Back to Learning Hub

What Is Smishing? SMS, WhatsApp, and Mobile Phishing Explained

Last updated: 2026-08-133 min read

Smishing is phishing delivered through text messages. Learn how SMS attacks work, why they bypass email defences, and how to train employees to spot them.

Smishing is phishing by text message — "SMS" plus "phishing". The pretexts are familiar from email — fake delivery alerts, account warnings, impersonated authority — but the channel changes the behavior around them.

Reported US smishing losses exceeded 470 million dollars in a recent year, per FBI Internet Crime Complaint Center data — an understatement, since most incidents go unreported. It works not because it is sophisticated, but because the phone is a high-trust device most organizations never trained anyone to defend.


Why it slips past email defences

Enterprise email has two decades of gateways, scanning, and quarantine behind it. SMS has almost none of that: carrier filtering is less mature, there is nothing to scan in short plain text, and shortened URLs hide the destination until the tap. Most organizations have no mobile "report phishing" button either, so employees who do spot an attempt have nowhere to send it.

Behavior compounds it. Texts are read at a glance, mid-task, and carry few signals for judging legitimacy — no sender domain, no header, no signature — on a device whose trust default is high.

Common tactics

  • Fake delivery alerts. "Package held, confirm your address within 2 hours."
  • Verification-code phishing. A text primes you, then a "fraud team" call extracts the real code.
  • Tax and government impersonation. IRS, HMRC, or regional authorities, trading on fear of penalties.
  • Payroll and HR pretexts. Salary reconfirmation or benefits deadlines — everyone has these touchpoints.
  • MFA fatigue. A text asking you to approve an unexpected push, alongside genuine prompts.
  • Executive impersonation. "Hi, this is the CEO — are you free?", escalating into a transfer request.

Smishing vs. WhatsApp phishing

Strictly, smishing means SMS phishing. WhatsApp, Telegram, and Signal attacks run the same playbook over different infrastructure: SMS unencrypted and carrier-routed, WhatsApp end-to-end encrypted through Meta. The split is regional too: SMS still carries business notifications in North America and Europe, while WhatsApp dominates the Gulf and much of Asia, making it the larger attack surface there. The defense is identical either way.

Red flags

An unknown number that knows your name. Urgency out of proportion to the request. Shortened or mismatched URLs. A "bank" texting from a personal mobile. Any request — wire transfer, credential change, gift card, tax data — that bypasses normal process.

Building the defense

Technical controls catch some of it, but recognition is the durable layer: show employees real pretexts in advance, drill the verification habit ("call a number you already have, not the one in the message"), and give them somewhere to report. Vishing and smishing simulation training covers structuring mobile-channel programs.

Where PhishSkill stands today

PhishSkill runs simulations on email and WhatsApp. SMS-channel simulation is not live. Smishing and vishing recognition are covered in the awareness training modules, so employees learn the patterns on channels we do not yet simulate. If SMS simulation is a near-term requirement, start there and layer simulation when it arrives.


Related Learning

Related PhishSkill Capabilities

Ready to stop phishing attacks?

Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.