Smishing
Phishing via SMS or mobile messaging. It exploits trust in the phone and the absence of filters: the message arrives direct, short and with a link.
Full definition
Smishing is phishing via text message or messaging apps. The attacker sends an SMS impersonating a bank, a delivery company or a well-known service, with a link that leads to a fake login or payment page.
It works because the phone lacks the defenses of corporate email: no filter analyzes the message, the small screen hides warning signs, and people respond to SMS with an immediacy they no longer have with email. Sender names and short codes are also easy to forge.
For companies, the risk is that employees use that same phone to authenticate corporate access. Human risk management programs include the SMS channel in their simulations to measure and train this surface, not just the inbox.
Related terms
Phishing
An attack that impersonates a trusted sender, such as a bank, a colleague or a vendor, to steal credentials, data or money, or install malware.
Vishing
Social engineering over a phone call. The attacker poses as tech support, a bank or a vendor to obtain access or payments in real time.
Quishing
Phishing via QR code. The malicious link travels as an image, slips past email filters and opens on the phone, outside corporate defenses.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.