The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

What Is Smishing?

Smishing is a phishing attack that uses SMS or other text messages to trick people into sharing sensitive information, opening malicious links, downloading malware, or taking another action that benefits an attacker.

Why smishing matters

Smishing brings familiar phishing attacks to a channel people often use for quick, everyday communication. Attackers can impersonate banks, delivery services, government agencies, employers, or other trusted organizations and send messages designed to prompt an immediate response.

Smishing is also a form of social engineering – instead of exploiting a software vulnerability directly, the attacker tries to influence a person's behavior. A message might claim that an account has been locked, a package can’t be delivered, or suspicious activity requires immediate verification.

A successful smishing attack can lead to several outcomes:

  • Credential theft: A fraudulent login page can capture usernames, passwords, or other authentication information.
  • Sensitive data exposure: Attackers may ask directly for personal, financial, or organizational information.
  • Malware infection: A link or download can lead to malicious software being installed on a device.
  • Account compromise: Stolen credentials can give an attacker access to email, financial, business, or other accounts.
  • Financial fraud: Some messages direct recipients to fraudulent payments or attempt to collect payment information.

Not every smishing attack follows the same path. A malicious link is common, but an attacker can also ask the recipient to reply with information, call a phone number, or download an application.

How smishing works

Smishing attacks combine a communication channel people recognize with a convincing pretext. The details vary, but the basic attack path typically moves from impersonation to a requested action.

1. The attacker establishes a pretext

The attacker creates a reason for contacting the recipient: They may impersonate a delivery company, financial institution, government agency, employer, or another recognizable sender.

2. The attacker sends a deceptive text

The message presents a situation that encourages a response. For example, it might report a failed delivery, suspicious bank transaction, account problem, or other issue that appears to require attention.

3. Social engineering creates pressure to act

The message may use urgency, concern, curiosity, or the appearance of authority to influence the recipient. The goal is to encourage action before the person verifies whether the message is legitimate.

4. The recipient is directed toward an action

The requested action depends on the attack. The message might direct someone to:

  • Open a link to a fraudulent website
  • Enter login or personal information
  • Reply with sensitive information
  • Call an attacker-controlled phone number
  • Download an application or other malicious content

5. The attacker pursues their objective

What happens next depends on the campaign. An attacker might capture credentials, collect sensitive information, obtain payment details, or deliver a malware attack.

Common smishing techniques and examples

The subject of a smishing message can change, but many attacks rely on the same basic components: a trusted identity, a believable story, a reason to act, and a destination or response controlled by the attacker.

Delivery and package messages

A recipient receives a text claiming that a package couldn’t be delivered. The message asks them to follow a link to reschedule delivery, confirm an address, or pay a small fee.

Bank and account alerts

A message appears to come from a financial institution and warns about suspicious activity or an account problem. It then asks the recipient to verify their identity or sign in through a supplied link.

These messages can be effective because legitimate organizations also send account notifications. The important distinction is where the message directs the recipient and what information it requests.

Authentication and password messages

An attacker can claim that an account needs to be verified, a password has expired, or an unusual login requires attention. A link may lead to a fraudulent login page designed to collect credentials.

Security controls such as multi-factor authentication (MFA) can add another authentication layer when a password is compromised, although organizations shouldn’t treat any single control as guaranteed protection.

Workplace impersonation

Smishing can also use a workplace pretext. An attacker might impersonate a colleague or other trusted contact and request information or another action. When phishing is deliberately tailored to a particular person or organization, it overlaps with spear phishing attacks.

How to recognize and respond to smishing

There is no single sign that proves a text message is malicious. Instead, look at the message's context, request, destination, and claimed sender before acting. Some of the more common warning signs include:

  • An unexpected request for login credentials, financial details, or other sensitive information
  • A link that doesn’t appear to match the organization the sender claims to represent
  • Pressure to act immediately because of an account, payment, security, or delivery problem
  • An unexpected request to download an application or file
  • A request to contact an unfamiliar number rather than an organization's established contact channel

If a message appears suspicious, avoid using the contact information or links contained in it to verify the request. Instead, contact the organization through a known website, phone number, application, or other trusted channel.

If someone has already interacted with a suspected smishing message, the appropriate response depends on what happened. Changing exposed credentials, reporting the incident through the appropriate security channel, and investigating the affected account or device can help determine whether additional action is needed.

How smishing fits into security operations

Smishing is best understood as part of the broader phishing and social-engineering landscape. The terms describe related concepts, but they aren’t interchangeable.

  • Phishing is the broader category of deceptive communications used to obtain information or prompt unsafe actions.
  • Smishing describes phishing conducted through SMS or other text messages.
  • Spear phishing describes phishing tailored to a specific person, organization, or target.
  • Vishing refers to phishing conducted through voice communications.

For security teams, that means smishing isn’t only a mobile-device issue. A successful attack can result in compromised credentials, malicious activity, or another incident that extends into organizational systems.

Defenses therefore span several areas: Security awareness can help people recognize suspicious requests; identity controls can reduce the impact of stolen credentials’ threat detection and incident response processes can help teams investigate activity when an interaction with a malicious message leads to compromise.

Author

Aaron Wells
Aaron Wells

Frequently asked questions