Smishing is phishing delivered by text message or a messaging app, where a lure like a failed delivery or a bank alert carries a malicious link. It works because a text feels personal and urgent, and a short link hides where it really goes, so people tap before they think.
What is smishing, in plain English?
Smishing is SMS phishing. Instead of an email, the bait arrives as a text or a message on WhatsApp, iMessage, or RCS. The message poses as someone you would act on without much thought: a courier holding a parcel, your bank flagging a charge, a toll road chasing an unpaid fee, or a tax office promising a refund. It carries a short link that leads to a fake login page or a payment form built to harvest what you type.
The technique leans on two things phones make easy. First, a text feels more personal and immediate than email, so the click rate is much higher. Second, sender IDs are easy to spoof, so a message can drop straight into the same thread as your bank's real alerts. Some smishing also pushes an app install or a profile that plants malware or steals one-time codes.
In the fraud stack, smishing is a delivery channel for phishing, sitting alongside voice phishing and QR-code phishing. It is usually the first step in a longer chain that ends in account takeover, an authorized payment, or a drained card.
How a smishing attack unfolds
- Bait — Send the lure at scale. A blast of texts spoofs a courier, bank, or agency, each with a short link and an urgent hook.
- Click — Victim taps the link. The short URL hides the real destination and opens a convincing fake page on the small phone screen.
- Harvest — Collect credentials or a code. The page captures the login, card, or one-time password, sometimes in real time as the victim enters it.
- Cash out — Use the access fast. The attacker logs in, changes contact details, and moves money before the victim realizes anything happened.
- Lower harm — Blocked at login. Device and behavior signals flag the new login and force a real step-up the attacker cannot pass.
- Higher harm — Live code relay. A one-time code entered on the fake page is replayed instantly, and the account is taken over.
Who is involved?
Who | Their role |
The sender | Runs the blast, often through a phishing kit rented as a service, and controls the fake landing pages. |
The spoofed brand | A courier, bank, or agency whose name and sender ID are faked to borrow trust. |
The victim | The phone user who taps the link and enters credentials, card details, or a one-time code. |
The bank or platform | Sees the takeover or payment that follows and is often the only party positioned to stop the cash-out. |
What it looks like in practice
In practice
A customer gets a text saying a parcel could not be delivered and a small redelivery fee is due, with a link. The page looks like the courier, asks for card details to pay the fee, then asks for the one-time code the bank just sent to confirm the card.
Minutes later the same card is added to a mobile wallet on a device the customer has never used, and a string of contactless charges begins in another city. The redelivery fee was never the point; it was cover to capture the card and the code in one sitting.
Why it matters to operators
Smishing converts fast and leaves little trace. There is no email gateway to filter the message, the link is short so the customer cannot see the real domain, and the whole exchange happens on a phone where warning signs are easy to miss. By the time a complaint arrives, the credential or code is already used.
That means your best leverage is downstream of the click. Signals like a new device, a wallet provisioning attempt right after login, or a contact-detail change followed by a payout are where smishing becomes visible. Treat a one-time code entered moments before a sensitive action as suspect, not as proof the customer is present.
What to watch for
- Code then change. A one-time code used, immediately followed by a new device, wallet add, or contact-detail edit.
- Fresh device, old account. A seasoned account suddenly logging in from a device and location it has never seen.
- Short-link lures. Customer reports of texts with shortened URLs claiming a delivery, toll, or refund issue.
- Speed of the chain. Login, detail change, and payout compressed into a few minutes points to a live relay, not a real user.
- Clusters by template. Many customers hitting the same fake domain in a short window signals an active campaign to escalate on.
Quick questions
How is smishing different from phishing?
It is the same trick delivered by text instead of email. The mechanics of a fake page and stolen credentials are identical, but SMS gets higher click rates and skips email security filters.
Why are short links such a problem?
On a phone the customer cannot easily see where a shortened URL leads, so a fake bank page looks the same as a real one. The link also lets attackers rotate destinations to dodge blocklists.
Can attackers really put a text in my bank's thread?
Yes. Sender IDs and alphanumeric sender names are spoofable in many regions, so a smishing message can appear in the same conversation as legitimate alerts, which makes it look trusted.
Does MFA stop smishing?
Not on its own if the code is a one-time password the customer can be tricked into typing on a fake page. Phishing-resistant methods like passkeys help because there is no code to relay.
What should a team do when a campaign is spotted?
Cluster customers hitting the same fake domain, watch those accounts for post-login changes, force step-up on new-device sessions, and share the domain for takedown and blocklisting.
Is quishing the same thing?
Close. Quishing uses a QR code as the lure instead of a link in text, but the goal, a fake page that harvests credentials, is the same.
Go deeper
- FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
- FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

