Smishing | What It Is, How It Works, and How to Protect Yourself

Knowledge Hub
Smishing

Smishing is a phishing scam carried out over text message, where an attacker poses as a trusted source, a bank, delivery service, or government agency, to trick you into clicking a malicious link or handing over personal information. The name is a blend of “SMS” and “phishing,” and it now ranks among the most common ways scammers reach consumers directly on their phones.

The scale of the problem is no longer marginal. According to the FTC, consumers lost $470 million to text message scams in 2024 alone, five times what was lost in 2020, and the trend has kept climbing into 2025 and 2026, fueled by fake toll notices, package-delivery alerts, and bank fraud warnings that feel routine enough to trust.

What makes Smishing effective isn’t sophistication; it’s familiarity. A text about an unpaid E-ZPass toll or a missed USPS delivery mimics something most people have actually experienced, which is exactly why it works well enough to sustain an entire criminal economy behind it. Understanding how these attacks are built, why they succeed, and how to spot one before you click is the fastest way to stop being an easy target.

What Is Smishing?

Smishing Definition

Smishing is a form of phishing attack delivered through SMS or text-based messaging apps, where a scammer impersonates a legitimate sender to manipulate someone into clicking a malicious link, downloading malware, or sharing sensitive information like login credentials or payment details. It relies on the same psychological tricks as email phishing: urgency, authority, and familiarity, but exploits the higher trust and immediacy people tend to give text messages over email.

That trust is exactly why the channel has grown so fast. Text messaging has now overtaken phone calls and email as scammers’ preferred way to reach consumers, according to the FTC, largely because people open texts faster and scrutinize them less.

Why It’s Called “Smishing” (SMS + Phishing)

The term smishing is a portmanteau of “SMS” (Short Message Service) and “phishing,” coined to describe phishing attacks that specifically use text messaging as the delivery method rather than email. The name reflects the mechanics, not a different kind of scam. Smishing is phishing, just moved to a channel with fewer spam filters and a smaller screen that makes fake links harder to inspect before tapping.

Smishing vs. Phishing vs. Vishing (Quick Comparison Table)

Smishing, phishing, and vishing are three delivery methods for the same underlying scam: impersonating a trusted party to steal information or money. What separates them is the channel the attacker uses to reach the victim.

Feature Smishing Phishing Vishing
Channel SMS / text messaging apps Email Phone calls / voicemail
Typical Hook Fake delivery, toll, or bank alert with a link Fake invoice, login alert, or attachment Fake IRS, bank, or tech-support call
Why It Works High open rates, low scrutiny, small screens hide fake URLs Familiar format, easy to spoof sender names Live voice adds urgency and false legitimacy
Common Defense Don’t click links from unknown numbers; verify via official app Spam filters, checking sender domain Hang up and call the organization back directly

These attack types are frequently combined in a single scam campaign, for example, a text message that directs the victim to call a phone number, blending Smishing and vishing into one attack chain. Recognizing which channel a message arrived through is the first step in deciding how much to trust it.

How Smishing Attacks Work

How Smishing Attacks Work

The Anatomy of a Smishing Text

A smishing text almost always follows the same basic structure: a message that looks like it’s from a real organization, paired with urgent language and a link designed to be tapped without much thought. Most scam texts share a handful of common markers: an unfamiliar or spoofed sender number, a sense of urgency (“your package is on hold,” “your account will be suspended”), a shortened or slightly misspelled link, and a request for personal or payment information once the victim lands on the fake page. None of these signs alone is proof of a scam, but a text carrying several of them at once almost always is.

Common Techniques and Pretexts

Smishing scams tend to borrow scenarios people already expect to encounter, which is what makes the fake version easy to mistake for the real thing. The most common pretexts include fake delivery notifications from carriers like USPS or Amazon, unpaid toll alerts impersonating agencies like E-ZPass or state DMVs, bank or payment-app fraud warnings from PayPal or Coinbase, and government impersonation texts claiming unpaid fines or benefit issues. The toll-scam pattern alone has become one of the most reported forms of Smishing: the FBI logged more than 60,000 complaints tied to fake unpaid-toll texts in 2024, spanning toll systems across nearly every state. A newer variant, CEO fraud smishing, targets employees directly, with a text posing as a company executive requesting a wire transfer, gift cards, or sensitive data, a technique that increasingly overlaps with vishing when the follow-up happens over a phone call instead of a reply text.

Why Smishing Attacks Are So Effective

Smishing succeeds because it exploits the built-in trust people place in text messages, not because the scams themselves are especially sophisticated. Texts get opened faster and read more casually than email, phone screens make it harder to inspect a link before tapping it, and most of the pretexts used- a toll bill, a missed delivery- mirror something the recipient has genuinely dealt with before. That combination of speed, plausibility, and reduced scrutiny is what turns a fairly simple message into a scam that a security-aware person might still click without a second thought.

Types of Smishing Scams (With Real Examples)

Types of Smishing Scams

Package & Delivery Scams (USPS, Amazon)

Package and delivery smishing scams impersonate shipping carriers or major retailers to tell recipients a delivery has failed, is on hold, or requires an address confirmation before it can be released. USPS has repeatedly warned customers about text messages claiming a package is stuck due to an “incomplete address,” directing recipients to a fake tracking page that harvests personal and payment information. Amazon-branded versions follow the same pattern, often timed around high-shipping periods like holidays, when a fake delivery alert is statistically more likely to match something the recipient is actually expecting.

Toll Road & EZ-Pass Scams

Toll road smishing scams claim the recipient owes money for unpaid tolls on a highway system such as E-ZPass, and link to a fake payment portal designed to capture card details. This has become one of the most widely reported smishing patterns in the U.S.: the FBI received more than 60,000 complaints about unpaid-toll text scams in 2024 alone, spanning toll agencies in nearly every state. The texts tend to use nearly identical wording regardless of which state or toll system they claim to be from, which is often the clearest sign the message is fraudulent rather than a genuine notice from a regional transportation authority.

Bank, PayPal & Coinbase Impersonation

Bank and payment-platform impersonation scams pose as a financial institution, PayPal, or a crypto exchange like Coinbase, warning of suspicious account activity or a login attempt that needs to be verified immediately. These messages are built to trigger a fast, anxious reaction; clicking through to “secure” an account feels much more urgent than checking a delivery status, which is why financial impersonation scams tend to convert at a higher rate than other pretexts. Because crypto transactions are irreversible once completed, Coinbase-style Smishing in particular is often paired with pressure to move funds quickly, cutting off the window a victim has to reconsider.

Government & DMV Impersonation

Government impersonation smishing poses as an agency, a state DMV, tax authority, or federal office, claiming the recipient owes a fine, has an unresolved benefits issue, or must confirm personal details to avoid penalties. This category has grown sharply: reported losses from government impersonation scams reached $797.9 million in 2025, nearly double the $405.6 million recorded the year before, according to FBI data. The pretext works because government communication already carries built-in authority and urgency, and most people don’t have a habit of independently verifying how a given agency actually contacts them.

CEO Fraud / Business Smishing

CEO fraud smishing targets employees directly with a text posing as a company executive, typically requesting an urgent wire transfer, gift card purchase, or sensitive internal data. Unlike consumer-facing Smishing, this version relies on organizational hierarchy rather than brand recognition; the message works because employees are conditioned to respond quickly to a request that appears to come from leadership, especially when it’s framed as time-sensitive or confidential. Business smishing attacks frequently escalate into a phone call once initial contact is made over text, blending Smishing with vishing to add a layer of live pressure that’s harder to resist than a message alone.

FBI Warnings and Recent Smishing Trends

Recent Smishing Trends

Latest FBI and FCC Alerts

The FBI and FCC have issued repeated public warnings about smishing campaigns targeting iPhone and Android users, most notably a wave of toll-payment and package-delivery texts that spread across all 50 states starting in early 2024. In 2025, the FBI issued a separate alert about a smishing campaign impersonating senior U.S. officials, in which attackers combined fraudulent text messages with AI-generated voice content and moved victims to a separate messaging platform to extract sensitive access. Regional FBI field offices have also flagged localized surges; Atlanta’s office, for example, reported a sharp spike in complaints tied to fake Peach Pass toll texts, with over 1,500 complaints logged in a single month. These alerts share a consistent message: Smishing is being treated as an active, evolving threat rather than a one-time scam wave.

2024–2026 Smishing Statistics

Smishing losses have grown every year since 2020, and the numbers reflect a threat that’s accelerating rather than leveling off. The FTC reported that consumers lost $470 million to text message scams in 2024, five times what was lost in 2020, while the FBI’s Internet Crime Complaint Center logged over 60,000 complaints tied to unpaid-toll smishing texts in that same year. Government impersonation scams, a category heavily driven by Smishing, saw reported losses nearly double year over year, climbing from $405.6 million in 2024 to $797.9 million in 2025. The FBI’s IC3 has flagged text-based phishing as a fast-growing threat in every annual Internet Crime Report since 2021, and complaint volume has continued climbing into 2026 with no sign of slowing.

AI and Deepfake-Enhanced Smishing/Vishing

A newer trend layers AI-generated voice and imagery on top of traditional Smishing, turning a single text into the opening move of a more elaborate scam rather than the whole attack. The FBI’s 2025 warning about impersonated senior officials described exactly this pattern: an initial smishing text used to build trust, followed by AI-generated voice messages that made the scam feel more convincing once the conversation moved to another platform. This blending of channels- text to open contact, AI-generated audio to sustain it- makes attacks harder to catch with tools built for a single format, and signals that smishing defenses built around static red flags like bad grammar or suspicious links may need to account for far more polished, convincing follow-through in the near future.

The Smishing Triad: Inside the Infrastructure Behind the Scams

Smishing Triad

How Stolen Phone Numbers End Up on the Dark Web

The near-identical wording behind so many toll and delivery scam texts isn’t a coincidence; much of it traces back to a single operation known as the Smishing Triad. This Chinese-speaking cybercrime group, researchers say, has generated more than $1 billion over the past three years by running large-scale SMS phishing campaigns. Rather than operating as a lone group of hackers, the Smishing Triad functions as a cybercrime-as-a-service provider: it builds phishing kits, then sells or leases them to other criminals through Dark Web marketplaces and Chinese-language Telegram channels. The personal data harvested through these campaigns- names, addresses, card numbers, one-time passcodes- is routinely resold on darknet forums, feeding directly back into future Smishing, account takeover, and identity theft attempts.

Bulk SMS Infrastructure and Number Harvesting

Running a smishing operation at this scale requires more than a script; it requires confirmed, active phone numbers to target and infrastructure that can send convincing messages without getting immediately blocked. Palo Alto Networks’ Unit 42 traced roughly 194,000 malicious domains to the Smishing Triad’s infrastructure since January 2024 alone, with the group preemptively cycling domains within days to stay ahead of takedown efforts. Behind that infrastructure sits a division of labor rarely visible to victims: data brokers who source phone number lists, hosting providers, phishing kit developers, and dedicated staff whose sole job is verifying which numbers are active and worth targeting. That verification step matters; a smishing campaign is only as profitable as its target list is accurate, which is exactly why harvested and confirmed phone numbers carry resale value on the Dark Web long after the original scam text has been sent.

How to Identify a Smishing Text

How to Prevent and Protect Against Smishing

Red Flags to Watch For

A smishing text can almost always be identified by the combination of an unfamiliar sender, artificial urgency, and a link designed to be tapped before you think twice. The clearest signals include a message from a number you don’t recognize (often a random 10-digit number rather than a short business code), pressure to act immediately, a suspended account, an unpaid toll, a missed delivery, a shortened or slightly misspelled link, and a request for personal or payment information once you land on the page it leads to. No single red flag guarantees a scam on its own, since legitimate businesses occasionally send urgent texts too. Still, a message carrying two or three of these traits at once is reason enough to stop and verify before clicking anything.

What a Real Smishing Message Looks Like

In practice, most smishing texts follow a near-identical script regardless of which brand or agency they impersonate: a short line claiming a problem with a delivery, toll payment, or account, followed by a link to “resolve” it. A typical example reads something like “USPS: Your package could not be delivered due to an incomplete address. Update your info here: [link]”, a message deliberately vague enough to plausibly apply to almost anyone, since most people have at least one package in transit at any given time. Toll-scam variants follow the same formula with different wording, which is part of why they’re so recognizable once you’ve seen one: legitimate toll agencies and carriers don’t typically send unsolicited payment demands by text, and a genuine outstanding balance is something you can always confirm by going directly to the organization’s official app or website rather than the link in the message.

How to Prevent and Protect Against Smishing

How to Prevent & Protect Against Smishing

Personal Protection Steps

The most effective way to prevent Smishing is simple in principle: never click a link in an unsolicited text, and verify any claim, toll bill, delivery issue, or account alert directly through the organization’s official app or website instead. Beyond that habit, a few practical steps meaningfully reduce exposure: enabling spam filtering through your carrier, keeping your phone’s operating system and security software updated, and never entering personal or payment information on a page you reached by tapping a text link rather than typing the address yourself. It’s worth remembering that legitimate organizations rarely ask you to confirm sensitive details through a text message in the first place, so treating any request to do so as suspicious by default is a safe baseline rather than an overreaction.

Enterprise Smishing Awareness Programs

For organizations, smishing prevention has to account for the fact that a single successful text can compromise an employee’s credentials and, from there, the broader network, which is why awareness training has become a standard layer of enterprise security programs rather than an optional add-on. Effective programs typically combine simulated smishing exercises that test employee response in a low-stakes setting, clear internal reporting channels so a suspicious text can be flagged quickly, and policy guidance on verifying financial or data requests through a second channel before acting on them. This last point matters especially for CEO fraud-style smishing, where an urgent-sounding text impersonating an executive is designed specifically to bypass the kind of scrutiny normal request channels would trigger.

Tools and Detection Approaches

Beyond individual vigilance, a growing set of technical tools is built specifically to catch Smishing before it reaches an inbox or a click. Carrier-level SMS filtering and anti-spoofing measures block a meaningful share of known phishing patterns before delivery. At the same time, dark web and brand-monitoring platforms can detect when an organization’s customer phone numbers or employee data are circulating in the underground marketplaces that fuel these campaigns in the first place. That last layer addresses a gap most detection tools miss entirely: by the time a smishing text lands on someone’s phone, the number has often already been harvested, verified, and sold weeks earlier, which means monitoring for that earlier leak point can flag risk before an attack campaign even goes out.

What to Do If You’ve Been Smished

What to Do If You've Been Smished

How to Report a Smishing Text (Carrier, FBI, USPS)

If you receive a smishing text, the fastest useful step is to report it rather than simply deleting it, since reported numbers and message patterns help carriers and agencies block future campaigns faster. Most carriers let you forward a suspicious text to 7726 (SPAM), which flags the number for filtering; the FBI’s Internet Crime Complaint Center (IC3) at ic3.gov accepts reports of smishing scams and uses them to track broader campaigns, which is how spikes like the toll-scam wave were identified in the first place. If the message impersonates USPS specifically, it can also be reported directly to the Postal Inspection Service at uspis.gov, and general text scams can be reported to the FTC at reportfraud.ftc.gov. Reporting takes a minute and doesn’t require you to have clicked anything; the goal is to flag the number and pattern before it reaches someone else.

If You Already Clicked a Link

Clicking a smishing link isn’t the same as being compromised, but it does call for a few quick actions to limit the damage. If you entered any personal or payment information on the page, contact your bank or card issuer immediately to monitor for fraudulent charges and consider freezing the card if the information included full card details. If you downloaded anything or granted app permissions after clicking, run a security scan on your device and change passwords for any accounts tied to the information you may have exposed, prioritizing accounts that reuse that password elsewhere. Finally, report the incident using the same channels above, IC3, your carrier, or the impersonated organization directly, since even a single report contributes to identifying the broader campaign behind the message you received.

Get Ahead of Smishing Before It Reaches an Inbox

Most smishing prevention advice focuses on what to do after a scam text lands, but by then, the phone numbers, employee data, or customer records behind that campaign have usually already been circulating on the Dark Web for weeks. DeXpose’s Dark Web Monitoring tracks when your organization’s data surfaces in breach dumps, stealer logs, and criminal marketplaces, the same sources that feed smishing and brand-impersonation campaigns before a single text goes out. Paired with Brand Protection to catch phishing domains impersonating your company, it gives security teams a way to act on exposure early instead of reacting to it after the fact.

Not sure if your organization’s data is already exposed? Run a free Dark Web Report to see what’s out there right now.

Frequently Asked Questions (FAQ’s)

Is Smishing the Same as Phishing?

Smishing is a type of phishing; the underlying scam is identical, but Smishing specifically uses SMS text messages as the delivery method instead of email. Every smishing attack is phishing; not every phishing attack is Smishing.

What’s the Goal of a Smishing Attack?

The primary goal is to steal personal information, payment details, or account credentials that can be used for identity theft or financial fraud. Some attacks also aim to install malware or gain unauthorized access to a device or corporate network.

Can Smishing Happen on WhatsApp or iMessage?

Yes, Smishing isn’t limited to traditional SMS and increasingly appears on messaging apps like WhatsApp and iMessage. The Smishing Triad, for example, has used compromised iCloud accounts to send scam iMessages that bypass standard SMS filtering.

What Does a Smishing Scam Typically Involve?

A typical smishing scam involves a text impersonating a trusted sender, a bank, carrier, or agency, paired with urgent language and a malicious link. The link usually leads to a fake page designed to capture personal or payment information.

Why Are Smishing Attacks Particularly Effective?

Smishing attacks work because people trust and act on text messages faster than email, with less scrutiny of sender addresses or links. Mobile screens also make it harder to inspect a URL before tapping it, increasing the odds of a successful click.

Free Dark Web Report

Keep reading

No results found.