← Glossary

Smishing

Phishing delivered by SMS text message. For companies the danger is the channel hop: attacks that start in email and move to unmonitored phones.

Updated

Key facts

  • SMS has minimal sender authentication and near-total open rates; there is no DMARC for text messages.
  • The classic corporate play is executive impersonation: "It's [CEO]. I'm in a meeting, need a quick favor", followed by gift card or payment requests.
  • MFA-fatigue and credential lures by SMS often reference context the attacker learned from a compromised or targeted mailbox.

The corporate smishing patterns

Executive impersonation texts to new employees (harvested from LinkedIn "excited to join" posts), fake IT messages pushing credential or MFA actions, and continuation attacks: an email thread that suddenly "moves to my cell" to escape the monitored channel. The common thread is that SMS is used exactly where email security would have caught the same content. See also phishing, quishing, business email compromise, social engineering and pretexting.

How to defend

Make the channel policy explicit: executives never request payments or purchases by text, IT never sends credential links by SMS, and any request that jumps from email to SMS gets verified back through a known channel. Protect the email side thoroughly, since most smishing campaigns against companies are researched or launched from information gathered by email attacks. Report and block sender numbers, but treat that as cleanup, not defense.

How Sentaro helps

Sentaro protects the email half of the attack: the reconnaissance phishing, the thread where "let's continue on my cell" appears, and the mailbox compromise that feeds smishing with context. Message Defense flags channel-switch requests paired with payment or credential intent, cutting the hop before it happens.

Questions we get asked.

What does smishing mean?

Phishing by SMS text message. The name combines SMS and phishing.

Why is smishing effective against companies?

Texts bypass every corporate email control, feel personal and urgent, and employees rarely expect impersonation there. New hires are prime targets for fake "CEO" texts.

What is an example of corporate smishing?

A text claiming to be from the CEO asking an employee to buy gift cards or process an urgent payment, often while the "CEO" is genuinely in a meeting, which the attacker learned from public calendars or a compromised mailbox.

How do we prevent smishing?

Clear channel policies (no payments or credentials via SMS, ever), verification through known channels, employee training that covers texts, and strong email security so attackers cannot harvest the context that makes smishing convincing.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.