Smishing
SMS phishing, a social engineering attack delivered via text message, often containing a malicious link or urgent request designed to steal credentials.
Smishing combines SMS and phishing: attackers send text messages that appear to come from banks, delivery services, government agencies, or employers. The messages create urgency (“Your account has been locked”, “Your package couldn’t be delivered”) and include a link to a credential-harvesting page.
Smishing is effective because people tend to trust text messages more than emails, and mobile browsers make it harder to verify URLs before clicking. The smaller screen also makes phishing pages harder to distinguish from legitimate ones.
Defenses include never clicking links in unexpected text messages, verifying claims by contacting the organization directly, using a password manager (which won’t autofill on phishing domains), and reporting suspicious messages to your carrier.
Related reading
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide