Smishing
Smishing (SMS phishing) is a social engineering attack that uses text messages to trick recipients into clicking malicious links or sharing sensitive information.
Smishing — a combination of "SMS" and "phishing" — delivers social engineering attacks through text messages. Because people tend to trust SMS more than email and read texts faster, smishing often achieves higher interaction rates than email phishing.
How it works
Smishing messages typically impersonate a trusted entity — a bank, delivery service, tax authority, or employer — and create urgency:
- Package delivery alerts. "Your parcel could not be delivered. Schedule redelivery: [link]." The link leads to a credential-harvesting page or malware download.
- Banking alerts. "Unusual activity detected on your account. Verify now: [link]." The fake banking page captures login credentials and one-time codes.
- IT/HR pretexts. "Your VPN certificate expires today. Renew here: [link]." Employees on mobile devices are less likely to inspect URLs before tapping.
- MFA code harvesting. "Your verification code is 482913. If you did not request this, call [number]." The attacker socially engineers the victim into sharing the real MFA code.
Mobile devices make smishing harder to detect: URLs are shortened or truncated, there is no hover-to-preview, and sender IDs can be spoofed to match legitimate short codes. Personal phones used for work under BYOD arrangements widen the exposure further, since work accounts sit one tap away from an unfiltered personal inbox.
How to defend against it
- Include SMS in simulation programs. Email-only testing leaves a blind spot. NOUSEC simulations support SMS as a first-class channel.
- Educate employees on SMS-specific red flags — unexpected links from short codes, urgency language, requests for codes or credentials.
- Deploy mobile threat defense on corporate devices to flag known-bad URLs opened in mobile browsers.
- Establish a reporting path for SMS so employees can forward suspicious texts the same way they report phishing emails.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo