Social Engineering & FraudMANIPULATIVE

Smishing (SMS Phishing)

What it is

Short text messages that impersonate a bank, delivery service, toll authority, or employer and push the recipient to tap a link or reply with information.

How it works

Text messages arrive on the device people trust most and read fastest, with almost none of the inspection cues available in email: no visible sender domain, no hover-to-preview, shortened links, and a small screen on which a counterfeit page looks like the real app. Smishing lures are short by necessity, so they lean on the most reliable triggers: a package that could not be delivered, a bank alert about a charge you did not make, an unpaid toll, a job offer. The message asks for one small act (tap, confirm, pay a two-dollar fee) whose real purpose is to capture card numbers or login codes. Volume is enormous because sending is cheap and phone numbers are easy to enumerate. The FTC reported that text-message scam losses reached about 330 million dollars in 2022, more than double the prior year, with fake bank fraud-prevention alerts the most common lure; text messages were also the single most reported contact method for fraud that year.

Real-world examples

  • The "USPS: your package is held" text linking to a lookalike tracking page that requests a small redelivery fee, harvesting the card details entered.
  • The 2022 "0ktapus" campaign sent employees of Twilio, Cloudflare, and more than 100 other companies texts posing as IT, linking to cloned Okta login pages that captured passwords and one-time codes; Cloudflare reported that its hardware security keys stopped the attack.
  • Waves of "unpaid toll" texts impersonating E-ZPass and state toll authorities spread across the United States in 2024 and 2025, prompting FBI and FTC warnings.
  • A "wrong number" text that turns friendly ("sorry, who is this?") is frequently the opening of a pig-butchering scam rather than a mistake.

Ethical guidelines

  • Sending deceptive texts to obtain money or data is fraud and breaches carrier rules and consumer-protection law.
  • Authorized smishing simulations should be rare, disclosed in policy, and never mimic personal emergencies or payroll.
  • Businesses that text customers should never include links to log in or pay, so that a link in a text becomes a reliable warning sign.

How to defend against it

  • Do not tap links in unexpected texts. Open the carrier's or bank's app or type the address yourself; a real delivery problem will show up on the official tracking page.
  • Look at the sending number: legitimate alerts come from short codes or numbers you have saved, while scam texts usually come from ordinary ten-digit or foreign numbers, though neither is proof.
  • Forward scam texts to 7726 (SPAM) on U.S. carriers and report at reportfraud.ftc.gov; the reports feed carrier blocking.
  • Use phishing-resistant MFA where available; a counterfeit page can relay a texted code but cannot complete a passkey or security-key login.
  • Ignore "wrong number" texts entirely; replying confirms a live, responsive number and starts a longer game.

From the Defense Playbook

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Fletcher, E. (Federal Trade Commission) (2023). IYKYK: The top text scams of 2022. FTC Consumer Protection Data Spotlight, June 2023 · link
    About 330 million dollars in reported text-scam losses in 2022; bank impersonation, fake gifts, and package-delivery lures as the top text scams.
  2. Federal Trade Commission (2023). Consumer Sentinel Network Data Book 2022. Federal Trade Commission · link
    Text messages as the most reported contact method for fraud in 2022.
  3. Ferreira, A., Coventry, L., & Lenzini, G. (2015). Principles of Persuasion in Social Engineering and Their Use in Phishing. Human Aspects of Information Security, Privacy, and Trust (HAS 2015), Lecture Notes in Computer Science 9190, Springer, 36-47 · link
    Content analysis showing which persuasion principles (authority, scarcity, liking) phishing messages combine.
Last reviewed
Suggest a correction

Detect Smishing (SMS Phishing) in any text

Paste any message, email, or article into our free Manipulation Detector to see if Smishing (SMS Phishing) or other techniques are being used on you.

Related Articles