What is Smishing?
Smishing is a social engineering attack that uses SMS text messages or mobile messaging apps to trick recipients into clicking malicious links, revealing credentials, or transferring money. It targets personal and work devices, where users are often less cautious than on email.
What it is
Smishing combines "SMS" and "phishing." An attacker sends a text message that appears to come from a trusted source: a bank, a delivery service, an IT helpdesk, or a colleague. The message creates urgency and asks the recipient to click a link, call a number, or reply with sensitive information.
Common smishing scenarios include:
- Fake package-delivery alerts with a link to "reschedule delivery"
- Fake IT messages asking employees to reset a password via a spoofed portal
- Fake two-factor authentication prompts designed to steal one-time codes
- CEO or HR impersonation asking for gift-card purchases
Smishing works on any mobile device. Corporate mobile device management does not block it by default. Personal phones used for work (BYOD) are especially exposed because they sit outside most enterprise security controls.
Why it matters
Click rates on SMS messages are significantly higher than on email. People read texts quickly and often act without scrutinizing the sender. A single successful smishing attack can hand an attacker valid credentials, session tokens, or direct financial transfers. Attackers also use smishing as the first step in a multi-stage attack, combining it with voice calls (vishing) or follow-up email.
How tools address it
Phishing simulation platforms are the primary tool organizations use to build awareness of smishing. Some platforms in this category send simulated SMS or multi-channel social engineering messages to employees, then measure click rates and deliver immediate training to those who interact with the fake message. Security awareness training programs teach employees to recognize the warning signs: unexpected urgency, unfamiliar short codes, links that do not match the claimed sender, and requests for credentials or payment. Human risk management platforms track which employees repeatedly fall for simulated attacks and flag them for additional coaching.