Cybersecurity Glossary

What is Smishing?

Smishing is phishing delivered by SMS or a similar text message. Attackers impersonate delivery services, banks, public authorities, mobile carriers or internal support. A link, callback or reply is intended to obtain credentials, payment information, one-time codes or installation of a malicious app.

How does smishing work?

Campaigns use stolen phone numbers, random number ranges or data from earlier leaks. Links lead to a mobile copy of a login or payment page. Other messages request a callback, where an attacker presents a prepared support story. Against corporate targets, an employee may be asked to install an alleged security app, device profile or remote-support software.

PretextRequested action
Parcel or customs feeEnter a small payment and card information.
Bank warningOpen a login, approve a transaction or call “support.”
Missed invoiceOpen a link, QR code or attachment.
Corporate ITDisclose an MFA code, install an app or permit device access.
Wrong personBegin an apparently accidental conversation and build trust.

Why do text messages appear credible?

Mobile screens truncate long URLs and sender details, while messages are read on the move and under time pressure. Sender numbers can be spoofed or messages sent through compromised accounts; a device may place a fraudulent message in an existing conversation. RCS and messaging apps add imagery, branding and interactive buttons that look professional but do not authenticate the content automatically.

How can smishing be recognized?

  • An unexpected message demands immediate payment, login or security confirmation.
  • The link uses a shortened, unrelated or lookalike domain.
  • A password, PIN, recovery or MFA code is requested by message or telephone.
  • Installation outside an official app store, a device profile or a remote-support app is requested.
  • The claim does not appear in the known app or on a website opened independently.

How should recipients respond?

Do not use the link, number or reply function from the message. Open the official app, type the known website independently or use an already saved telephone number. Never disclose codes or passwords. Forward work-related messages through the reporting route or preserve a screenshot with sender, text and time. Block and delete only after preserving what is needed.

What should happen after a click or data entry?

  1. A click alone does not necessarily mean compromise; close the page and report it.
  2. Change submitted credentials from a trusted device, revoke sessions and review MFA.
  3. For payment information, contact the bank or card issuer immediately using known details.
  4. After installing an app, profile or remote tool, disconnect the device and obtain expert examination.
  5. Do not rush into a factory reset when evidence preservation or corporate analysis is required.

How can organizations protect mobile communication?

Business processes should never base sensitive approval solely on an incoming text. Phishing-resistant MFA, mobile device management, managed app sources and DNS or web filtering reduce impact. Training must account for personal and corporate devices and provide easy reporting. SMS one-time codes are better than no second factor but weaker against real-time phishing, SIM swapping and disclosure than FIDO2 methods.

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on Smishing? Tell us!