
From Email to WhatsApp: The Expanding World of Smishing and Vishing Attacks
For two decades, “phishing” meant one thing: a suspicious email. We trained our people to scrutinize their inboxes, and we built filters to catch the worst of it. But while we were guarding the front door, attackers walked around the side. Today, the most dangerous lures arrive not in a corporate inbox but on the device we trust most and guard least — the phone in our pocket. Text messages, WhatsApp chats, and phone calls have become primary attack channels, and they slip past both our technical defenses and our mental ones. The era of email-only phishing is over, and any organization still defending only the inbox is protecting the wrong door.
The Phone Is the New Front Line
There is a simple reason attackers have moved to mobile: it is where our guard is lowest. We treat our phones as personal, intimate spaces. A text message feels more immediate and more trustworthy than an email, and we tend to read and respond to them within minutes. Messaging apps like WhatsApp carry an added layer of implied intimacy — these are the channels we use with family, friends, and close colleagues. When a scam arrives there, it borrows that sense of closeness.
The data confirms the migration. A remarkable 41% of phishing incidents are now multi-channel, combining email, SMS, QR codes, and voice. Attackers no longer rely on a single touchpoint. They might send an email, follow up with a text, and finish with a phone call, each step reinforcing the illusion of legitimacy. This coordinated approach is far harder to spot than a lone suspicious email, because each individual contact seems plausible and the combination feels like genuine, persistent communication from a real organization.
Smishing: Trouble in a Text Message
“Smishing” — phishing via SMS or messaging apps — thrives on brevity and immediacy. A text has no room for the elaborate formatting that sometimes gives away a phishing email, and that simplicity works in the attacker’s favor. A short message claiming a package is delayed, a payment failed, or an account needs verification, paired with a single tappable link, is enough. On a small screen, the destination of that link is nearly impossible to inspect, and the casual, on-the-go context in which we read texts discourages careful thought.
WhatsApp and similar apps have added new dimensions to this threat. Attackers impersonate executives, recruiters, or delivery services, striking up a conversation that feels personal and direct. A common scheme involves a message that appears to come from a senior leader, asking an employee to discreetly handle an urgent task or purchase. Because the conversation happens in a chat app rather than a monitored corporate system, it unfolds entirely outside the organization’s visibility — and outside its protection.
Vishing: The Return of the Phone Call
If smishing exploits the text message, “vishing” exploits the human voice. Voice-based phishing surged 442% in 2025, a staggering rise that reflects how effective it has become. A phone call adds urgency and emotional pressure that text simply cannot match. A live human voice — confident, authoritative, and seemingly in a hurry — is profoundly persuasive, and it leaves the victim little time to reflect.
Artificial intelligence has made vishing dramatically more dangerous by removing its old limitations. Voices can now be cloned convincingly from short audio samples, so the caller may sound exactly like a trusted executive. The results are alarming: 41% of organizations were hit by a deepfake combined with social engineering on an audio call, and 35% on a video call. The world has already seen what this can cost — the engineering firm Arup lost $25 million to a deepfake video call impersonating its CFO and colleagues in 2024. What once required an attacker to be a skilled impersonator can now be accomplished with software.
Why Mobile Channels Slip Through the Cracks
The shift to mobile is not just a change of venue; it is a change in the balance of defense. Email security has matured over decades, with sophisticated filters scanning every message. The mobile and voice channels have no equivalent. Consider what makes them so exposed:
1. Personal devices often sit outside corporate security monitoring, especially when employees use their own phones for work.
2. Text messages and chat apps lack robust, built-in scam filtering, so malicious messages arrive unflagged.
3. Phone calls cannot be content-scanned in real time the way emails can.
4. The casual, trusted context of mobile communication lowers people’s natural skepticism.
The financial stakes of this gap are real. Business email compromise — increasingly initiated or reinforced through these mobile channels — caused $3.046 billion in losses across 24,768 complaints in 2025, while total US cybercrime losses reached $20.877 billion, up 26% year over year (FBI IC3 2025). For organizations under India’s DPDP Act, a breach that originates from a mobile or voice scam carries the same regulatory weight as any other, with penalties up to ₹250 crore for inadequate safeguards and a mandatory duty to report every breach.
Defending Beyond the Inbox
The encouraging reality is that the human defenses against smishing and vishing are consistent, no matter the channel. The core instinct is the same one that protects against email phishing: when a message or call creates urgency, requests money or sensitive information, or pressures you to bypass normal procedures, pause and verify through an independent channel. A suspicious text from “the CEO” should be confirmed with a known phone number. An urgent call demanding a transfer should trigger a callback to a verified line, never the number that called.
But these instincts only hold if people have practised them, and most security programs still focus almost entirely on email. Verizon’s 2025 research found that traditional one-off training did little to change click rates — and that gap is even wider for channels people were never trained to question in the first place. The solution is to extend realistic, supportive practice across every channel attackers use, not just the inbox.
Conclusion
Phishing has expanded far beyond the inbox, and the most dangerous lures now arrive on the device we trust most and guard least. Smishing exploits the immediacy of a text, while vishing — supercharged by AI voice cloning — exploits the persuasive power of a live human voice, and the two increasingly work together in coordinated, multi-channel campaigns. These mobile channels slip through the cracks precisely because they lack the mature filtering that email enjoys and because our guard is naturally lower. The human defense is the same across every channel: pause and verify through an independent line. Attackers have expanded their reach from the inbox to WhatsApp and the phone call, and your defenses, and your people’s instincts, need to expand with them.
How Shieldbyte Infosec Can Help
Shieldbyte Infosec’s ShieldPhish platform closes the mobile gap by running safe, realistic simulations across email, SMS, messaging apps, and voice — not just the inbox. By letting people experience smishing and vishing attempts in a controlled setting, and turning each one into a brief, encouraging coaching moment, ShieldPhish helps your team carry their skepticism onto every device and into every conversation. The platform measures human risk across all of these channels, so you can see where exposure is greatest rather than assuming email is the only front line. Adaptive training then directs practice toward the channels and people that need it most. Clear reporting gives leadership a complete view of resilience beyond the inbox. If you are curious how your team would respond to a scam that arrives by text or voice rather than email, we would be glad to help you find out.

