What Smishing Actually Is
Smishing, SMS plus phishing, is a phishing attack delivered through text message rather than email, and in the Indonesian context that almost always means SMS or WhatsApp. The message typically impersonates a bank, courier, government agency, or e-commerce platform, and pushes the recipient toward a link that leads to a fake login page, a request to reply with a one-time password, or a phone number to call that connects to a live scammer posing as customer service.
The underlying goal is identical to email phishing: harvest credentials, one-time passwords, or personal data that lets an attacker take over a bank account, an e-wallet, or a corporate system. What differs is the channel's characteristics: SMS has no spam folder in the way email does, sender IDs can be spoofed to display a bank's actual short code or name, and WhatsApp messages arrive with the same visual trust markers, a profile photo, in some cases a business verification checkmark, that a legitimate business account would have.
A growing variant layers smishing with vishing: the text message does not ask for information directly but instructs the recipient to call a number, where a scammer with a prepared script extracts the same credentials or one-time password verbally. This combination is particularly effective against employees and consumers alike, because it removes the suspicious-link signal from the interaction almost entirely, replacing it with a phone call that feels like a normal customer service interaction.
Why SMS and WhatsApp Feel More Trustworthy Than Email
Email has had two decades of public awareness campaigns, spam filtering, and don't-click-suspicious-links training behind it, and users have absorbed at least a baseline level of suspicion toward it. SMS and WhatsApp have not received nearly the same volume of security education, despite carrying just as much financial risk, and both channels are used for so many legitimate, time-sensitive notifications, delivery updates, one-time password codes, appointment reminders, that a message demanding urgent action does not register as unusual on its own.
SMS sender-ID spoofing is a specific technical reason texts feel more credible in Indonesia: attackers can register or exploit a spoofed sender ID so that a phishing message appears in the same conversation thread as genuine messages from a bank, meaning the fake message sits directly beneath real notifications from the same sender with no visual distinction at all. WhatsApp compounds this with personal familiarity, since most Indonesians primarily use WhatsApp for close personal and family communication, so a message that opens in a tone of urgency or familiarity, for instance 'Kak, tolong bantu verifikasi...', borrows the emotional register of a real conversation rather than a cold marketing blast.
The mobile-first nature of both channels also limits the practical defenses available. There is no equivalent of hovering over a link to preview the destination URL on most phones, screens are small enough that a full domain name rarely displays in full, and the recipient is frequently reading and reacting in a distracted moment, on public transport, between meetings, walking, rather than at a desk where a suspicious email might get a second look.
The Lures That Work in Indonesia: Bank, Courier, Prize, Tax, and E-Wallet
Bank impersonation is the most financially damaging category: SMS or WhatsApp messages claiming a customer's account will be blocked, that a large transaction requires confirmation, or that a card needs reactivation, always with a link or number attached. Because major Indonesian banks do genuinely send SMS notifications for real transactions and account alerts, the population has been conditioned to associate bank-branded texts with legitimate urgency, which is exactly the conditioning smishing exploits.
Courier and delivery scams have surged alongside Indonesia's e-commerce boom: a text claiming a package could not be delivered due to an incomplete address or an unpaid customs or shipping fee, with a link to a fake tracking page that harvests payment details, arrives constantly during major shopping seasons such as Harbolnas and Ramadan sales, when consumers genuinely are expecting multiple deliveries and cannot easily verify which one is real. Prize and lottery lures, promising a windfall such as 'Selamat, Anda memenangkan undian berhadiah', remain effective specifically because they promise a gain rather than threaten a loss, lowering the recipient's guard in the opposite direction from a bank-threat message.
Government and tax-themed smishing has grown as digital tax services such as DJP Online and e-Filing, and social assistance programs, became more central to daily life; messages impersonating the tax office demanding verification of NPWP data, or claiming eligibility for a bantuan sosial disbursement, exploit both fear of penalty and hope of benefit. E-wallet impersonation, of GoPay, OVO, DANA, or ShopeePay, targeting both consumers and, increasingly, employees using e-wallets for reimbursement or payroll top-ups, follows the same bank-impersonation playbook but with a lower average transaction size that makes victims less cautious.
How to Spot and Verify a Suspicious Text Before You Act
Treat urgency itself as the first red flag, not a reason to act faster: any message insisting on immediate action within minutes or hours, for example a claim that your account will be blocked within 24 hours, is applying a pressure tactic that legitimate institutions rarely use over SMS. Second, never tap a link or call a number embedded in the message itself; instead, open the bank's app directly, or find the institution's official customer service number independently, from the back of a card, the official website, or a prior statement, and call that instead.
Never provide a one-time password, PIN, or CVV to anyone, whether by text reply or over a phone call, regardless of how official the caller sounds or how much personal information they already seem to have, since attackers frequently have partial data from previous breaches, which they use to sound credible. Check the sender's number and message thread carefully: a legitimate bank rarely mixes personal requests with automated notifications in the same thread, and any WhatsApp account, even one with a profile photo matching a real logo, can be created by anyone, so the presence of a logo is not verification.
When in doubt, verify through a second, independent channel before doing anything: call the institution using a number you already had before the message arrived, log in to the app directly rather than through any link, or ask a colleague or the IT or security team. Organizations should make it explicit and easy for employees to forward a suspicious SMS or WhatsApp message to the same phish-reporting channel used for email, since the reporting habit matters far more than the specific channel the attack arrived through.
How to Run Smishing Simulations Ethically
Smishing simulation must be handled with more legal and ethical care than email phishing, since it typically requires processing an employee's personal mobile number and sending to a channel, SMS or WhatsApp, that carries stronger personal-life connotations than a work email inbox. Before running any smishing campaign, confirm the legal basis under UU PDP for processing employee phone numbers for this purpose, secure explicit sign-off from HR and legal, and communicate to the workforce in advance that smishing simulations are part of the security program, without revealing specific timing or scenarios.
Scenario design should mirror the real lures documented above, a fake courier delivery notice, a spoofed bank alert, an e-wallet top-up confirmation, using a dedicated, clearly-scoped test sender ID or number rather than attempting to spoof a real bank or courier's actual number, and the landing page should capture the click and, if the scenario includes it, the one-time-password entry attempt, without ever storing anything resembling a real credential. As with any simulation, the immediate follow-up matters more than the trap: a user who clicks or replies should be shown corrective JIT content within moments, not simply logged as a failure.
Feed smishing results into the same risk-scoring, reporting-rate, and training-assignment pipeline used for email, vishing, and quishing simulations so a single unified view of an individual's susceptibility across channels emerges, rather than siloed per-channel scores that never get compared. Because SMS and WhatsApp genuinely do carry higher emotional and privacy sensitivity than a work email, keep the cadence of smishing simulations lower than email simulations and pair every campaign with a short, clear communication explaining why it happened and what to do differently, reinforcing that the program exists to protect people, not catch them out.
Key takeaways
- Smishing exploits SMS and WhatsApp's higher baseline trust and the lack of spam-filtering and hover-to-check habits built around email.
- Sender-ID spoofing lets fake bank messages sit in the same thread as real ones, with no visual difference to the recipient.
- The most effective local lures are bank account alerts, courier delivery fees, prize notifications, tax or BPJS verification, and e-wallet top-ups.
- Never tap a link or call a number inside the message itself; verify independently through the bank's app or an official, previously known number.
- Smishing simulations need explicit UU PDP, HR, and legal sign-off given the personal-device and personal-number context, and should run at a lower cadence than email tests.