Smishing is phishing delivered through text messages. Learn how SMS attacks work, why they bypass email defences, and how to train employees to spot them.
Smishing is phishing by text message — "SMS" plus "phishing". The pretexts are familiar from email — fake delivery alerts, account warnings, impersonated authority — but the channel changes the behavior around them.
Reported US smishing losses exceeded 470 million dollars in a recent year, per FBI Internet Crime Complaint Center data — an understatement, since most incidents go unreported. It works not because it is sophisticated, but because the phone is a high-trust device most organizations never trained anyone to defend.
Why it slips past email defences
Enterprise email has two decades of gateways, scanning, and quarantine behind it. SMS has almost none of that: carrier filtering is less mature, there is nothing to scan in short plain text, and shortened URLs hide the destination until the tap. Most organizations have no mobile "report phishing" button either, so employees who do spot an attempt have nowhere to send it.
Behavior compounds it. Texts are read at a glance, mid-task, and carry few signals for judging legitimacy — no sender domain, no header, no signature — on a device whose trust default is high.
Common tactics
- Fake delivery alerts. "Package held, confirm your address within 2 hours."
- Verification-code phishing. A text primes you, then a "fraud team" call extracts the real code.
- Tax and government impersonation. IRS, HMRC, or regional authorities, trading on fear of penalties.
- Payroll and HR pretexts. Salary reconfirmation or benefits deadlines — everyone has these touchpoints.
- MFA fatigue. A text asking you to approve an unexpected push, alongside genuine prompts.
- Executive impersonation. "Hi, this is the CEO — are you free?", escalating into a transfer request.
Smishing vs. WhatsApp phishing
Strictly, smishing means SMS phishing. WhatsApp, Telegram, and Signal attacks run the same playbook over different infrastructure: SMS unencrypted and carrier-routed, WhatsApp end-to-end encrypted through Meta. The split is regional too: SMS still carries business notifications in North America and Europe, while WhatsApp dominates the Gulf and much of Asia, making it the larger attack surface there. The defense is identical either way.
Red flags
An unknown number that knows your name. Urgency out of proportion to the request. Shortened or mismatched URLs. A "bank" texting from a personal mobile. Any request — wire transfer, credential change, gift card, tax data — that bypasses normal process.
Building the defense
Technical controls catch some of it, but recognition is the durable layer: show employees real pretexts in advance, drill the verification habit ("call a number you already have, not the one in the message"), and give them somewhere to report. Vishing and smishing simulation training covers structuring mobile-channel programs.
Where PhishSkill stands today
PhishSkill runs simulations on email and WhatsApp. SMS-channel simulation is not live. Smishing and vishing recognition are covered in the awareness training modules, so employees learn the patterns on channels we do not yet simulate. If SMS simulation is a near-term requirement, start there and layer simulation when it arrives.
Related Learning
- What Is Phishing?
- What Is Social Engineering?
- What Is Spear Phishing?
- What Is a Phishing Simulation?
- Vishing and Smishing Simulation Training
Related PhishSkill Capabilities
- WhatsApp Phishing Awareness Training — the WhatsApp channel implementation with admin-controlled enrolment
- AI-Powered Phishing Awareness Training — context-aware template generation for the channels we simulate today
More Learning Resources
View all learning resourcesHow to Run a Phishing Simulation
A practical guide to running a phishing simulation — scoping it, choosing a fair pretext, teaching at the click, and reading the numbers after.
Phishing Email Examples
Seven phishing emails your team will actually receive, what makes each one work, and the two habits that catch them all.
Quick Guide: Deepfake Phishing
Deepfake phishing uses AI-cloned voices and video to impersonate executives. Learn how it works and the verification habits that stop it.
Ready to stop phishing attacks?
Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.