Phishing, Vishing and Smishing Explained
One trick, three channels: email, phone call, SMS. Here's how to tell them apart and what the law says.
Phishing, vishing and smishing are the same trick sent down three different pipes. A fraudster pretends to be someone the victim trusts (the bank, the income tax department, a courier company) and asks for something that unlocks the victim's money: a password, card details, an OTP, or an app install. Phishing uses email or fake websites, vishing uses voice calls, and smishing uses SMS.
For bank staff these are the frauds that walk into the branch the next morning. The customer is usually not careless; the message was urgent, looked official, and arrived at a busy moment.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The Three Lures Compared
Channel
Phishing
Email, fake websites
Vishing
Phone call (voice phishing)
Smishing
SMS (SMS phishing); the same pattern on WhatsApp
Typical bait
Phishing
"Your net banking will be blocked, verify here"
Vishing
"I'm calling from your bank's KYC desk, please confirm the OTP"
Smishing
"KYC expired, update now" with a short link
What it steals
Phishing
Login ID and password, card details
Vishing
OTP, card PIN, approval of a UPI request
Smishing
Credentials via a link, or installs an app that reads SMS
Tell-tale sign
Phishing
Sender domain or link that is close to, but not, the bank's
Vishing
Pressure to act during the call; asks for an OTP or PIN
Smishing
Shortened link, spelling errors, sender ID that is a normal mobile number
| Phishing | Vishing | Smishing | |
|---|---|---|---|
| Channel | Email, fake websites | Phone call (voice phishing) | SMS (SMS phishing); the same pattern on WhatsApp |
| Typical bait | "Your net banking will be blocked, verify here" | "I'm calling from your bank's KYC desk, please confirm the OTP" | "KYC expired, update now" with a short link |
| What it steals | Login ID and password, card details | OTP, card PIN, approval of a UPI request | Credentials via a link, or installs an app that reads SMS |
| Tell-tale sign | Sender domain or link that is close to, but not, the bank's | Pressure to act during the call; asks for an OTP or PIN | Shortened link, spelling errors, sender ID that is a normal mobile number |
Variants You Should Recognise
- Spear phishing
- A phishing message tailored to one person, using details such as their name, branch or recent transaction to look genuine.
- Whaling
- Spear phishing aimed at senior people, such as a bank's CFO or a corporate client's treasurer, where one approval moves large sums.
- Clone phishing
- A copy of a real email the victim already received, with the link or attachment swapped for a malicious one.
- Pharming
- Redirecting a victim to a fake site even when they type the correct address, by tampering with DNS settings or the device. No bait message is needed.
- Business email compromise
- A forged or hijacked email from a known supplier or executive asking for payment to a new account number.
What a Branch Should Do When a Customer Reports One
- 1
Block first
Block the card, net banking and UPI access at once so the attacker can't make further debits.
- 2
Point the customer to 1930
The national helpline (or cybercrime.gov.in) starts the process of tracing and holding the money in the receiving accounts. Speed matters more than paperwork here.
- 3
Record the complaint with time
Note the date and time the customer reported. RBI's customer liability rules turn on how quickly the bank was told.
- 4
Preserve evidence
Screenshots of the SMS or email with full sender details, the caller's number, and the transaction references.
- 5
Escalate internally
Route through the bank's fraud monitoring and incident process. Phishing campaigns aimed at the bank's brand are reportable to CERT-In within 6 hours under its 2022 Directions.
Quick practice on banking operations. No signup.
The Law That Applies
Using a victim's password, OTP or other unique identification feature is identity theft under section 66C of the IT Act: up to 3 years' imprisonment and a fine of up to ₹1 lakh. Pretending to be the bank over a phone or computer to cheat someone is cheating by personation under section 66D, with the same punishment. Police usually add the Bharatiya Nyaya Sanhita offences of cheating (section 318, formerly IPC 420) and cheating by personation (section 319, formerly IPC 419).
A suspected fraud call or SMS where no money was lost can be reported on the Department of Telecommunications' Chakshu facility on Sanchar Saathi. Chakshu is not for reporting an actual loss; that goes to 1930 or the cyber crime portal.
How the IIBF Exam Tests This
Scenario MCQs: "A customer receives an SMS with a link to update KYC..." and the options are phishing, vishing, smishing and pharming. Match the channel, not the bait. The common trap is pharming: if no message lured the victim and the correct web address still led to a fake site, it is pharming. Expect also a law question pairing 66C (identity theft) with 66D (personation); both carry the same punishment, so learn what each covers.
FAQs
What is the difference between phishing, vishing and smishing?expand_more
The channel. Phishing uses email or fake websites, vishing uses phone calls, and smishing uses SMS. All three impersonate a trusted organisation to steal credentials, OTPs or money.
What is the punishment for phishing in India?expand_more
There is no offence named phishing. It is usually charged under IT Act sections 66C (identity theft) and 66D (cheating by personation), each up to 3 years and a fine up to ₹1 lakh, along with BNS sections 318 and 319.
Where do I report a phishing call or SMS?expand_more
If money was lost, call 1930 or file on cybercrime.gov.in, and tell your bank immediately. If no money was lost, report the suspected fraud call or message on Chakshu (Sanchar Saathi).
Does a bank ever ask for an OTP over the phone?expand_more
A genuine bank employee has no reason to ask a customer for an OTP, PIN or password. An OTP is the customer's approval of a transaction, so sharing it hands that approval to whoever asked.
Next steps
- Social Engineeringarrow_forward
- Identity Theftarrow_forward
- Reporting Cyber Crimearrow_forward
- Online Banking Fraudarrow_forward
120 questions, 2 hours, scored instantly.
