SMS phishing - Smishing
Smishing is phishing over SMS or messaging apps. The attacker sends a short message with a link, a request to confirm something, or an instruction for an urgent action, counting on messages being read quickly on a phone and without much checking.
Term
description · examples · notesSmishing is phishing over SMS or messaging apps. The attacker sends a short message with a link, a request to confirm something, or an instruction for an urgent action, counting on messages being read quickly on a phone and without much checking.
Description
The impersonation is usually a bank, a courier, a government service, a payment platform or a well-known app. The message offers a simple reason to click: the parcel cannot be delivered, the account is blocked, a transaction looks suspicious, a package is waiting on a small charge. Everything is reduced to a few words and one link.
Smishing works well because it happens on the device where the user already receives codes, confirms payments and feels they are handling small daily matters. If the victim enters details on a fake page or installs an app from outside the official store, the attacker gets credentials, payment details or access to the phone.
Examples
- An SMS about an undelivered parcel leads to a fake courier page, where a small charge and card details are requested.
- A message from a supposed bank warns of a suspicious transaction and asks for an urgent account check through a link.
- A false prize notification leads to a page that asks for an account login or the installation of an app from outside the official store.
Notes
- A link in an unexpected SMS is not the start of a check but the reason for one. The service is opened by hand, through the official app or a known address.
- A small extra charge for a parcel is often the bait. The amount is deliberately low so that card details are entered more readily.
Mentioned in the news
- 4. JUL 2026. Lažne saobraćajne kazne, navodno od Puteva Srbije, vode do krađe platnih kartica →
- 28. APR 2026. Kineskojezične PhaaS platforme šire krađu kredencijala preko SMS poruka →
- 28. APR 2026. Kanada uhapsila trojicu zbog SMS blaster phishing uređaja →
- 24. APR 2026. Rast smishing napada u Srbiji kroz lažnu eUprava kampanju →
- 20. APR 2026. Britanac priznao smishing napade i krađu miliona dolara u kriptovalutama →
Techniques
carried out with 3Techniques used to carry it out. Select one to open its page.
Defenses
countered by 4How it is defended against. Select one to open its page.