Mastodon Mastodon Mastodon Mastodon

Smishing

Updated: · CyberSecureFox Editorial Team

Smishing (SMS phishing) is phishing carried out through text messages and messaging apps, luring victims to fake websites or tricking them into sharing codes and payment details.

How smishing works

The attacker sends a short, urgent message with a link: a parcel cannot be delivered, a toll or parking fine is unpaid, a bank card has been blocked, a tax refund is waiting. The link leads to a convincing copy of a courier, bank or government website that asks for card details, login credentials or a one-time password. Sender names are often spoofed, and messages may come through iMessage, RCS or WhatsApp to bypass carrier spam filters.

Large criminal groups use “smishing kits” and SIM farms to send millions of messages. Since 2024, waves of fake “unpaid toll” texts have targeted drivers in the US, prompting warnings from the FBI and toll operators.

Why smishing works

People read texts almost instantly, trust messages that look like they come from known services, and see only a shortened URL on a small screen. Mobile browsers make it harder to check the real domain. Like other forms of phishing, smishing relies on social engineering rather than technical exploits.

How to protect yourself

  • Do not tap links in unexpected messages; open the official app or type the address yourself.
  • Never send one-time codes to anyone – a real bank or courier will not ask for them.
  • Report suspicious texts to your mobile operator (7726 in the US and UK) and delete them.
  • Use phishing-resistant authentication such as passkeys instead of SMS codes where possible.
Synonyms:
SMS phishing