The Phone Call That Cost One Company $23 Million

In early 2024, a finance employee at a multinational firm in Hong Kong joined a video call with what appeared to be the company's CFO and several colleagues. Every person on the screen was a deepfake. The employee transferred $25.6 million before anyone realized the entire call was a sophisticated vishing operation. That incident made global headlines, but it was just the tip of the iceberg.

The FBI warning on vishing and smishing attacks has grown louder every year, and for good reason. The Bureau's Internet Crime Complaint Center (IC3) reported over $12.5 billion in total cybercrime losses in its 2023 annual report, with phishing — including voice phishing (vishing) and SMS phishing (smishing) — remaining the single most reported crime type. If you think these attacks only target grandparents and the tech-illiterate, you're dangerously wrong.

What Exactly Are Vishing and Smishing?

Vishing is voice-based social engineering. A threat actor calls you — or deepfakes a video call — pretending to be your bank, your IT department, or a government agency. The goal is credential theft, wire transfers, or installing remote access tools on your device.

Smishing uses SMS or messaging apps to deliver malicious links or trick you into sharing sensitive data. That text from "USPS" about a missed package? That urgent "fraud alert" from your bank? Classic smishing.

Both bypass email security entirely. Your spam filter, your email gateway, your DMARC policy — none of them can stop a phone call or a text message. That's exactly why attackers have pivoted hard toward these channels.

Why the FBI Keeps Sounding the Alarm

The FBI has issued multiple public service announcements about vishing and smishing, including specific warnings about campaigns targeting remote workers. In 2020, the FBI and CISA released a joint advisory detailing how threat actors were using vishing to harvest VPN credentials from employees working from home. That campaign hasn't slowed down — it's evolved.

Here's what I've seen change since then. Attackers now use AI-generated voice clones that sound exactly like your CEO. They spoof caller ID so the call appears to come from your company's actual phone number. They time their smishing messages to arrive during business hours when you're distracted and less skeptical.

The FBI's IC3 data consistently shows phishing and its variants as the number one reported cybercrime category, with hundreds of thousands of complaints filed annually. The FBI warning on vishing and smishing isn't hypothetical — it's based on massive, documented losses across every industry.

The Anatomy of a Modern Vishing Attack

Step 1: Reconnaissance

The attacker scrapes LinkedIn, your company website, and social media. They identify your name, title, reporting structure, and the tools your company uses. This takes minutes, not days.

Step 2: The Call

You receive a call from someone claiming to be IT support. They reference your actual help desk ticketing system by name. They know your manager's name. They say there's been a security incident and they need to verify your identity — by having you enter your credentials on a site they control.

Step 3: Credential Theft and Escalation

Once they have your login, they attempt to bypass multi-factor authentication. Common methods include MFA fatigue attacks (bombarding you with push notifications until you approve one), SIM swapping to intercept SMS codes, or simply social engineering the MFA reset process with your help desk.

Step 4: Access and Damage

With valid credentials, the threat actor moves laterally. They deploy ransomware, exfiltrate data, or set up persistent access for later use. The Verizon 2024 Data Breach Investigations Report found that stolen credentials were involved in roughly 31% of all breaches over the past decade. Vishing is one of the most effective ways to steal them.

Smishing: The Attack Vector in Your Pocket

Smishing has exploded because it exploits a simple truth: people trust text messages more than email. Research consistently shows SMS open rates above 90%, compared to roughly 20% for email. Attackers know this.

Common smishing scenarios I've encountered in the wild include fake shipping notifications from USPS, FedEx, or UPS with malicious tracking links. Fake bank fraud alerts asking you to "verify" your account by entering credentials. Fake HR messages during open enrollment or tax season. Messages impersonating IT teams with links to credential harvesting pages designed to look like Microsoft 365 or Okta login screens.

The FTC has documented numerous scam patterns using these exact techniques, and they continue to warn consumers and businesses alike.

How Do You Defend Against Vishing and Smishing?

This is likely the question that brought you here, and the answer requires layered defenses. No single tool solves this.

  • Security awareness training is your front line. Your employees need to recognize vishing and smishing attempts before they hand over credentials. Regular, scenario-based training — not a once-a-year compliance checkbox — actually changes behavior. Our cybersecurity awareness training program covers these exact attack vectors with real-world examples.
  • Implement phishing-resistant MFA. SMS-based MFA is better than nothing, but it's vulnerable to SIM swapping. Hardware security keys (FIDO2/WebAuthn) or app-based authenticators with number matching are far more resilient against social engineering.
  • Adopt a zero trust architecture. Never assume a user is legitimate just because they have valid credentials. Verify continuously based on device posture, location, and behavior.
  • Establish callback verification procedures. Train employees to hang up and call back using a known, published number — never the number the caller provides. For wire transfers or sensitive requests, require out-of-band verification through a separate channel.
  • Run vishing and smishing simulations. Just like phishing simulations test your email defenses, voice and SMS simulations test your human defenses against these channels. Our phishing awareness training for organizations includes simulation capabilities that help you measure and improve resilience.
  • Filter and block at the carrier level. Enable carrier-level spam filtering and consider enterprise mobile threat defense solutions that can detect and block smishing URLs before employees tap them.

The $4.88M Lesson Most Organizations Learn Too Late

IBM's Cost of a Data Breach Report has consistently found that the global average cost of a data breach hovers near $4.88 million. Breaches that start with social engineering — including vishing and smishing — tend to take longer to identify and contain, which drives costs even higher.

I've worked with organizations that had excellent email security, advanced endpoint detection, and rigorous network segmentation — but zero training on voice and SMS-based social engineering. Their employees picked up the phone and gave away the keys to the kingdom.

The FBI warning about vishing and smishing isn't just for consumers. It's for CISOs, IT directors, and security teams who assume their perimeter defenses cover every attack surface. Your employees' phones are part of that perimeter now, whether you've secured them or not.

What Makes 2026 Different

Three factors have made vishing and smishing dramatically more dangerous this year.

AI voice cloning is accessible and cheap. Tools that can clone a voice from a few seconds of audio are widely available. A threat actor can pull audio from a CEO's earnings call, conference presentation, or podcast appearance and generate a convincing clone in minutes.

Smishing-as-a-service platforms have matured. Just like ransomware-as-a-service, underground markets now offer turnkey smishing kits with templates, link shorteners, and even customer support. The barrier to entry has nearly disappeared.

Remote and hybrid work is permanent. Employees are accustomed to receiving IT support calls and HR notifications on personal devices. The contextual cues that once helped people detect scams — like recognizing that IT would never call your cell phone — no longer apply.

Your Action Plan Starts Now

Don't wait for the FBI's next warning to take action. Start with an honest assessment: when was the last time your organization trained employees specifically on vishing and smishing? If the answer is "never" or "I'm not sure," you have a gap that threat actors are already exploiting.

Build a training program that addresses voice and SMS attacks alongside traditional email phishing. Make verification procedures for sensitive requests non-negotiable. And invest in phishing-resistant MFA before an attacker social engineers their way past your current setup.

The FBI has told you what's coming. The data backs it up. The only question is whether you act before or after a vishing call costs your organization millions.