What is smishing?¶
Smishing is phishing delivered through SMS, multimedia messaging or another text-message service.
Avoid the dangerous assumption¶
The dangerous assumption is that a message showing a familiar sender name or telephone number came from that organisation or person.
Sender information can be spoofed, manipulated or presented within an existing message thread. A message may also come from a compromised legitimate account or device.
Smishing messages commonly try to create urgency.
They may claim that:
- a payment is due
- a parcel is waiting
- an account will be suspended
- a security issue must be resolved
- a fine or refund requires action
- a family member needs help
- the recipient must confirm personal details.
The requested action may be clicking a link, calling a number, replying, installing an application, making a payment or entering credentials.
Preserve the message as received. Record the sender display, number, timestamp, full text, links and any conversation history. Where possible, retain device and provider records rather than relying only on screenshots.
Check what happened next.
Was the link opened?
Was a website loaded?
Was information entered?
Was an application installed?
Was a call made?
Was money transferred?
Did the recipient receive later authentication alerts?
The message itself may show the representation and delivery method. It does not prove that the displayed sender controlled the sending infrastructure or that the recipient acted upon it.
Smishing campaigns may use shortened links, disposable domains, compromised websites or legitimate services abused for redirection.
Cross-link the communication evidence with device, browser, account, provider and payment records.
Operational takeaway¶
Preserve the original text message and associated device activity, and distinguish the displayed sender, delivery, user interaction and resulting harm.