Quick quiz. Someone sends you a text pretending to be your bank. Is that phishing? Vishing? Smishing? If you had to pause and think, you’re not alone, and that’s exactly the problem.

phishing, vishing, smishing quishing, what’s the difference?

Scammers have four main ways of getting to you: email, phone, text and QR code. Each one has its own name, its own tricks and its own warning signs. Knowing the difference isn’t just trivia for cyber security nerds. It’s the kind of everyday knowledge that could save your business a very bad day.

Because here’s the truth nobody likes to say out loud: this isn’t a case of if it happens to you, it’s a case of when. So, let’s make sure you’re ready.

phishing: the one that started it all

Phishing is the classic. An email lands in your inbox, made to look like it’s from your bank, a supplier, a colleague or even your boss. It usually asks you to click a link, download a file or hand over information you’d never normally share.

The scary part? These emails have got a lot better. Poor spelling and dodgy logos used to be the giveaway. Now, with AI doing the writing, phishing emails can look polished, sound professional and even reference real people and real projects.

vishing: phishing, but on the phone

Vishing is voice phishing. Instead of an email, it’s a phone call, and the person on the other end is putting on a very convincing act. They might claim to be from your bank, a government department or even your own IT team, asking you to confirm details or move money urgently.

AI has raised the stakes here too. Voice cloning tools can now copy the sound of a real person, meaning a call that sounds exactly like your finance director asking for an urgent transfer might not be your finance director at all.

smishing: phishing by text message

Smishing is phishing sent straight to your phone as a text. You’ll recognise the pattern: a missed delivery, a suspicious bank alert, a prize you didn’t enter for, all with a link attached that wants you to act fast.

The trick with smishing is speed. Texts feel personal and urgent, so people tend to react before they think. That’s exactly what scammers are counting on.

quishing: phishing hidden in a QR code

Quishing is the newest name on the list, and it uses QR codes to do the dirty work. You scan what looks like a normal code, perhaps on a poster, an invoice or a parking machine, and it quietly takes you to a fake website designed to steal your details.

Because QR codes hide the web address until you scan them, and most email security tools aren’t built to check inside an image, quishing can slip through defences that would catch a dodgy link in plain text.

why knowing the difference matters

You might be thinking, does it really matter what we call it, as long as we know to be careful? Fair question. But each type of scam relies on a different moment of trust: your inbox, your phone call, your text messages, your camera.

Knowing the specific tricks for each one means you and your team know exactly what to look out for, wherever the attack comes from.

And with AI making all four harder to spot than ever, “I’ll just know it when I see it” isn’t a strategy anymore.

how to stay one step ahead

✅ Slow down before you click, scan, call back or reply, especially if something feels urgent

✅ Double check unexpected requests for money or information through a separate, trusted channel

✅ Turn on multi-factor authentication wherever you can

✅ Be wary of QR codes from sources you can’t verify, and check the web address before entering any details

✅ Make sure your team knows all four terms, not just phishing, and knows it’s always okay to report something that feels off

✅ Keep your email security and staff training up to date. Scammers evolve, so your defences need to as well

Let’s get your team fluent in scam

Learning to spot phishing, vishing, smishing and quishing shouldn’t feel like homework. It should feel like a habit your whole team picks up together, so that when one of these does land in your inbox, on your phone or under a QR code, you’re ready for it.

Last week we joined a cyber resilience event and heard from Welsh Government and Dyfed Powys Police. One message came through loud and clear: it’s no longer a case of if an attack comes your way. It’s when.

That shift in thinking changes everything. Instead of hoping you won’t be targeted, the smart move is preparing for the moment you are, so your business can respond fast, protect its data and keep moving. If you haven’t had that conversation yet, now’s a good time to start.

That’s where we come in. We’ll help you put the right training, tools and safeguards in place, so your business is prepared long before “when” arrives.

Book a 10-minute discovery call with us and let’s get your defences ready. Also, find out how secure you are; download for your free Cyber Readiness Checklist to assess your setup independently.