Smishing
Smishing is a type of phishing attack carried out through SMS or text messages instead of email. Attackers send deceptive text messages designed to trick recipients into clicking malicious links, revealing sensitive information, or downloading harmful software. The term combines 'SMS' and 'phishing.'
Smishing is a social engineering attack vector that leverages SMS or text messaging to trick targets into disclosing sensitive information, clicking fraudulent links, or downloading malware. As a variant of phishing, it relies on manipulative messaging that impersonates trusted entities to induce a target action, differing from email-based phishing primarily in the delivery channel. In a payment security context, smishing may be used to harvest credentials or cardholder-adjacent personal data that can support downstream fraud such as account takeover or card-not-present fraud; the effectiveness of any single defensive control against it is limited, and it should be addressed as part of broader awareness and anti-phishing measures.
Why it matters
Smishing matters because it exploits a communication channel that many people treat as more trustworthy and immediate than email. Text messages are often read quickly and acted on without the scrutiny applied to email, which makes manipulative messaging that impersonates banks, card issuers, delivery services, or government agencies effective at inducing a target action. In a payment security context, the concern is not the text message itself but what it enables: harvested credentials, one-time passcodes, or personal data that can support downstream fraud such as account takeover or card-not-present fraud.
Because smishing relies on social engineering rather than a technical flaw in payment systems, it sits largely outside the direct control of the cardholder data environment and is not resolved by any single technical safeguard. It should be treated as one component of a broader anti-phishing and security awareness program. The effectiveness of any single defensive control against smishing is limited, and detection controls that flag suspicious messages carry the usual trade-offs of false positives and false negatives.
Exact figures on smishing prevalence and losses depend heavily on the source, reporting period, and methodology, so organizations should rely on qualitative understanding of the risk and their own measured data rather than assuming fixed rates.
Who it's relevant to
Inside Smishing
Common questions
Answers to the questions practitioners most commonly ask about Smishing.