Vishing and smishing are not semantic variations of phishing. They are distinct channels that now require a different response. For CISOs, IT, and compliance teams in LATAM, the key point is that PCI DSS already requires coverage of phishing, related attacks, and social engineering in awareness programs, and it also requires acceptable use training for end-user technologies such as mobile devices, while regional risk is rising precisely through SMS, WhatsApp, and voice. If the program still centers on email or on course completion, it leaves an operational gap in both compliance and real exposure of the CDE, Coggno, Segurilatam, Kaspersky.
What appears when the sources are put together
The sources either describe the terms separately, explain PCI, or show regional pressure in LATAM. What emerges when they are read together is a concrete operational gap: the formal requirement is already in PCI DSS and the real pressure has already shifted to mobile and voice, but many programs still measure only email or course attendance.
| Subject type | Primary channel | Target action | Program or control requirement | Evidence of measurement or scope | LATAM relevance | fuente |
|---|---|---|---|---|---|---|
| Vishing | subtype of phishing / social engineering | voice, phone calls, or voice messages | induce the victim to reveal sensitive information or start a trust-based conversation | not specified | phishing by voice communication, calls or voice messages to obtain credentials, cards, or banking data | not specified |
| Smishing | subtype of phishing / social engineering | SMS or text messages | get the victim to click a link, download files or apps, or start a conversation | not specified | CISA defines it as phishing by text message, IBM and Experian link it to information theft or malware | Segurilatam reports 286 million mobile fraud attempts via SMS and WhatsApp in 2023, and 74% of organizations in LATAM victims of smishing |
| PCI DSS 12.6 | compliance requirement | not specified | ensure staff know the policy, procedures, and their role in protecting cardholder data | formal awareness program implemented | applies to PCI entities in LATAM, the source does not regionalize | PCI SSC |
| PCI DSS 12.6.3.1 | compliance sub-requirement | not specified | awareness of threats and vulnerabilities that could affect cardholder data, including phishing, related attacks, and social engineering | minimum content required starting March 31, 2025 | applies to PCI organizations in LATAM, the source does not regionalize | Coggno |
| PCI DSS 12.6.3.2 | compliance sub-requirement | end-user technologies, including mobile devices, remote access, and removable media | acceptable use of end-user technologies | minimum content required starting March 31, 2025 | relevant because smishing is shifting to mobile devices | Coggno |
| LATAM exposure context | regional risk series | fake messages, mobile, SMS, and WhatsApp | fraud, phishing, and smishing at scale | not specified | Kaspersky recorded 1.291 billion phishing blocks in Latin America between 2023 and 2024, an 85% increase, and Segurilatam reported 286 million mobile fraud attempts and 74% of organizations as smishing victims | explicit |
| Whalemate HRM approach | operating model / platform | multichannel, not limited to email | simulate, train, measure, intervene, and report human risk | the risk score consolidates signals from simulations, courses, reports, and behavior, and is used to prioritize interventions, not for discipline | Whalemate is aimed at IT, CISO, and compliance teams in Latin America | Whalemate HRM, Whalemate |
What exactly does it mean that vishing and smishing are variants of phishing?
The overlap across sources is broad: vishing and smishing are phishing subtypes differentiated by channel. CISA defines vishing as phishing by voice communication and smishing as phishing by text messages, CISA PDF. NIST reinforces that phishing is no longer limited to email and can appear as fraudulent text messages or fraudulent phone calls.
Experian summarizes phishing, smishing, and vishing as differing in how the attacker contacts the victim, email, text, or phone, Experian. SentinelOne and Dexpose use the same channel-based classification, distinguishing phishing, smishing, and vishing by email, SMS, and voice calls. Whalemate's reading is that this distinction is not just useful for an internal glossary: it enables separate metrics by channel, because the behavior to detect and correct is not identical in voice, SMS, or email.
Why does the channel difference change operational risk?
In vishing, CISA describes a conversation dynamic designed to build trust and get the victim to disclose sensitive information, including by inducing the person to call a specified number. Cisco adds that those calls or voice messages seek credentials, card numbers, or banking data. Adaptive Security adds that attackers also seek MFA codes or transfers.
In smishing, the dominant pattern is different. CISA ties it to messages that lead the user to click, download files or applications, or start a conversation, CISA PDF. IBM, Egress, and NCB highlight the mobile component, links, and automatic opening of browser, email, or call features, IBM, Egress, NCB. Whalemate's reading is that a single phishing indicator is not enough if vishing aims to sustain a conversation and smishing aims to trigger an immediate action on the device.
What does PCI DSS 12.6 require, and why isn't a single course enough?
The SAQ D Merchant document for PCI DSS v4.0 states that a formal security awareness program must be implemented so that all personnel know the security policy and procedures and their role in protecting cardholder data, PCI SSC. Whalemate's material, aligned with that requirement, emphasizes that PCI DSS 12.6 requires an awareness program, not an isolated course, Whalemate.
Secondary ISO 27001 summaries point in the same direction of continuous process. Control Institute and High Table note that people under the organization's control must be aware of the policy, their contribution to the system, and the implications of noncompliance, Control Institute, High Table. Guardey, High Table, Cyberzoni, and Advisera add that control 6.3 requires a formal program, broad coverage, regular updates, and evidence of effectiveness, Guardey, High Table Annex A 6.3, Cyberzoni, Advisera. Whalemate's reading is that compliance is already pushing toward continuity and evidence, not toward annual training disconnected from real behavior.
What do PCI DSS 12.6.3.1 and 12.6.3.2 add to the problem?
Coggno explains that under 12.6.3.1 the training must include awareness of threats and vulnerabilities that could affect cardholder data, including phishing, related attacks, and social engineering, Coggno. The same source says that 12.6.3.2 requires coverage of acceptable use of end-user technologies such as remote access, mobile devices, and removable media, also starting March 31, 2025, Coggno.
That intersection changes how vishing and smishing should be read by PCI teams. If smishing happens through SMS, messaging, and mobile, and if vishing uses calls, voicemail, VoIP, and even AI-driven impersonation, then the expected scope of the program cannot stay limited to email phishing. Whalemate's reading is that 12.6.3.1 and 12.6.3.2 together require mapping human risk and technology use by channel, not just proving attendance in a training session.
Where is the tension between NIST's broad guidance and real-world execution?
NIST says two relevant things. First, phishing is not limited to email and also appears as smishing and vishing. Second, teams need to stay vigilant across all communication areas, NIST. That wording expands the awareness perimeter.
Whalemate, in its reading of NIST SP 800-50r1, shifts the focus from the presentation to practical exercise. It argues that the enterprise-wide program should include phishing, spear phishing, vishing, and smishing, and that the operational focus is not the talk but whether the user detects the attempt or clicks, Whalemate blog. The tension is not doctrinal, it is about execution: NIST expands the channels, but if the organization does not test observable behavior by channel, it is left with educational intent and no evidence of response.



