Key facts
- SMS has minimal sender authentication and near-total open rates; there is no DMARC for text messages.
- The classic corporate play is executive impersonation: "It's [CEO]. I'm in a meeting, need a quick favor", followed by gift card or payment requests.
- MFA-fatigue and credential lures by SMS often reference context the attacker learned from a compromised or targeted mailbox.
The corporate smishing patterns
Executive impersonation texts to new employees (harvested from LinkedIn "excited to join" posts), fake IT messages pushing credential or MFA actions, and continuation attacks: an email thread that suddenly "moves to my cell" to escape the monitored channel. The common thread is that SMS is used exactly where email security would have caught the same content. See also phishing, quishing, business email compromise, social engineering and pretexting.
How to defend
Make the channel policy explicit: executives never request payments or purchases by text, IT never sends credential links by SMS, and any request that jumps from email to SMS gets verified back through a known channel. Protect the email side thoroughly, since most smishing campaigns against companies are researched or launched from information gathered by email attacks. Report and block sender numbers, but treat that as cleanup, not defense.
How Sentaro helps
Sentaro protects the email half of the attack: the reconnaissance phishing, the thread where "let's continue on my cell" appears, and the mailbox compromise that feeds smishing with context. Message Defense flags channel-switch requests paired with payment or credential intent, cutting the hop before it happens.