Smishingโthe combination of the terms โSMSโ and โphishingโโis, according to IBM, โa social engineering attack that uses fake mobile text messages to trick people into downloading malware, sharing sensitive information, or sending money to cybercriminals.โ Unfortunately, with new technology comes new ways to elicit information from end users.
The first โrobocallโโautomated phone solicitingโwas documented in 1977. Robocalls were rebranded as โDinner Hour Marketing.โ This was when real people, not bots, would call landlines during dinner time to try and sell products or services.
With the introduction of emails, this type of solicitation quickly expanded. Yep, thatโs right, weโre talkinโ spam. In fact, the first unsolicited email was sent by Gary Turk in 1978 to 400 people. As spam emails became more sophisticated, email phishing emerged. In the 90s, bad actors started sending emails disguising themselves as others to trick the recipient. Today, phishing attacks are highly advancedโemail senders are disguised as businesses, employees, relatives, etc.
And now we’re back to the present day where these phishing attempts have breached messaging apps. So, what does a smishing attack look like? How do they work? Letโs explore SMS phishing a bit more to shed some light on this new type of attack.
SMS Marketing
We canโt talk about smishing without first talking about SMS marketing. With SMS marketing, brands can send customers texts sharing promotions, order updates, etc. So, as a result, people are starting to get used to text messages coming from unknown numbers with links to promotions.
Thereโs a catch, however. To receive marketing text messages, customers have to opt in and explicitly agree to get these types of messages. There also needs to be a way to opt out. Just as easily as customers can sign up, they can remove themselves from your SMS marketing list. Thatโs one way to distinguish between smishing and legit SMS marketing, but there are some other ways too.
What Does Smishing Look Like?
Smishing is one of those things that you recognize when you see it. At this point, most of us have probably experienced a smishing attack. When you open a text and think โHm, this is a little weirdโ or โThey probably have the wrong number,โ it could be a smishing attack.
The goal of a smishing attack is to try to get some information from the recipient. So, generally these messages ask the user to complete some sort of next step. Whether itโs clicking a link, responding with a password, or sharing your name, the scammer is looking to collect data that helps them access protected information. These attacks can be incredibly sneaky as the sender can disguise themselves as a brand or a person and itโs hard, as the recipient, to ensure the sender is who they say they are.
And, as IBM points out, โIt’s also harder to spot dangerous links on cell phones. For instance, on a computer, users can hover over a link to see where it leads, but on smartphones, they don’t have that option.โ
Take this text from an unknown number, for example. I received this message around 3:30pm on December 19th (conveniently right before I wrote this post) while sitting on my couch. My first thought was, โWhat did I order?โ Then, โWait, whatโs Tabit?โ

After some research, I learned that Tabit is a POS system for restaurants. So, one of two things could have happened: someone who actually was at a restaurant accidentally used my phone number when placing their order or someone is disguising themselves as Tabit to try to get recipients to click on the attached link.
Either could still be possible but, to play it safe, I didnโt click the link.
How to Combat Smishing
With sneaky senders, itโs hard to know whatโs smishing and whatโs not. So how are we supposed to know? From personal experience, itโs better to be suspicious. When in doubt, donโt respond, donโt click any links, and donโt send any personal information. If someone is trying to contact you with important information, theyโll find another way to do so.
IBM also provided a list of common smishing scams to be on the lookout for. These include pretending to:
- Be a financial institution
- Be the government
- Be customer support
- Be a shipper
- Be a boss or colleague
- Text the wrong number
- Be locked out of an account
- Offer free apps
With any of the above examples, there are other ways these actual senders would contact you if it was truly necessary. Your bank would probably email you before they text, your boss would probably Slack you, etc. These smishing attacks have been so prevalent that our CEO, Andrew Boni, once said to the entire company โIโll never text you about gift cards.โ That cleared that up.
Feel free to ignore, report, and block any numbers youโre not familiar with. Like we said, any legit marketing text message will give users the option to opt out. So, if you get a message from a brand and arenโt given that option or donโt remember opting in in the first place, use caution.
SMS Isnโt All Bad
In the words of Olivia Rodrigo, itโs brutal out here. These bad actors aim to take advantage of vulnerability. They often use fear and urgency to scare the recipient into acting immediately. Remember, if something is truly an emergency, youโll know about it outside of text messages.
All that being said, you shouldnโt fear signing up for marketing text messages. SMS marketing is highly regulated with rules in place to make SMS marketing extremely beneficial for the customers. Donโt let smishing scare you out of connecting with the brands you love.
If youโre a marketer looking to expand your brandโs mobile marketing program to include SMS, schedule an Iterable demo today to see whatโs possible.
