Avatier

Phished or stolen credentials

Smishing

Also called: SMS phishing

Smishing is phishing delivered by text message. The attacker sends an SMS or messaging-app text that poses as a bank, delivery company, toll agency or employer and pushes the reader to tap a link, call a number or reply with a code. The link usually leads to a fake login or payment page.

How it works

Attackers send the same short, urgent message to large lists of phone numbers, often warning of a fee, a missed delivery or a locked account. Phones show little of the real link, and people read texts quickly, so a convincing lookalike page can collect a password, card number or one-time code before the target notices anything wrong.

A real example

In April 2024 the FBI's Internet Crime Complaint Center said it had received over 2,000 complaints since early March about smishing texts that impersonated road toll collection services in at least three states.

Source: Smishing Scam Regarding Debt for Road Toll Services (I-041224-PSA) — FBI Internet Crime Complaint Center (IC3), 2024-04-12

The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Phishing-resistant MFA, such as passkeys or FIDO2 keys, stops a password typed into a fake page from being enough to sign in. Do not use SMS codes as the only second factor for work accounts.

Related terms

Threat actors that use it

Sources

  1. Smishing Scam Regarding Debt for Road Toll Services (I-041224-PSA) — FBI Internet Crime Complaint Center (IC3), 2024-04-12

Last reviewed Oct 2, 2026