Back to the glossary
    Social engineering & phishingCybersecurity glossary

    Smishing

    Phishing via SMS or mobile messaging. It exploits trust in the phone and the absence of filters: the message arrives direct, short and with a link.

    Full definition

    Smishing is phishing via text message or messaging apps. The attacker sends an SMS impersonating a bank, a delivery company or a well-known service, with a link that leads to a fake login or payment page.

    It works because the phone lacks the defenses of corporate email: no filter analyzes the message, the small screen hides warning signs, and people respond to SMS with an immediacy they no longer have with email. Sender names and short codes are also easy to forge.

    For companies, the risk is that employees use that same phone to authenticate corporate access. Human risk management programs include the SMS channel in their simulations to measure and train this surface, not just the inbox.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.