High School BeginnerModule B9Lesson 3 of 7

B9.3 Smishing, Vishing, and Social Media Scams

Learn how phishing appears through texts, calls, voicemail, direct messages, social posts, gaming chats, and copied profiles—and practice safe verification across channels.

Lesson Progress

Smishing, Vishing, and Social Media Scams

High School BeginnerB9: Phishing and Social Engineering Defense • Lesson 3 of 7

43% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

The Channel Changes, but the Manipulation Often Stays the Same

A suspicious request may arrive as a delivery text, fraud call, voicemail, copied social profile, emergency direct message, prize post, or gaming chat. The sender may change the channel to make the request feel more personal or urgent.

Safety reminder: every phone number, text, voicemail, account, profile, post, link, and payment request in this lesson is fictional.

Learning Objective

Explain smishing, vishing, direct-message scams, and social account impersonation.

Learning Objective

Recognize suspicious links, caller pressure, copied profiles, emergency requests, and code demands.

Learning Objective

Choose separate verification channels without replying, calling back, paying, or sharing information.

Why This Matters

Fast, Personal Channels Can Reduce Careful Thinking

Texts, calls, and direct messages often feel immediate and personal. That speed can make people respond before checking. Strong defenders create distance from the request and verify through another trusted route.

Visual Diagram

The Cross-Channel Scam Review Flow

The communication channel may change, but the defensive process remains consistent: identify the channel, pressure, requested action, and trusted verification method.

1

Identify the channel

Decide whether the request arrived by text, phone, voicemail, direct message, social post, or gaming chat.

2

Identify the pressure

Look for urgency, fear, rewards, authority, secrecy, emergency claims, or requests for quick payment.

3

Identify the target action

Determine whether the sender wants a click, reply, call, payment, code, login, download, or account approval.

4

Verify separately

Use an official website, known number, school portal, trusted adult, or known contact method.

Defender rule: never verify a suspicious request using the same message, phone number, profile, or reply thread that delivered it.

Core Concept

Verify the Person or Organization Outside the Suspicious Channel

A familiar number, voice, profile picture, username, or message history does not prove identity. Numbers can be spoofed, profiles can be copied, and accounts can be compromised. Separate verification is essential.

Key Vocabulary

Terms for Cross-Channel Phishing

Smishing

Phishing delivered through text messages, messaging apps, or other mobile-message channels.

Vishing

Voice phishing carried out through phone calls, voicemail, or voice-based communication.

Direct-message scam

A deceptive request sent through a social platform, gaming service, chat app, or community account.

Caller ID spoofing

Making a call appear to come from a trusted number even when the caller is somewhere else.

Account impersonation

Using a copied profile, stolen account, familiar name, or similar username to appear trustworthy.

Separate verification

Confirming a request through another known official channel instead of replying, calling back, or using the suspicious message.

Technical Breakdown

Communication Channel Clue Board

Different channels have different clues, but requests for urgency, secrecy, money, credentials, codes, or unsafe links require the same careful verification.

Text-message clues

Review question

Does the text use a shortened link, urgent fee, delivery claim, account warning, prize, or unknown sender?

Safer choice

Do not reply or use the link. Open the official service directly.

Phone-call clues

Review question

Does the caller demand secrecy, payment, remote access, a code, or immediate action?

Safer choice

End the call and contact the organization using a known official number.

Social-profile clues

Review question

Does the account have a similar username, copied photo, unusual request, new payment demand, or changed writing style?

Safer choice

Verify through another known channel before trusting the profile.

Recovery and account clues

Review question

Does the message request a password, MFA code, recovery code, login approval, or account-reset action?

Safer choice

Do not provide anything. Review the official account and report the request.

Fake Dashboard

Smishing, Vishing, and Social Scam Panel

This fictional panel compares deceptive texts, calls, voicemails, direct messages, and social posts without contacting any sender.

Fake Data

Delivery text

Shortened link asks for a small redelivery fee

Do not use the link. Open the delivery company’s official website or app directly.

Bank call

Caller demands a one-time code to stop fraud

End the call. Contact the bank through the number on the official website or card.

Friend direct message

Account requests emergency money and says not to call

Verify through another known channel because the account may be copied or compromised.

Prize post

Social message claims the student won and must sign in now

Do not use the link. Confirm the promotion through the verified official account.

School voicemail

Message asks the student to call an unfamiliar number and provide credentials

Do not call the number. Use the official school directory or portal.

Fake Dashboard

Fake Cross-Channel Scam Dashboard

Training dashboard using fictional text, phone, voicemail, direct-message, and social-platform evidence.

Requests reviewed

22

Fictional texts, calls, voicemails, social posts, and direct messages.

Impersonation clues

13

Spoofed numbers, copied profiles, familiar names, and fake support identities.

Verified separately

10

Requests were checked using official websites, known numbers, or trusted contacts.

Fake SOC Alert

Caller Requests MFA Code to Stop Fraud

Source: Fake Phone Scam Training • Time: 3:18 PM

High Severity
A fictional caller claims to be from a bank, says fraud is happening now, and requests a one-time code to secure the account.
Defensive recommendation: Do not share the code. End the call, open the official banking app or website, and contact the bank through a known official number.

Fake Log Panel

Fake Cross-Channel Review Log

training-log-viewer.log
15:06:02 CALLER_ID displayed='known_bank_number' identity_verified='false'
15:08:17 PRESSURE tactic='fraud_urgency' secrecy='requested'
15:10:31 REQUEST type='one_time_code' policy_match='false'
15:12:46 CALL action='ended_without_sharing_information'
15:15:09 VERIFICATION channel='official_bank_app' result='no_matching_alert'
15:18:04 REPORT method='trusted_adult_and_official_bank_number' status='completed'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

What Makes This Social Message Suspicious?

A fictional profile uses a close friend’s name and photo.
The username contains one extra character.
The message asks for emergency money immediately.
The sender says not to call or tell anyone.

What is the safest conclusion?

Common Mistakes

Mistakes That Make Cross-Channel Scams More Effective

Trusting a text because it includes the correct name, location, or recent activity.
Assuming caller ID proves who is calling.
Calling back the number provided in a suspicious voicemail.
Sending money because a familiar social profile claims there is an emergency.
Sharing MFA codes, recovery codes, passwords, or payment details during a call or chat.
Using the suspicious message’s link, number, profile, or reply thread to verify the request.

Safe Defensive Lab

Compare Fictional Text, Call, and Social Scenarios

Fake Scenario Set

Cross-Channel Scam Review

A fictional student receives a delivery text, a bank call, an emergency friend message, a prize post, and a school voicemail.

Defender Review Steps

  • Identify the communication channel.
  • Name the manipulation tactic and requested action.
  • Identify what evidence is unverified.
  • Choose a separate official verification channel.
  • Decide whether the scenario should be ignored, verified, or reported immediately.

Scenario Decision Lab

A Delivery Text Requests a Small Fee

A fictional text says a package cannot be delivered until a small fee is paid through a shortened link.

Scenario Decision Lab

A Caller Claims to Be School Technology Support

A fictional caller says the student’s school account is being attacked and asks for the current MFA code.

Defender Habits

Smishing, Vishing, and Social Scam Checklist

Check Your Understanding

B9.3 Mini Quiz: Smishing, Vishing, and Social Media Scams

Choose your answers first. Explanations appear only after submission.

1. What is smishing?

2. What is vishing?

3. Why should caller ID not be trusted by itself?

4. A friend’s social account asks for emergency money and says not to call. What is the safest response?

5. What should a student do with a delivery text containing a shortened payment link?

Portfolio Prompt

Portfolio Prompt

Create a one-page fictional cross-channel scam comparison. Include one text, one phone call, one voicemail, one direct message, and one social post. For each, identify the pressure tactic, requested action, warning signs, separate verification method, and safest response.

Use fictional numbers, accounts, messages, links, organizations, and payment requests only.
Do not include real suspicious phone numbers, URLs, credentials, or private information.
Explain why the displayed number, profile, or name does not prove identity.

Key Takeaways

What You Should Remember

1.Smishing uses text or mobile messages, while vishing uses phone calls or voicemail.
2.Copied profiles, compromised accounts, and spoofed caller ID can make scams appear familiar.
3.Emergency requests, secrecy, quick payment demands, and requests for codes are major warning signs.
4.Verification should happen outside the suspicious channel.
5.Passwords, MFA codes, recovery codes, payment details, and private information should never be shared with an unverified sender or caller.

Navigation

Continue Module B9