The text from "your bank." The call from "HMRC." The email from "the CEO." Different channels, different scripts — but the same trick at the heart of all of them: someone you trust is not who they claim to be. Impersonation fraud does not break in. It is invited in, by a victim persuaded that the message is genuine.

These scams wear three names, one for each channel they travel down. Phishing arrives by email. Smishing arrives by SMS text message. Vishing arrives by telephone, as a live voice or a recorded one. The vocabulary is new; the con is ancient. Each is a confidence trick that borrows the identity of a trusted institution — a bank, a courier, a tax authority, an employer — to extract money, login credentials, or the one-time codes that unlock an account.

What unites them is impersonation, and what makes them dangerous is volume and polish. A criminal can send millions of messages at negligible cost, knowing that even a fraction of a percent of responses is profitable. Understanding how each channel works — and how the underlying psychology is the same — is the most reliable defence available to anyone with a phone.

The three channels, defined

Phishing, smishing, and vishing are not three separate threats so much as one threat using whatever route reaches you. Knowing which is which helps you recognise the pattern the moment it begins.

Phishing is the email version, and the oldest. A message appears to come from a familiar organisation and asks you to click a link, open an attachment, or "verify" your details on a page that mimics the real site. Smishing compresses the same idea into a text message — shorter, more urgent, and trusted more readily because we tend to treat our phones as personal. Vishing uses the telephone: a caller poses as your bank's fraud team, a tax inspector, or technical support, and talks you, in real time, into transferring money or surrendering a code. The live human contact makes vishing especially persuasive, because pressure can be applied moment by moment.

The modern tactics

The crude, typo-ridden message is largely a thing of the past. Today's impersonation fraud is professional, localised, and increasingly automated.

Spoofed senders and lookalike domains

Display names are trivial to fake, so an email may show "HMRC" or your bank's name while the underlying address is nothing of the sort. Lookalike domains push this further — a single transposed letter, an added hyphen, or a foreign-character substitution can produce a web address that reads correctly at a glance but belongs entirely to the fraudster.

Fake delivery and parcel texts

Among the most common smishing scripts is the "missed delivery": a text claiming a parcel could not be delivered and inviting you to pay a small redelivery fee or confirm your address. The sum is deliberately trivial; the goal is to harvest card details and personal data, which are worth far more than the fee itself.

Fake bank "fraud department" calls

In a classic vishing approach, the caller claims to be from your bank's fraud team and warns that your account is under attack. To "protect" your money, they say, you must move it to a "safe account." There is no safe account — it belongs to the criminal — and the urgency is engineered to stop you pausing to verify.

QR-code "quishing" and AI voice cloning

Newer tactics add fresh disguises. Quishing hides a malicious link inside a QR code — placed on a fake parking notice, a poster, or even a sticker over a legitimate one — so that the destination is invisible until you have already scanned it. More troubling still, AI voice-cloning tools can now reproduce a familiar voice from a short audio sample, lending a deepfake "relative in trouble" or "your chief executive" call a chilling plausibility. MFA-fatigue attacks, meanwhile, bombard a victim with repeated approval prompts in the hope that one is wearily accepted.

The psychology that makes them work

Technology delivers these scams, but psychology is what completes them. Every impersonation attempt is built on a small number of deeply human reflexes, deployed before reason can intervene.

The first is authority. We are conditioned to comply with figures of institutional power — a bank, the tax office, the police, a senior manager — and a convincing impersonation borrows that deference wholesale. The second is urgency: "act now or your account will be suspended," "the warrant will be issued in the hour." Time pressure is designed to collapse the gap in which you might stop and check. The third is fear — of losing money, of legal trouble, of letting down an employer. Frightened people do not reason carefully; they react. Combine an authoritative voice, an impossible deadline, and a threatened loss, and even careful, intelligent people can be steered into a decision they would never otherwise make.

The message is not trying to convince your judgement. It is trying to bypass it — to make you act on the feeling before your reason can ask a single question.
Red Flags to Recognise

Any one of these warrants caution. Several together are a near-certain sign of an impersonation scam:

  • Unexpected urgency — a threat, a deadline, or a warning that something will be lost if you do not act immediately.
  • Links to click or attachments to open in a message you were not expecting.
  • Any request for security codes, passwords, PINs, or one-time passcodes.
  • A sender address or phone number that is slightly off, even when the display name looks right.

How to break the chain

Impersonation fraud depends on you trusting the channel it arrives on. The defence is to refuse that trust by default and verify on a route you control — every time, without exception.

How to Protect Yourself
  • Never click links in unsolicited messages. Treat any link in an unexpected email or text as suspect, however convincing the sender appears.
  • Verify independently. Contact the organisation using a number or website you already trust — the number on the back of your bank card, or an address you type yourself — never the contact details supplied in the message.
  • Never share one-time codes. No legitimate bank, retailer, or authority will ever ask you to read out a security code, password, or PIN. A genuine caller already knows not to ask.
  • Enable multi-factor authentication. MFA blocks most account takeovers — but approve a prompt only when you yourself initiated the login, never on demand.
  • Use a password manager. Beyond strong, unique passwords, a manager will not auto-fill your credentials into a lookalike domain — a quiet, reliable warning that a site is fake.
  • Report it. In the UK, forward suspicious texts to 7726 (spelling "SPAM" on the keypad), report scam emails to the NCSC, and report fraud to Action Fraud.

How Crejj & Partners can help

Our Financial Recovery & Civil Claims team acts for individuals and businesses who have lost money to impersonation fraud — whether a single fraudulent transfer or a sustained, sophisticated attack. We move quickly to preserve evidence, engage with banks under the rules governing authorised push payment fraud, pursue recall of payments, and bring civil claims and tracing efforts against those who can be identified. Where credentials or codes have been compromised, we advise on containing the damage and protecting against further loss. If you have responded to a message you now doubt, or transferred money you fear was a mistake, the time to speak to us is now.

Key Takeaways
  • Phishing (email), smishing (SMS), and vishing (phone) are three channels for one con: impersonating a trusted institution to extract money or credentials.
  • Modern tactics include spoofed sender names, lookalike domains, fake parcel texts, "safe account" bank calls, QR-code quishing, AI voice cloning, and MFA-fatigue prompts.
  • The scams work by exploiting authority, urgency, and fear — reflexes designed to make you act before you can verify.
  • Break the chain by refusing to trust the channel: never click unsolicited links, never share one-time codes, and always verify on a number or website you already trust.
  • If you have responded or paid, contact your bank at once, preserve the evidence, report it, and seek legal advice promptly.
C&P
Crejj & Partners — Financial Recovery & Civil Claims
Fraud, Asset Tracing & Civil Recovery
Our team advises victims of investment, romance, and authorised-payment fraud on rapid evidence preservation, civil remedies, and recovery strategy. We act with discretion and urgency from the first call.

This article is provided for general information only and does not constitute legal advice or create a solicitor–client relationship. Fraud situations are fact-specific and time-sensitive; if you believe you have been targeted, seek tailored advice promptly. Crejj & Partners is a fictional firm presented for illustrative purposes on this website.