Glossary

What is smishing?

Smishing (SMS phishing) is a phishing attack sent by text message.

Also known as
SMS phishing, text message scam
Channel
SMS text messages
Typical goal
Credentials, card details, one-time codes, payments
Related term
RCS phishing

How it works

Short message,
short link, quick tap.

  1. 01

    Spoof a sender

    The text appears to come from a bank, courier, tax office or employer, sometimes in the same thread as real messages.

  2. 02

    Keep it short

    A brief alert about a parcel, a blocked account or a refund leaves little room for doubt.

  3. 03

    Push to act

    A shortened link or phone number, plus a deadline.

  4. 04

    Harvest

    A mobile-friendly fake page collects logins, card details or codes.

Simulated examples

Two texts that
want a tap.

Simulated example
SMS08:47

VM-ACCTUPD

KYC update pending

Dear customer, your account will be blocked today. Update KYC: kyc-update-now.example

  • Threat of account block
  • Generic greeting
  • Link instead of the bank’s app

Questions buyers ask

Frequently asked questions.

What does smishing stand for?

Smishing combines “SMS” and “phishing”. It means phishing delivered by text message.

Can I get hacked just by opening a text?

Opening a text is generally low risk. The danger comes from tapping links, calling numbers or replying with information.

How do I report a smishing text at work?

Use your organisation’s reporting process or tell your security team, with a screenshot if possible. Don’t tap the link or reply.

Let’s connect the dots

See the human risk.
Change what happens next.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo