Remix.run Logo
james_marks 16 hours ago

> In 2023, hackers used vishing (voice phishing) to impersonate employees and gain access to the internal systems of MGM Resorts International and Caesars Entertainment on the Las Vegas Strip, causing hundreds of millions of dollars in financial losses.

First time I’ve heard the term “vishing” to describe the attack we’ve all seen coming.

wrayjustin 16 hours ago | parent | next [-]

Phishing (Email), Smishing (SMS/Text Messages), and Vishing (Voice) are all standard industry terms, though obviously phishing is most well known.

Then there's even subcategories that further define some of these, like Spear Phishing, Whaling.

The industry loves its fun naming.

airstrike 15 hours ago | parent | next [-]

"Phishing" isn't limited to email

lostlogin 12 hours ago | parent | next [-]

That’s lucky. Putting ‘ishing’ on the end of something email related doesn’t work very well.

jerrythegerbil 14 hours ago | parent | prev [-]

[flagged]

gpm 14 hours ago | parent [-]

That's not my understanding, or wikipedia's [1] understanding, of the term. Phishing is the general category of tricking people into telling you things they shouldn't. Email phishing, voice phishing (vishing), sms phising, and so on are subcategories.

[1] https://en.wikipedia.org/wiki/Phishing

Etymologically "phreak" and "fishing" both have nothing to do with email, "phreak" is "phone freak" and I believe it originally described messing with the tones that controlled the telephone system...

jerrythegerbil 4 hours ago | parent [-]

That’s my exact point. Just because you repeatedly see it used a certain way by non-practitioners to generalize for simplified communication doesn’t mean it’s the correct usage, and leads to the exact confusion I’m attempting to clarify for you.

Phishing is by default email. It’s varying mediums are subcategories.

Bottom paragraph of first section of the very same Wikipedia article.

“Phishing techniques and vectors include email spam, vishing (voice phishing), targeted phishing (spear phishing, whaling), smishing (SMS), quishing (QR code), cross-site scripting, and MiTM 2FA attacks.”

airstrike 3 hours ago | parent [-]

Phishing is not by default email

mmaunder 13 hours ago | parent | prev | next [-]

Never heard of vishing. I’m in the industry.

saithound 11 hours ago | parent [-]

Wrong industry. It is primarily the "sell anti-phishing training to enterprise employees" industry that uses these terms.

8 hours ago | parent [-]
[deleted]
Ekaros 3 hours ago | parent | prev | next [-]

Why is it not emishing with email?

Razengan 6 hours ago | parent | prev [-]

> Smishing

uh that's something completely different (and not Monty Python)

electroglyph 16 hours ago | parent | prev | next [-]

social engineering is as old as hacking itself

ChrisMarshallNY 16 hours ago | parent [-]

That was Mitnick’s specialty, and he was hacking before the Web.

AstroNutt 12 hours ago | parent [-]

The Art of Deception was one of my favorite books when it came out.

StanislavPetrov 12 hours ago | parent | prev [-]

In my day we used to call it "social engineering".

Barbing 11 hours ago | parent [-]

“human hacking”