Glossary

Smishing

Smishing is phishing by text message: a fraudulent SMS that lures people into clicking a link, sharing a code or calling a number. How it works, the numbers, and how businesses reduce it.

Last updated

A cell tower sends signal to a SIM card; the line type is identified as mobile rather than landline or VoIP.A cell tower sends signal to a SIM card; the line type is identified as mobile rather than landline or VoIP.

Smishing is phishing by SMS: a fraudulent text message that pretends to come from a trusted organisation to trick the recipient into clicking a link, entering credentials, sharing a one-time password, paying a fake fee or calling a scam number. The name combines "SMS" and "phishing". The same scams now arrive through messaging apps and RCS as well.

How does smishing work?

A typical smishing message has three parts:

  1. A trusted disguise. A spoofed or look-alike sender ID, or a message that lands in the same thread as genuine texts from that brand.
  2. A pretext with urgency. The FTC lists common lures: fake package-delivery notices, "suspicious activity" on an account, prizes and gift cards, credit-card or student-loan offers, and fake invoices (FTC).
  3. A call to action. A link to a copy of the real login page, a request to reply with a code, or a number to call.

Criminals buy phishing kits and bulk-send through compromised accounts, SIM farms or cheap routes. When they get a live password and one-time code, they sign in straight away, before the code expires.

How big is the problem?

The FBI's Internet Crime Complaint Center groups these scams under phishing/spoofing: "the use of unsolicited email, text messages, and telephone calls purportedly from a legitimate company requesting personal, financial, and/or login credentials". In 2025 it was again the most-reported crime type, with 191,561 complaints and reported losses of $215.8 million (IC3 2025 Annual Report). Reported losses understate the damage, because a phished login often shows up later as account takeover or payment fraud.

Why does it matter for businesses?

  • Your brand is the bait. Smishers copy the businesses customers trust. Every customer they fool costs support time, refunds and reputation.
  • OTP theft. Codes are the target in real-time phishing. A customer who types a code into a fake page hands over the account. This is one reason passkeys are replacing SMS codes for sign-in.
  • Deliverability. Operators and platforms filter aggressively against smishing. Legitimate business traffic that looks similar, with shortened links, changing sender IDs or unregistered headers, is filtered too.

How can you reduce smishing risk?

  1. Register and keep one sender ID in every country that supports registries. See sender ID.
  2. Never ask for codes, passwords or payments by text. Say so in your messages, and in the code message itself.
  3. Use full, recognisable domains in links, not URL shorteners.
  4. Protect the account, not just the login. Add checks when a phone number or e-mail is changed, because smishers follow a phished login with a contact change. See account security.
  5. Help customers report. In the US, forwarding to 7726 (SPAM) helps operators block similar messages.

How does MobileValidate help?

MobileValidate doesn't filter messages. It adds evidence about the numbers involved: line type and carrier for numbers that call or text your customers or appear in a support contact, and spam reputation, which reports whether a number appears in regulator actions, government complaint data or community reports. Spam reputation is in limited access and covers US, CA and DE numbers only. See the phone-number fraud signals field guide.

Frequently asked questions

What is smishing?

Smishing, short for SMS phishing, is a scam text message that pretends to come from a trusted organisation, such as a bank, courier or government agency, to get the recipient to click a link, give up a password or one-time code, or call a fraudulent number.

How do I report a smishing text?

In the US, forward the message to 7726 (SPAM) so your wireless provider can block similar messages, and report it to the FTC. Other countries run similar short-code or online reporting services.

How can a business protect its customers from smishing?

Use one consistent, registered sender identity, never ask for codes or passwords by text, tell customers what your genuine messages look like, and require phishing-resistant sign-in such as passkeys so stolen codes are worth less.