Overview Attack Chain Techniques Statistics Demo Prevention Legal Resources

Smishing Guide

What is Smishing?

Smishing (SMS phishing) is a type of social engineering attack where attackers use text messages (SMS) to trick victims into revealing sensitive information (bank account numbers, credit card details, login credentials) or installing malware. Attackers impersonate trusted entities (banks, delivery services, government agencies, tech support) using urgency tactics ("Your account has been locked", "Package delivery failed", "Tax refund pending"). Smishing attacks have increased dramatically due to widespread SMS usage and lower user suspicion compared to email.

Attack Prevalence: 85% of organizations experienced smishing attacks in 2023 (Proofpoint). 300% increase in smishing attacks since 2020. Average cost per smishing incident: $800,000 (data breach, financial fraud).

85%
Organizations Affected (2023)
300%
Increase Since 2020
$800K
Average Cost per Incident

Common smishing attack impersonations:

How Smishing Works (Attack Chain)

1. SMS Delivery

Attacker sends mass SMS messages using SMS gateways, spoofed sender IDs, or compromised phone numbers.

2. Impersonation

Message impersonates FedEx, bank, IRS, or tech support. "Your package delivery failed", "Account locked".

3. Malicious Link

Victim clicks shortened/obfuscated link (bit.ly, tinyurl, typosquatted domain).

4. Exploitation

Victim enters credentials on fake website (credential harvesting) or downloads malware (Android banking Trojan).

// Smishing SMS examples (malicious) Example 1: FedEx delivery scam "FedEx: Your package delivery failed. Please reschedule delivery: http://fedex-delivery.xyz" Example 2: Bank account locked "Chase Bank: Your account has been locked due to suspicious activity. Verify now: https://chase-verify.xyz" Example 3: IRS tax refund "IRS: You have a pending tax refund of $1,200. Claim now: http://irs-refund.xyz" Example 4: Amazon account alert "Amazon: Your account will be suspended. Update payment info: https://amazon-security.xyz"

Smishing Techniques & Social Engineering

Delivery Service Impersonation

Attacker impersonates FedEx, UPS, USPS, Amazon. "Package delivery failed", "Tracking update". Malicious link to credential harvesting site or malware download.

Most Common

Bank Impersonation

Attacker impersonates major banks (Chase, Bank of America, Wells Fargo). "Your account has been locked", "Unauthorized transaction detected". Malicious link to fake banking login page (credential harvesting).

IRS / Tax Scams

"You have a pending tax refund of $1,200", "Claim your stimulus payment". Malicious link to credential harvesting site (steals SSN, bank account).

Malware Distribution

SMS contains link to malicious APK (Android malware). Banking Trojans (Cerberus, EventBot, Anubis) steal banking credentials, intercept SMS 2FA codes.

Smishing Statistics

// Smishing statistics (Proofpoint, FTC, 2023) - 85% of organizations experienced smishing attacks (2023) - 300% increase in smishing attacks since 2020 - Average cost per smishing incident: $800,000 - 65% of smishing messages impersonate delivery services (FedEx, UPS, USPS) - 20% impersonate banks - 10% impersonate IRS/government - 5% impersonate tech support - 40% of smishing victims click malicious links (mobile devices) - 25% of victims enter credentials on fake websites - 15% of victims download malware (Android banking trojans) // Major smishing campaigns 1. FedEx Smishing (2022-2023): 5 million+ SMS messages 2. IRS Refund Scam (2023): $50 million stolen 3. Bank Account Locked (2021-2023): $100 million stolen

Smishing Attack Simulation (Delivery Scam)

This demonstration simulates a smishing attack where an attacker impersonates FedEx delivery service:

Click "Click the Link" to see smishing attack simulation

This is a simulated demonstration. Real smishing attacks can steal bank credentials, install malware (Android banking trojans), and cause financial fraud. Never click links in unsolicited SMS. Verify delivery status by visiting official website (type URL manually). Forward smishing attempts to 7726 (SPAM) - your mobile carrier will investigate. Enable MFA (App-based authenticator, not SMS) to prevent MFA bypass.

Preventing Smishing Attacks

Never Click Links in SMS

Never click links in unsolicited text messages. Verify delivery status by typing official website URL manually (fedex.com, usps.com, amazon.com). Do not use link from SMS.

Report Smishing (7726 - SPAM)

Forward smishing messages to 7726 (SPAM). Mobile carriers (AT&T, Verizon, T-Mobile) investigate and block malicious numbers. Report to FTC (ftc.gov/complaint).

Enable SMS Filtering

Enable carrier spam blocking (AT&T ActiveArmor, Verizon Call Filter, T-Mobile Scam Shield). Use third-party apps (Truecaller, RoboKiller) to filter smishing.

Use App-Based MFA (Not SMS)

SMS 2FA can be bypassed via smishing (malware intercepts SMS). Use app-based authenticator (Google Authenticator, Authy, Microsoft Authenticator) or hardware token (YubiKey).

Best Practice - Never Click Links in SMS: Never click links in unsolicited text messages. Verify delivery status by typing official website URL manually (fedex.com, usps.com, ups.com, amazon.com). Forward smishing attempts to 7726 (SPAM). Enable app-based MFA (not SMS 2FA). Report smishing to FTC (ftc.gov/complaint).

Further Resources

FTC Smishing Complaint (ftc.gov)

Report smishing to Federal Trade Commission (FTC).

7726 (SPAM) Reporting

Forward smishing messages to 7726 (SPAM) to report to mobile carrier (AT&T, Verizon, T-Mobile).

← Back to Knowledge Base