Skip to content

Smishing: SMS Phishing Attacks and How to Defend

What smishing is, why SMS phishing bypasses email defences and works so well on phones, the common attack types, and how to test and defend against it.

Invadel TeamAugust 27, 20265 min read

Smishing is phishing delivered by text message , SMS phishing. The name is a contraction of “SMS” and “phishing,” and the technique is exactly what it sounds like: a fraudulent text designed to make you tap a link, call a number, or hand over information. It has grown fast for a simple reason , people trust and act on texts far more readily than emails, and almost none of the defences that guard the inbox exist on the messaging app.

Why SMS works better for attackers than email

The channel does most of the work:

No filtering. Corporate email has years of layered defence. SMS arrives essentially raw , there is no enterprise spam filter, no link rewriting, no attachment sandbox sitting between the attacker and the screen. The message simply appears.

Higher trust and urgency. Texts are personal. They come from friends, family, delivery drivers, your bank’s fraud line. People open nearly every text within minutes, and they act on them quickly , which is precisely the reflex an attacker wants.

The small screen hides the tells. The clues that expose a phishing email , the full sender address, the real URL on hover , are hidden or absent on a phone. A shortened or lookalike link is hard to inspect, and mobile browsers show little of the address. The medium removes the evidence.

Blurred work and personal boundaries. People read work and personal texts on the same device, in the same relaxed frame of mind, often while distracted. A work-targeted smish lands in that unguarded context.

The common smishing attacks

Most smishing falls into a few reliable patterns:

  • Package delivery , “Your parcel is held, confirm your details here.” Ubiquitous because almost everyone is expecting something, and the timing often lands.
  • Bank and payment fraud alerts , “Suspicious transaction detected, verify now.” Manufactured urgency around money, driving a tap before thought.
  • Account and MFA lures , a fake “verify your account” text, or one prompting for a code, aimed at harvesting credentials or a one-time passcode.
  • Boss / executive texts , “Hi, it’s the CEO, I’m in a meeting and need you to sort something urgently.” The SMS cousin of business email compromise, often opening with a request for gift cards or a transfer.
  • Government and tax , impersonating a tax authority or agency with a threat or a refund.

The through-line is a trusted sender, a manufactured reason to act now, and a link or number that leads somewhere the attacker controls.

Smishing in a corporate breach

It is tempting to file smishing under personal fraud, but it is a genuine enterprise threat. Employees use phones for work , email, MFA, chat, VPN. A smish that harvests corporate credentials or an MFA code through a convincing fake login page is a direct route into the organisation, and it arrives on a device your email gateway never sees. The executive-impersonation variant targets finance staff for transfers exactly as email BEC does. Any assessment of your human attack surface that stops at email is missing the channel sitting in every employee’s pocket.

How smishing is tested

Controlled SMS campaigns are part of social engineering penetration testing, run alongside email and voice for full coverage of the human attack surface. With authorisation, testers send realistic smishing messages to agreed participants and measure who taps, who submits information on the landing page, and who reports it. Because it exercises a channel most organisations have never tested, smishing assessments frequently reveal that staff who are cautious with email are markedly less guarded over text , a gap you can only find by testing all three channels together.

How to defend against it

Smishing is countered with training, technical controls, and process:

  • Phishing-resistant MFA , FIDO2 keys and passkeys defeat the credential-and-code harvesting that most smishing aims for. The strongest single control.
  • Awareness that explicitly covers SMS , staff need to know texts are an attack channel, that delivery and bank alerts are prime lures, and that a link in a text deserves the same suspicion as one in an email. Most training never mentions it.
  • A verification habit , never act on an unexpected text through its link or number. Open the official app, or call the organisation on a known number. For any “boss” request, verify out of band.
  • Reporting that includes texts , give employees an easy way to report a suspicious SMS, and make clear it is welcomed. You cannot respond to what no one reports.
  • Mobile device management , on corporate devices, MDM and mobile threat defence can block known malicious sites and add a filtering layer SMS otherwise lacks.

The short version

Smishing works because SMS is the channel with the least protection and the most trust: no enterprise filter, a small screen that hides the warning signs, and a reader primed to act fast. It is a real corporate threat , employees carry work credentials and MFA on the same phones , not merely personal fraud. The defences are phishing-resistant MFA, awareness training that actually names SMS as an attack vector, an out-of-band verification habit, and easy reporting. And since staff cautious with email are often careless over text, testing all three channels together is the only way to see the whole picture.

Want to know how your team responds across email, voice, and text? A multi-channel social engineering assessment tests all three together. Scope one here.

Written by

Invadel Team

Senior penetration testers writing from real engagements — the same team that scopes, tests, and reports for our clients. About Invadel →

All articlesRed Teaming

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire?
Start the conversation