Skip to content

Smishing

Smishing most precisely refers to phishing delivered through SMS or similar mobile text-message services. The same deceptive patterns also appear through instant-messaging and social-media direct messages, which Pretext8 treats alongside smishing because the defensive indicators are similar. The interaction may seek credentials, account approvals, payment, information, software installation, or movement to another communication channel.

Mobile messaging carries immediacy and familiarity. Delivery updates, account notifications, work instructions, and personal requests routinely arrive through short-form channels, allowing a deceptive message to sit inside an established interaction pattern. Limited screen space, shortened destinations, and reduced sender visibility can further constrain verification.

Smishing may also exploit interpersonal familiarity. A message presented as a manager, colleague, supplier, or known contact can create pressure to respond quickly, particularly where the sender claims to be using a new number or alternate account.

Smishing ranges from a single short message to an exchange that develops across multiple replies. The message may imitate a service notification, introduce a work-related instruction, or establish a personal reason for contact.

The exchange opens under a claimed sender and a stated reason for contact. Links, phone numbers, QR codes, payment requests, account prompts, or channel shifts then move the target towards the attacker’s intended outcome.

ElementWhat it meansExamples
Message channelThe messaging environment through which the request is delivered.SMS, WhatsApp, iMessage, Signal, Telegram, Messenger, workplace chat, social DMs.
Claimed senderThe person, service, or organisation the message appears to represent.Bank, courier, government service, employer, supplier, executive, colleague, recruiter.
PromptThe action the message seeks from the target.Tap a link, call a number, reply, make a payment, enter a code, approve a request, download an app.
Pressure or hookThe context used to make a rapid response appear necessary or routine.Delivery issue, account lockout, refund, missed payment, urgent work task, new number claim.
DestinationThe service, page, number, application, or conversation reached from the message.Login page, payment page, support number, app download, file, QR code, messaging thread.

The claimed sender, the destination, the requested action, and movement between channels hold most smishing indicators. Short message length can obscure the absence of normal business or interpersonal context.

IndicatorWhat to look for
Unexpected messageThe message arrives from an unknown number, unfamiliar account, new contact, or platform that is not normally used for the request.
New number claimA known person is presented as using a new number, temporary phone, replacement device, or alternate messaging account without established context.
Link or destination mismatchA shortened link, lookalike domain, unfamiliar subdomain, or destination does not align with the claimed organisation or service.
Credential or code requestUsernames, passwords, MFA codes, one-time passwords, recovery details, account approvals, or verification codes are requested through the message.
Payment or purchase requestBank details, card details, payment, gift cards, cryptocurrency, transfer approval, or urgent purchasing are introduced through the messaging channel.
Mobile-channel pressureAccount lockout, missed delivery, failed payment, fines, security concerns, or urgent work demands are used to accelerate action on the device.
Channel shiftThe sender directs the interaction to another application, phone number, personal account, or private conversation without an established reason.
Tone or isolation mismatchWording or timing differs from the claimed sender, or normal points of confirmation are deliberately excluded from the interaction.