A helpdesk technician is reviewing a security ticket submitted by a finance manager. The manager received a text message on her mobile phone appearing to come from the company's banking vendor, warning that the organization's payroll account would be locked within 30 minutes due to unverified compliance documentation. The message contained a hyperlink prompting her to log in immediately. Which of the following social engineering attack vectors describes this initial contact method?
- SmishingAnswer
- BVishing
- CSpear phishing
- DWatering hole attack
Answer
The correct attack vector is smishing, as it specifically utilizes SMS text messaging on mobile devices to deliver deceptive phishing links.
Smishing refers specifically to phishing attacks conducted over Short Message Service (SMS) text messages. The scenario describes an urgent text message sent to a cellular device containing a fraudulent link designed to harvest banking credentials.
Step-by-Step Solution
Key Concept
Social Engineering Delivery Vectors (Smishing vs. Vishing vs. Phishing)