or replies. They are frequently combined in a single attack chain: a text creates the pretext, and a follow-up call closes the deal.
Why are vishing and smishing increasing so fast?
Because email defenses got better and mobile defenses didn't. Secure email gateways, DMARC, and link scanning now block most bulk email phishing, so attackers moved to channels with almost no filtering: the phone network. CrowdStrike measured a 442% increase in vishing between the first and second half of 2024, and the FTC reported $470 million in U.S. losses to text scams in 2024 alone.
Does MFA protect against vishing attacks?
Only partially. Push-based and SMS-based MFA can be defeated by a convincing caller who talks the victim into approving a prompt or reading out a code, and help-desk vishing bypasses MFA entirely by getting credentials reset. Phishing-resistant MFA (FIDO2 hardware keys or passkeys) plus strict identity-verification procedures for help desks close most of this gap.
How do I train employees to spot vishing and smishing?
Simulation works better than lectures. Run realistic voice and SMS simulations alongside email phishing tests, measure who engages, and deliver short training at the moment of failure. Track improvement per employee and per channel over time — repeated exposure to safe simulations measurably lowers real-world click and disclosure rates.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo