Smishing
Also called: SMS phishing
Smishing is phishing delivered by text message. The attacker sends an SMS or messaging-app text that poses as a bank, delivery company, toll agency or employer and pushes the reader to tap a link, call a number or reply with a code. The link usually leads to a fake login or payment page.
How it works
Attackers send the same short, urgent message to large lists of phone numbers, often warning of a fee, a missed delivery or a locked account. Phones show little of the real link, and people read texts quickly, so a convincing lookalike page can collect a password, card number or one-time code before the target notices anything wrong.
A real example
In April 2024 the FBI's Internet Crime Complaint Center said it had received over 2,000 complaints since early March about smishing texts that impersonated road toll collection services in at least three states.
Source: Smishing Scam Regarding Debt for Road Toll Services (I-041224-PSA) — FBI Internet Crime Complaint Center (IC3), 2024-04-12
The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Phishing-resistant MFA, such as passkeys or FIDO2 keys, stops a password typed into a fake page from being enough to sign in. Do not use SMS codes as the only second factor for work accounts.
Related terms
Threat actors that use it
- ALPHV Blackcat
Profile with government sources
- Scattered Spider
Profile with government sources
Sources
- Smishing Scam Regarding Debt for Road Toll Services (I-041224-PSA) — FBI Internet Crime Complaint Center (IC3), 2024-04-12
Last reviewed Oct 2, 2026