Smishing (SMS Phishing)
What it is
Short text messages that impersonate a bank, delivery service, toll authority, or employer and push the recipient to tap a link or reply with information.
How it works
Real-world examples
- •The "USPS: your package is held" text linking to a lookalike tracking page that requests a small redelivery fee, harvesting the card details entered.
- •The 2022 "0ktapus" campaign sent employees of Twilio, Cloudflare, and more than 100 other companies texts posing as IT, linking to cloned Okta login pages that captured passwords and one-time codes; Cloudflare reported that its hardware security keys stopped the attack.
- •Waves of "unpaid toll" texts impersonating E-ZPass and state toll authorities spread across the United States in 2024 and 2025, prompting FBI and FTC warnings.
- •A "wrong number" text that turns friendly ("sorry, who is this?") is frequently the opening of a pig-butchering scam rather than a mistake.
Ethical guidelines
- ●Sending deceptive texts to obtain money or data is fraud and breaches carrier rules and consumer-protection law.
- ●Authorized smishing simulations should be rare, disclosed in policy, and never mimic personal emergencies or payroll.
- ●Businesses that text customers should never include links to log in or pay, so that a link in a text becomes a reliable warning sign.
How to defend against it
- ►Do not tap links in unexpected texts. Open the carrier's or bank's app or type the address yourself; a real delivery problem will show up on the official tracking page.
- ►Look at the sending number: legitimate alerts come from short codes or numbers you have saved, while scam texts usually come from ordinary ten-digit or foreign numbers, though neither is proof.
- ►Forward scam texts to 7726 (SPAM) on U.S. carriers and report at reportfraud.ftc.gov; the reports feed carrier blocking.
- ►Use phishing-resistant MFA where available; a counterfeit page can relay a texted code but cannot complete a passkey or security-key login.
- ►Ignore "wrong number" texts entirely; replying confirms a live, responsive number and starts a longer game.
From the Defense Playbook
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.
Treat any demand to pay a debt, fine, fee, bail, or "security deposit" with gift cards, cryptocurrency, a wire to a stranger, a payment app, or cash handed to a courier as proof of fraud, because no legitimate institution collects money that way.
Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Fletcher, E. (Federal Trade Commission) (2023). IYKYK: The top text scams of 2022. FTC Consumer Protection Data Spotlight, June 2023 · linkAbout 330 million dollars in reported text-scam losses in 2022; bank impersonation, fake gifts, and package-delivery lures as the top text scams.
- Federal Trade Commission (2023). Consumer Sentinel Network Data Book 2022. Federal Trade Commission · linkText messages as the most reported contact method for fraud in 2022.
- Ferreira, A., Coventry, L., & Lenzini, G. (2015). Principles of Persuasion in Social Engineering and Their Use in Phishing. Human Aspects of Information Security, Privacy, and Trust (HAS 2015), Lecture Notes in Computer Science 9190, Springer, 36-47 · linkContent analysis showing which persuasion principles (authority, scarcity, liking) phishing messages combine.
Related Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.