
Phishing, vishing and smishing are three types of social engineering fraud where scammers attempt to steal your financial account credentials, passwords or personal information by impersonating a trusted source. The main difference is in how they reach you. Phishing arrives by email, smishing by text message and vishing by phone call. Regardless of the contact method, you should always react the same way: never share account information with anyone who reaches out to you.
It happens every day. Someone receives a text that looks like it’s from their bank, a call from a person who sounds like a fraud investigator or a personalized email requesting an urgent account action. Only later do they realize they were scammed when they discover bank withdrawals, unfamiliar credit card charges or collection calls for debts they don’t recognize.
These scams are growing fast and becoming increasingly sophisticated. According to Citizens’ recent Cybersecurity & Fraud Survey*, only 16% of respondents feel completely confident they could recognize a financial scam. To protect your personal and financial information, it helps to understand exactly what you’re up against.
Phishing, vishing and smishing may appear as separate, isolated scams. In reality, these channels are simply the entry points — the delivery methods — that fraudsters use to launch much larger financial crimes, such as account takeovers or identity theft. Understanding exactly how a scammer is trying to reach you is critical because the channel they choose determines your specific defense. Let's break down how to recognize each delivery method so you know exactly how to verify or block them.
Phishing is a type of email-based fraud where scammers impersonate a trusted organization to steal credentials or personal information. In 2024 alone, the Federal Bureau of Investigation received 193,407 phishing complaints, resulting in over $70 million in losses.
Phishing emails often look very convincing. They may include company logos and be written in a way that builds trust. You can identify phishing emails by looking for:
For example, you might receive an email that appears to be from the "Citizens Security Team,” reporting unusual activity and asking you to verify your account information right away. However, clicking on the provided link takes you to a fake login page that records your account information.
Key red flags to watch for in emails include:
Vishing is a type of fraud where scammers contact you by phone or voicemail. You may talk to a live or AI-generated caller impersonating a bank, government agency or other trusted institution. Keep in mind that Citizens will never call you to collect your card information or ask for your password.
Vishing is a rapidly growing scam. The CrowdStrike 2025 Global Threat Report states that vishing attacks increased 442% from the first to the second half of 2024. The Pew Research Center also reports that 68% of U.S. households receive at least one scam call each week.
Scammers can spoof caller ID, making vishing calls appear to come from real institutions. They often create a sense of urgency to force you to make quick decisions without thinking. They might tell you "your account has been compromised," and ask for a one-time passcode, account numbers or verification information. They may also use AI cloning to impersonate real people using only seconds of voice audio.
For example, you might receive a phone call with a caller ID that shows it's from a delivery service. When you answer, the friendly voice says there’s a problem with the delivery and that they need to confirm your identity before the package can be released.
Key red flags to watch for in phone calls include:
Smishing is a type of fraud where scammers contact you via text messages that often contain malicious links or prompts to call a fraudulent number. Because you receive these messages on trusted devices, you may not perceive them as dangerous. The Anti-Phishing Working Group reports that smishing grew 30% to 40% each quarter in 2025.
Smishing messages often impersonate banks, delivery services or government agencies. Similar to phishing, the short text messages create a sense of urgency. They urge you to click a link to a spoofed site that captures your login credentials or installs malware on your device.
For example, you might receive a text message claiming that a suspicious charge was made with your debit card. It asks you to click a link right away to verify the purchase. However, when you do, you're taken to a spoofed site that records your login credentials.
Key red flags to watch for in text messages include:
AI has made it much easier for scammers to create official-looking emails and text messages and impersonate company representatives. Scams that used to require a high-budget team are now inexpensive, even for a single person.
"As technology advances, so do the tactics used by scammers," says Brendan Goode, Chief Security Officer at Citizens. "AI has made it easier for criminals to create convincing emails, text messages and even phone calls, making it critical for consumers to stay current on emerging threats. A healthy level of skepticism and an understanding of today's fraud techniques can go a long way in protecting your finances and personal information."
When phishing, vishing and smishing are used together as part of a single coordinated attack, messages can feel more real, increasing their effectiveness. According to research compiled by StationX, 35% of all phishing attempts involve text messages.
For example, you might receive a phishing email claiming unusual account activity, but ignore it, assuming it's a scam. An hour later, you receive a smishing text with a case number, and you think it might be legitimate after all. Then you call the "fraud line" number in the text and reach a visher using an AI-generated voice. By the time you realize you’ve been manipulated, you’ve confirmed your account number and provided your login credentials.
Scams are designed by professionals to deceive smart, careful people, and you shouldn't feel bad for responding to one. Instead of panicking, follow these steps right away to report fraud and protect your accounts and personal information:
Phishing, vishing and smishing scams are increasing, but that doesn't mean you're powerless against them. The best way to prevent fraud is to always apply the same logic when you receive unsolicited messages and never share your account credentials or one-time passcodes.
If a message feels off, trust that instinct and contact Citizens before responding. Our dedicated Fraud and Security Center can help you detect and protect yourself from phishing, vishing and smishing.

Shopping online is easy and convenient, but you have to watch for digital fraud. Explore the steps to shop safely and protect yourself.

Citizens may occasionally contact you. Here's how we protect your information, and how you can know a message is really from us.

Learn how you can protect yourself and your information from different types of fraud.
© Citizens Financial Group, Inc. All rights reserved. Citizens Bank, N.A. Member FDIC
Disclaimer: The information contained herein is for informational purposes only, as a service to the public, and is not legal advice or a substitute for legal counsel, nor does it constitute advertising or a solicitation. You should do your own research and/or contact your own legal or tax advisor for assistance with questions you may have on the information contained herein.
* The Citizens Cybersecurity & Fraud Survey was conducted by Wakefield Research among 1,000 nationally representative U.S. consumers age 16 and older. The survey was fielded from February 27 to March 13, 2026, using an online survey methodology. Data has been weighted to align with national benchmarks. The margin of error for the total sample is ±3.1% at a 95% confidence level. Weighting is a statistical technique used to adjust survey data after collection to improve the accuracy of survey estimates.
**Wireless carrier, text and/or data charges may apply.