GRC Careers

HomeResourcesSmishing

CS-036 · Email Security

Smishing

Phishing delivered through text messages to steal information or push malicious links.

Executive Summary

Smishing is phishing carried out through text messages, most commonly SMS, that trick recipients into tapping a malicious link, revealing personal or financial information, or installing harmful software. It exploits the trust and immediacy people give to texts, along with the difficulty of inspecting links on a small screen. Smishing has grown rapidly as more services and organizations legitimately communicate by text.

What It Is

Smishing is a channel-specific form of phishing that uses text messaging instead of email. A typical smishing message impersonates a bank, a delivery service, a government agency, or an internal system, and prompts the recipient to act urgently by tapping a link or replying with information. The link often leads to a counterfeit login or payment page, or attempts to install a malicious app. Because texts are short, informal, and read quickly on mobile devices, recipients have fewer cues to judge legitimacy and less ability to preview where a link really goes. Smishing is part of the broader phishing family and is frequently combined with voice calls (vishing) to add pressure and credibility.

Why It Matters

People tend to trust and respond to texts faster than email, and mobile devices make it harder to spot warning signs, so smishing can be highly effective. A single tap can lead to stolen banking credentials, account takeover, fraudulent charges, or malware on a device that also holds work data. For organizations that allow personal and work use on the same phones, a successful smishing attack can bridge into corporate accounts. Smishing also fuels larger schemes such as multi-factor code theft and business fraud. For professionals, understanding this channel is increasingly important as attackers diversify beyond email, and defending mobile and messaging channels is now part of a complete security program.

How It Works

An attacker sends a text designed to look like a legitimate notification: a package cannot be delivered, an account is locked, a payment failed, or a verification code is needed. The message creates urgency and includes a shortened or look-alike link or a number to call. Tapping the link opens a counterfeit page that captures whatever is entered, or triggers a prompt to install a malicious app or grant permissions. In some schemes the attacker follows up by phone to walk the victim through handing over a one-time passcode, defeating certain forms of multi-factor authentication. Because sender numbers can be spoofed and links disguised, the message can look convincing, which is why caution with unexpected texts and independent verification are the core defenses.

Architecture Diagram

Attacker sends a deceptive text messageMessage impersonates a bank, courier, or agencyUser taps a shortened or look-alike linkCounterfeit page captures data or installs malwareAttacker uses stolen credentials, codes, or funds
Smishing uses a deceptive text and a disguised link to capture information or install malware on a mobile device.

Visual Workflow

The attacker crafts a text impersonating a trusted service and spoofs the sender number.The message urges quick action with a disguised link or a callback number.The recipient taps the link or calls, opening a counterfeit page or a live scam call.Credentials, payment details, or a one-time passcode are captured.The attacker uses the information for account takeover, fraud, or further attacks.Reported messages are shared with carriers and security teams to block the numbers and links.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

Mobile device management
Separates and protects work data and accounts on phones
Phishing-resistant MFA
Resists one-time-passcode theft that smishing enables
Carrier and message filtering
Blocks known scam numbers and malicious links at the network
Security awareness platform
Trains staff to recognize and report smishing attempts

Industry Standards

NIST SP 800-63
Digital identity guidance including stronger authentication methods
NIST SP 800-124
Guidance on securing mobile devices in the enterprise
CIS Critical Security Controls
Authentication and awareness safeguards that reduce smishing impact

Career Relevance

Smishing extends phishing defense into mobile and messaging channels. SOC analysts investigate reported texts and related account takeovers, incident responders handle compromises that reach work systems through phones, and security awareness leads add smishing to training. Security engineers deploy mobile device management and stronger authentication, while GRC analysts assess mobile and messaging risk. For the AI-Governance-Jobs.com audience, smishing is an important and growing part of social engineering defense.

Interview Questions

Related Certifications

CompTIA Security+ ISC2 Certified in Cybersecurity (CC) GIAC Security Essentials (GSEC)

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

How is smishing different from phishing?

Smishing is simply phishing delivered by text message rather than email. The goal is the same, to deceive you into revealing information, tapping a malicious link, or installing malware, but the channel makes warning signs harder to spot on a small screen.

Why do attackers ask for a one-time passcode?

A one-time passcode is often the second factor protecting an account. If an attacker already has your password, tricking you into sharing the code lets them complete the login. No legitimate organization will ask you to read back a passcode, so never share it.

What should I do about a suspicious text?

Do not tap any links or call the number provided. Navigate to the organization directly using a known app or website to check. Report the message to your carrier and delete it, and if you interacted with it, change affected passwords and alert your security team.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

CompTIA Security+ISC2 Certified in Cybersecurity (CC)GIAC Security Essentials (GSEC)

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: Smishing
  3. Go deeper: Vishing
  4. Go deeper: Phishing
  5. Validate it: work toward CompTIA Security+
  6. Find the role: browse current openings

Related sheets

More in Email Security

Share this LinkedIn Facebook X Email