Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is smishing?

Smishing is phishing delivered through SMS or another text-message service.

The aim is usually to make the recipient click, call, reply, pay, install something or disclose information.

The message is only the first stage

A smishing message might say:

Royal Mail: your parcel is awaiting a £1.45 redelivery payment.

The useful evidence may include:

Example smishing message
Received: 2026-09-14 10:22 UTCSender display: Royal MailLink: https://parcel-redelivery.exampleThread: existing delivery notifications

That fixes the representation, time and link.

Sender display is not sender identity

Text-message sender names and numbers may be:

  • spoofed;
  • manipulated;
  • routed through internet messaging services;
  • inserted into an existing message thread;
  • sent from a compromised legitimate account or device.

So the display alone should not be treated as proof of who sent it.

Follow the recipient action

If the recipient interacted, the next evidence may sit in:

  • browser history;
  • DNS/proxy records;
  • page requests;
  • downloads;
  • call records;
  • app installations;
  • authentication records;
  • payment activity.
MessageWhat was sent?Text, claimed sender, link or call-back number.
InteractionWhat did the recipient do?Click, call, reply, install or pay.
OutcomeWhat happened next?Credential use, app activity, payment or account change.

Preserve the native message where possible

Keep:

  • full message text;
  • sender display/number;
  • timestamp;
  • thread context;
  • exact URL;
  • screenshots as supporting views;
  • device and provider records where relevant.

Shortened links and redirects may need safe technical analysis before you know the final destination.

The practical point is: smishing is text-delivered phishing. Separate apparent sender, delivery, recipient action and resulting harm rather than treating the message itself as the whole incident.

Reference: CIM-032Cyber Incidents & Offender Methods