03/09/2026
Smishing is text message phishing, and it's now more effective at reaching people
than email phishing.
The reason is mechanical. Most businesses spent the last decade hardening their
email gateways and training people on suspicious links. Almost nobody applied the
same effort to text messages. The result is a channel where employees still tap first
and think later.
The patterns repeat: a "delivery failed" message with a link asking for login
credentials, a "this is your CEO" text from a number nobody recognizes asking for gift
cards or a wire, a fake account-lockout message that looks identical to a real bank
alert, and a "hey, I'm in a meeting, can you help me with something quick?" text
impersonating a senior person.
These work because texts feel personal in a way email doesn't. They land on the same
screen where your spouse, your kids, and your coworkers reach you, which makes the
brain default to trusting them. That's the entire attack.
The rules to give your team:
1. No business decision happens over text. That includes wire transfers, vendor
changes, payroll changes, gift card requests, and password resets.
2. If a text claims to be from a coworker, verify through a different channel before
responding. A 30-second Slack message or phone call kills most of these
attacks.
3. Never click a login link inside a text. Open the app or website directly.
4. Forward suspected smishing to 7726 (which spells SPAM on a phone keypad).
Carriers use it to block the source.
Smishing works when the response happens before the thinking. Train your team to
slow down, and most of these attacks dead-end before the attacker has time to react.