Glossary
What is smishing?
Smishing (SMS phishing) is a phishing attack sent by text message.
- Also known as
- SMS phishing, text message scam
- Channel
- SMS text messages
- Typical goal
- Credentials, card details, one-time codes, payments
- Related term
- RCS phishing
How it works
Short message,
short link, quick tap.
- 01
Spoof a sender
The text appears to come from a bank, courier, tax office or employer, sometimes in the same thread as real messages.
- 02
Keep it short
A brief alert about a parcel, a blocked account or a refund leaves little room for doubt.
- 03
Push to act
A shortened link or phone number, plus a deadline.
- 04
Harvest
A mobile-friendly fake page collects logins, card details or codes.
Simulated examples
Two texts that
want a tap.
VM-ACCTUPD
KYC update pending
Dear customer, your account will be blocked today. Update KYC: kyc-update-now.example
- Threat of account block
- Generic greeting
- Link instead of the bank’s app
Questions buyers ask
Frequently asked questions.
What does smishing stand for?
Smishing combines “SMS” and “phishing”. It means phishing delivered by text message.
Can I get hacked just by opening a text?
Opening a text is generally low risk. The danger comes from tapping links, calling numbers or replying with information.
How do I report a smishing text at work?
Use your organisation’s reporting process or tell your security team, with a screenshot if possible. Don’t tap the link or reply.
Let’s connect the dots
See the human risk.
Change what happens next.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo