Last price

What is smishing?

Every day we receive dozens of messages on our phones: bank notifications, delivery alerts, communications from public bodies. Most are legitimate, but some conceal a growing threat. Smishing – a term combining SMS and phishing – is a form of cyberattack that exploits precisely this daily habit to deceive victims, tricking them into revealing sensitive data or clicking on malicious links.

Unlike other types of digital fraud, smishing strikes on a channel we tend to perceive as more trustworthy: the text message. We lower our guard more easily on the phone than we do in front of a suspicious email, and cybercriminals know this well. Understanding how it works and how to recognise it is the first step to avoiding becoming a victim.

 

Definition and meaning

The term smishing is a blend of two words: SMS and phishing. It is a cyberattack technique in which criminals send fraudulent text messages designed to look like official communications from banks, couriers, government bodies, or major companies. The objective is always the same: to push the recipient into taking an action – clicking a link, calling a number, providing personal data – that allows the attacker to steal information or money.

The spread of smishing has grown significantly in recent years, in parallel with the increased use of smartphones to manage banking, online shopping, and communications with public authorities. According to the Proofpoint State of the Phish Report 2023, over 76% of organisations globally experienced smishing attacks, with a steady year-on-year increase. In Italy, the phenomenon is further amplified by the widespread adoption of digital services and the habit of receiving SMS communications from banks and delivery companies.

 

What is the difference between smishing and phishing?

Smishing and phishing share the same underlying logic: deceiving the victim by impersonating a trustworthy entity to steal data or money. The difference lies in the channel used. Traditional phishing occurs via email, a medium on which users have developed a certain awareness over the years: spam filters, visual security indicators, the habit of checking the sender. Smishing, on the other hand, arrives via SMS, a channel that historically has very high open rates – it is estimated that around 98% of text messages are opened, compared to 20–30% of emails.

This makes smishing particularly insidious. The small phone screen limits visibility of suspicious details: the sender appears as a name or short number, any URL shown is often abbreviated or truncated, and the message arrives in a context where we expect brief, direct communications. Phishing attacks via email leave more traces and lend themselves to easier verification; smishing exploits the speed with which we tend to respond to an SMS, especially when the message communicates urgency or danger.

 

Smishing and phishing compared
  Phishing (email) Smishing (SMS)
Channel Email Text message (SMS)
Average open rate 20–30% Up to 98%
Sender visibility Full email address visible Often just a name or short number
URL visible Text link, often verifiable Often abbreviated or truncated
Protection filters Advanced and widespread spam filters Limited on SMS
User perception Growing wariness Channel perceived as trustworthy

 

How does a smishing attack work?

A smishing attack follows a fairly precise pattern, although there are many variations. The starting point is always a message that captures attention and, above all, convinces the recipient to act immediately. The construction of this message is anything but accidental: behind it lies an analysis of the behaviour, expectations, and fears of potential victims.

 

Fraudulent messages and malicious links

The fraudulent messages used in smishing carefully imitate communications from well-known organisations. The logo, tone, and even the sender number can be falsified through spoofing techniques, making the message practically indistinguishable from the original. A classic example is the fake bank SMS: “We have detected a suspicious access to your account. Click here to verify your identity.” Or the fake delivery notification: “Your parcel cannot be delivered. Update your details within 24 hours.”

The link contained in the message almost always leads to a clone website designed to faithfully replicate the appearance of the legitimate site. Once there, the user is invited to enter credentials, credit card details, or personal information, which go directly into the attacker’s hands. In some cases, simply clicking the link may be enough to install malware on the device, exploiting vulnerabilities in the mobile browser. This is why encryption of transmitted data – recognisable by the HTTPS prefix in the URL – is one of the first things to check before entering any information on a site reached via SMS.

 

Social engineering techniques

At the heart of every smishing attack is social engineering: the art of manipulating human behaviour by exploiting emotions such as fear, urgency, or curiosity. Cybercriminals study the psychological mechanisms that drive people to act without thinking and systematically incorporate them into their messages.

The sense of urgency is the most commonly used lever: “within 24 hours”, “your account will be suspended”, “immediate action required” are formulas designed to eliminate critical evaluation time. The fear of losing money, facing legal consequences, or having an account compromised pushes many people to click before thinking. Equally effective is the promise of a benefit – a tax refund, a prize, an exclusive offer – which exploits curiosity and self-interest.

In some more sophisticated smishing campaigns, attackers personalise messages using partially real information about the victim – name, bank name, place of residence – obtained from previous data breaches or public sources. This approach, known as spear smishing, enormously increases the credibility of the message and the likelihood that the victim will take the bait.

 

What are the risks for users?

The consequences of a smishing attack can be serious and long-lasting. It is not just a matter of a single fraudulent transaction: stolen data often fuels chains of subsequent attacks, leaving the victim vulnerable over time.

Personal data theft

Personal data theft is the most common objective of smishing attacks. The stolen information – banking credentials, OTP codes, credit card numbers, personal details, copies of identity documents – is used directly to access the victim’s accounts or sold on the dark web, where it feeds a shadow market of compromised digital identities.

A telling example is the so-called SIM swapping: after obtaining the victim’s personal data through smishing, criminals contact the mobile operator pretending to be the account holder in order to transfer the SIM to a device in their possession. They then receive all messages, including the OTP codes used to authenticate payments and banking access, emptying accounts within hours. It is one of the most damaging attacks that can originate from a single SMS.

Scams and digital fraud

Alongside data theft, smishing is also used to perpetrate direct scams. In these cases the objective is not to steal credentials, but to convince the victim to make a bank transfer, top up a prepaid card, or provide a code that authorises a transaction. This is the case with scams simulating requests for help from family members in difficulty, fake communications from the tax authority promising refunds, or SMS messages announcing prizes and winnings to be claimed after paying small delivery fees.

Digital fraud originating from smishing is often difficult to prosecute because criminals operate from different jurisdictions, use temporary or VoIP numbers, and quickly take down clone sites. For the victim, recovering lost funds or restoring their digital identity can take months, with a significant impact not only financially but also psychologically.

 

How to protect yourself from smishing?

The most effective defence against smishing starts with awareness: understanding how an attack works is already half the protection. But awareness alone is not enough: it must be translated into concrete behaviours and stable habits.

Recognising suspicious messages

The first step to defending yourself from smishing is learning to read the warning signs in fraudulent messages. A legitimate SMS from a bank or public body never asks you to enter credentials, PIN codes, or card details via a link. Similarly, no courier requires payment of additional charges via SMS to release a delivery: these are classic smishing pretexts.

Exaggerated urgency is one of the most reliable signals: if a message insists that you act “immediately” or “within a few hours”, it is almost always an attack attempt. It is worth pausing, not clicking, and verifying directly on the official website of the organisation – by typing the address into the browser, never following the link in the message – or by calling the official customer service number. Senders should also be examined carefully: an unrecognised number, a name slightly different from what you would expect, or a foreign number for an Italian service are all indicators of possible fraud.

Safe behaviours to adopt

Beyond recognising warning signs, some good practices significantly reduce the risk of falling victim to a phishing SMS attack:

  • Never click on links received via SMS from unknown or unexpected senders, even when the message seems convincing. If you believe it may be genuine, reach the service by manually typing the address into the browser or using the official app.
  • Keep your phone’s operating system and apps up to date, to reduce the vulnerabilities that malicious links can exploit to install malware.
  • Enable two-factor authentication on all important services – banking, email, cloud – to add a layer of protection even if credentials are stolen.
  • Report suspicious messages to your mobile operator and the relevant authorities, such as the Postal Police in Italy: each report helps to block fraudulent numbers more quickly.
  • In corporate environments, invest in regular staff training on social engineering techniques and phishing attack methods: the most vulnerable link in any security system remains the human one.

 

In a world where phone and digital identity are now inseparable, smishing represents a real and constantly evolving threat. Recognising it, knowing how to read it, and adopting conscious behaviours is today an integral part of a security culture that concerns everyone: private citizens, companies, and those who manage critical infrastructure.