Attack technique

Smishing

Smishing is phishing carried out over SMS or other text messaging, where attackers send fraudulent texts to trick people into revealing data, clicking malicious links, or sending money.

Definition

Smishing, a blend of SMS and phishing, is a form of social engineering in which an attacker sends fraudulent text messages to deceive a recipient into taking a harmful action. That action is typically clicking a malicious link, replying with sensitive information such as a one-time password or banking detail, calling a fraudulent number, or installing a malicious app. Smishing applies the same psychological pressure as email phishing, urgency, authority, fear, or reward, but delivers it through SMS and increasingly through messaging apps, where messages feel personal and links are harder to inspect.

A typical smishing attack arrives as a short text that impersonates a trusted sender: a bank, a delivery courier, a tax office, a telecom provider, or an internal IT helpdesk. The message creates a reason to act quickly, such as a blocked account, a pending parcel, a suspicious transaction, or an expiring reward, and includes a link or phone number. Because mobile screens are small and SMS strips out the sender verification cues people rely on in email, recipients often cannot tell that a shortened or look-alike link leads to a credential-harvesting page rather than the real service.

Smishing is effective because text messages have very high open rates and are usually read within minutes, and because people tend to trust their phones more than their inbox. Attackers spoof sender IDs, abuse link shorteners, and register look-alike domains to appear legitimate. A common pattern targets one-time passwords: the victim is lured to a fake login page, enters their credentials and the SMS code, and the attacker uses both in real time to take over the account. This is one reason SMS-based codes alone are a weaker second factor than app-based or hardware authentication.

Smishing matters for regulated organizations because a single employee who taps a malicious link on a personal or work phone can expose corporate credentials, customer data, or payment systems. In markets where mobile messaging is a primary channel, the attack surface is large and the volume is high. Defending against it requires more than technical filtering: people need to recognize the warning signs, verify requests through a known channel, and avoid acting on links sent by text. This makes smishing as much a human risk problem as a technical one.

At a glance

Severity
Medium-High
Prevalence
Very common
Primary targets
Mobile phone users, especially banking and delivery customers
Also known as
SMS phishing

How it works

  1. 1

    Impersonation: the attacker sends a text that appears to come from a bank, courier, telecom provider, or IT helpdesk.

  2. 2

    Urgency: the message creates a reason to act quickly, such as a blocked account, a pending parcel, or an expiring reward.

  3. 3

    Malicious link or number: it includes a link to a fake page or a phone number to call.

  4. 4

    Deceptive page: the shortened or look-alike link leads to a page that mimics a real login or payment screen.

  5. 5

    Capture: the victim enters credentials, an OTP, or payment details, which the attacker uses immediately, often to bypass SMS-based verification.

Warning signs

  • Unexpected text about a blocked account, pending parcel, or urgent transaction
  • Shortened or unfamiliar link that does not show the real destination
  • Message asking you to reply with an OTP, password, or bank details
  • Sender ID that looks official but the request feels out of place
  • Poor grammar or formatting inconsistent with the claimed sender

How to defend

  • Never tap links in unexpected text messages; go to the service directly instead
  • Never reply to a text with an OTP, password, or banking detail
  • Verify unusual account or delivery notices through the official app or website
  • Use app-based or hardware multi-factor authentication instead of SMS codes where possible
  • Report suspicious texts to your telecom provider or security team

Real-world example

A customer in Surabaya receives an SMS claiming a courier delivery is on hold pending a small customs fee, with a link to pay. The link opens a convincing payment page that captures the customer's card details, which the attacker uses for fraudulent purchases within the hour.

How Claro helps

Claro treats smishing as a measurable human risk, not just an inbox problem. The platform runs controlled smishing and phishing simulations to see who acts on a suspicious text, then turns those moments into short, encouraging micro-training delivered in the recipient's language. Results feed into per-user and per-department risk scores, so security teams can target the people and units most exposed and show measurable behavior change over time. For regulated Indonesian institutions, Claro also packages this activity into compliance evidence aligned with OJK, BSSN, ISO 27001, and UU PDP requirements.

Frequently asked questions

What is Smishing?

Smishing is phishing carried out over SMS or text messaging, where an attacker sends a fraudulent text, often posing as a bank, courier, or government body, to trick you into clicking a link or sharing information.

Why is smishing so effective?

Text messages have very high open rates and are usually read within minutes, and people tend to trust their phones more than their email inbox. Mobile screens are also small, making it harder to inspect a link before tapping it.

How is smishing different from phishing?

The underlying psychological tactics are the same, but smishing is delivered over SMS or messaging apps instead of email, which strips away many of the sender verification cues people rely on and reaches a channel people check more urgently.

Are SMS one-time codes a strong second authentication factor?

They are better than no second factor, but weaker than app-based or hardware authentication, since a smishing attack can lure the victim into providing both the password and the SMS code, letting the attacker complete the login in real time.

What should I do after clicking a smishing link?

Avoid entering any information on the resulting page. If you already entered details, change the relevant password or card details immediately, and report the incident so your organization can watch for follow-on fraud.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo