Smishing
Phishing attacks delivered via SMS text messages, tricking recipients into clicking malicious links or sharing personal information.
Smishing, a portmanteau of SMS and phishing, is a cyberattack that uses text messages to deceive victims into taking harmful actions. Attackers send fraudulent SMS messages that appear to come from legitimate sources — banks, delivery services, government agencies, or employers — containing malicious links or instructions to call fake support numbers. The concise nature of text messages and the trust people place in SMS communications make smishing particularly effective.
The rise of smishing parallels the shift toward mobile-first communication. People tend to read and respond to text messages far more quickly than emails, and mobile devices often display shortened URLs that obscure the true destination. Attackers exploit these factors by creating time-sensitive messages — package delivery alerts, account security warnings, or two-factor authentication requests — that prompt immediate action without careful scrutiny. Smishing links typically lead to credential-harvesting pages optimized for mobile browsers or trigger the download of mobile malware.
Smishing is increasingly used as part of multi-channel attack strategies. An attacker might send a smishing message that references a phishing email, or use SMS to deliver one-time passcodes to bypass multi-factor authentication on accounts they are simultaneously compromising. Mobile device management (MDM) solutions, SMS filtering apps, and user awareness are key defenses against this growing threat vector.
The rise of smishing parallels the shift toward mobile-first communication. People tend to read and respond to text messages far more quickly than emails, and mobile devices often display shortened URLs that obscure the true destination. Attackers exploit these factors by creating time-sensitive messages — package delivery alerts, account security warnings, or two-factor authentication requests — that prompt immediate action without careful scrutiny. Smishing links typically lead to credential-harvesting pages optimized for mobile browsers or trigger the download of mobile malware.
Smishing is increasingly used as part of multi-channel attack strategies. An attacker might send a smishing message that references a phishing email, or use SMS to deliver one-time passcodes to bypass multi-factor authentication on accounts they are simultaneously compromising. Mobile device management (MDM) solutions, SMS filtering apps, and user awareness are key defenses against this growing threat vector.
Examples
- A text message claiming to be from a delivery service with a link to reschedule a package delivery that leads to a phishing site.
- An SMS alert pretending to be from a bank warning of unauthorized activity and requesting login credentials via a link.
- A fake text from a toll authority demanding immediate payment to avoid penalties, with a malicious payment link.
Prevention
- Never click links in unsolicited text messages; navigate directly to official websites or apps instead.
- Enable spam filtering and SMS protection features available on modern smartphones.
- Report suspicious text messages to your mobile carrier by forwarding them to 7726 (SPAM).
- Verify any urgent claims by contacting the organization directly through official channels.