Glossary
Smishing
Smishing is phishing via text message. 'Your package is delayed - click here.' 'Your bank account is locked - verify now.' These texts look urgent and legitimate but lead to fake websites that steal your info. They work because people trust texts more than emails.
What is Smishing?
SMS phishing - social engineering attacks conducted via text messages to trick victims into clicking malicious links or revealing sensitive information.
Why Should You Care?
Smishing is often more effective than email phishing because it bypasses email security controls and reaches personal mobile devices where skepticism is lower. Attackers use smishing to steal employee credentials and gain organizational access, and SMS lacks the standardized authentication, filtering, and enterprise gateways that protect corporate email. This makes mobile-targeted social engineering difficult for organizations to defend against.
Is your business exposed?
Real-World Example
In August 2022, attackers sent current and former Twilio employees SMS messages impersonating the company's IT department, directing them to fake login pages mimicking Twilio and Okta. Employees who entered their credentials unknowingly handed attackers access to internal systems; Twilio disclosed that the breach affected a limited number of its customers, and the same broader campaign was later linked to the exposure of phone numbers and SMS codes for Signal users. The incident shows how a single convincing text can lead to a multi-organization compromise.
How to Protect Against Smishing
- 1.
Never click links in unexpected text messages
- 2.
Go directly to official websites instead
- 3.
Report smishing texts to 7726 (SPAM)
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required