Smishing (SMS phishing) is a type of social engineering attack where attackers use text messages (SMS) to trick victims into revealing sensitive information (bank account numbers, credit card details, login credentials) or installing malware. Attackers impersonate trusted entities (banks, delivery services, government agencies, tech support) using urgency tactics ("Your account has been locked", "Package delivery failed", "Tax refund pending"). Smishing attacks have increased dramatically due to widespread SMS usage and lower user suspicion compared to email.
Attack Prevalence: 85% of organizations experienced smishing attacks in 2023 (Proofpoint). 300% increase in smishing attacks since 2020. Average cost per smishing incident: $800,000 (data breach, financial fraud).
Common smishing attack impersonations:
Attacker sends mass SMS messages using SMS gateways, spoofed sender IDs, or compromised phone numbers.
Message impersonates FedEx, bank, IRS, or tech support. "Your package delivery failed", "Account locked".
Victim clicks shortened/obfuscated link (bit.ly, tinyurl, typosquatted domain).
Victim enters credentials on fake website (credential harvesting) or downloads malware (Android banking Trojan).
// Smishing SMS examples (malicious)
Example 1: FedEx delivery scam
"FedEx: Your package delivery failed. Please reschedule delivery: http://fedex-delivery.xyz"
Example 2: Bank account locked
"Chase Bank: Your account has been locked due to suspicious activity. Verify now: https://chase-verify.xyz"
Example 3: IRS tax refund
"IRS: You have a pending tax refund of $1,200. Claim now: http://irs-refund.xyz"
Example 4: Amazon account alert
"Amazon: Your account will be suspended. Update payment info: https://amazon-security.xyz"
Attacker impersonates FedEx, UPS, USPS, Amazon. "Package delivery failed", "Tracking update". Malicious link to credential harvesting site or malware download.
Attacker impersonates major banks (Chase, Bank of America, Wells Fargo). "Your account has been locked", "Unauthorized transaction detected". Malicious link to fake banking login page (credential harvesting).
"You have a pending tax refund of $1,200", "Claim your stimulus payment". Malicious link to credential harvesting site (steals SSN, bank account).
SMS contains link to malicious APK (Android malware). Banking Trojans (Cerberus, EventBot, Anubis) steal banking credentials, intercept SMS 2FA codes.
// Smishing statistics (Proofpoint, FTC, 2023)
- 85% of organizations experienced smishing attacks (2023)
- 300% increase in smishing attacks since 2020
- Average cost per smishing incident: $800,000
- 65% of smishing messages impersonate delivery services (FedEx, UPS, USPS)
- 20% impersonate banks
- 10% impersonate IRS/government
- 5% impersonate tech support
- 40% of smishing victims click malicious links (mobile devices)
- 25% of victims enter credentials on fake websites
- 15% of victims download malware (Android banking trojans)
// Major smishing campaigns
1. FedEx Smishing (2022-2023): 5 million+ SMS messages
2. IRS Refund Scam (2023): $50 million stolen
3. Bank Account Locked (2021-2023): $100 million stolen
This demonstration simulates a smishing attack where an attacker impersonates FedEx delivery service:
This is a simulated demonstration. Real smishing attacks can steal bank credentials, install malware (Android banking trojans), and cause financial fraud. Never click links in unsolicited SMS. Verify delivery status by visiting official website (type URL manually). Forward smishing attempts to 7726 (SPAM) - your mobile carrier will investigate. Enable MFA (App-based authenticator, not SMS) to prevent MFA bypass.
Never click links in unsolicited text messages. Verify delivery status by typing official website URL manually (fedex.com, usps.com, amazon.com). Do not use link from SMS.
Forward smishing messages to 7726 (SPAM). Mobile carriers (AT&T, Verizon, T-Mobile) investigate and block malicious numbers. Report to FTC (ftc.gov/complaint).
Enable carrier spam blocking (AT&T ActiveArmor, Verizon Call Filter, T-Mobile Scam Shield). Use third-party apps (Truecaller, RoboKiller) to filter smishing.
SMS 2FA can be bypassed via smishing (malware intercepts SMS). Use app-based authenticator (Google Authenticator, Authy, Microsoft Authenticator) or hardware token (YubiKey).
Best Practice - Never Click Links in SMS: Never click links in unsolicited text messages. Verify delivery status by typing official website URL manually (fedex.com, usps.com, ups.com, amazon.com). Forward smishing attempts to 7726 (SPAM). Enable app-based MFA (not SMS 2FA). Report smishing to FTC (ftc.gov/complaint).
Smishing (SMS phishing, wire fraud) is illegal in all jurisdictions with severe penalties:
Smishing (SMS phishing) is illegal. Penalties include:
Important: This guide is for educational and defensive purposes only. Smishing is illegal and harmful.
Report smishing to Federal Trade Commission (FTC).
Forward smishing messages to 7726 (SPAM) to report to mobile carrier (AT&T, Verizon, T-Mobile).