Glossary
What is RCS phishing?
RCS phishing is phishing delivered through Rich Communication Services, the messaging standard that adds images, logos, buttons and read receipts to text messages.
- Also known as
- Rich messaging phishing
- Channel
- RCS messages on mobile phones
- Typical goal
- Credentials, card details, payments
- Related term
- Smishing
How it works
Richer messages,
more convincing fakes.
- 01
Look official
The message uses a business-style name, logo, images and cards that resemble a real brand’s messages.
- 02
Add a button
Instead of a bare link, a tidy “Pay now” or “Track parcel” button hides the destination.
- 03
Create urgency
A failed payment, held parcel or expiring reward needs attention today.
- 04
Collect
The button opens a fake page for logins, card details or a payment request.
How to spot it
Good design is
not a credential.
A logo, a product image and a neat button cost an attacker very little. Treat them as decoration, not proof.
Warning signs
- Unexpected message with payment or login buttons
- Sender name you haven’t seen before
- Button destination you can’t see
- Small fee, failed payment or expiring reward
- Asks for card details or a one-time code
Verify in the official app, then report.
Questions buyers ask
Frequently asked questions.
What is RCS messaging?
RCS (Rich Communication Services) is a messaging standard that upgrades SMS with features such as images, typing indicators, read receipts and interactive buttons.
Is RCS phishing different from smishing?
It follows the same idea but uses richer formatting. Buttons and branding can make the message look more official and hide where a link goes.
Does a business name or logo mean the message is genuine?
Not on its own. Look-alike names and copied logos are easy to produce, so verify through the company’s official app or website.
Let’s connect the dots
See the human risk.
Change what happens next.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo