Smishing is a specialized form of phishing that transmits malware or steals credentials through text messages. The nature of smishing has evolved in a short time from minor nuisance to enterprise-level threat, and is responsible for major breaches in the last few years.
This article will focus on smishing, its current state in web communications, and solutions for mitigating the threat it poses.
Key Takeaways:
Smishing dominates mobile phishing, accounting for almost 70% of all mobile-targeted phishing.
The high trust and expediency of SMS-based communications make Smishing a lucrative attack vector.
High-profile enterprise breaches are now trending towards SMS-based social engineering as the point of origin.
SURBL helps combat smishing by identifying and blacklisting malicious URLs, and shortened URLs, found in unsolicited messages.
SmishReport by SURBL is a community-driven platform designed to identify and block malicious domains found in SMS phishing (smishing) attacks. It facilitates user submissions of suspicious links or screenshots to enhance threat intelligence and protect against credential theft.
State of Smishing
What is Smishing?
Smishing is a combination of “SMS” and “phishing.” It is a specialized form of phishing that uses text messages on mobile devices to carry out the scam. Smishing uses deceptive text messages to trick people into revealing sensitive information.
How Does Smishing Work?
People tend to trust text messages more than emails, and because phones are often in hand, users are more likely to click links quickly. Smishing also tends to pose as delivery services like FedEx or UPS, financial institutions, or government agencies like the IRS. The combined convenience of communication and the sense of urgency often lures in potential victims easily.
Current State of Smishing
Smishing has evolved from an occasional nuisance to an industrial-scale fraud economy in a few short years. It is responsible for millions of dollars in consumer losses and is becoming more favorable over email because SMS lacks the kind of built-in spam filters that protect email. This allows attackers to exploit the high trust and immediate attention users give to mobile notifications.
Residents of the United States are commonly bombarded with SMS messages about toll road violations (“Toll Scams”), purporting to be the Department of Transportation demanding a delinquent fee.
Top Targets of Smishing
Smishing works because it’s simple. It relies on the trust people place in text messages. SMS click-through rates are significantly higher than email phishing, and the smaller screen format also makes it harder to inspect URLs before clicking.
The impact it has on enterprises is more complex and extremely severe. High profile compromises at companies like Twilio, Uber, and MGM Resorts all track back to SMS-based social engineering as the initial breach. These coordinated campaigns resulted in hundreds of compromised accounts, unauthorized internal access, and losses exceeding $100 million.
Key Risks of Smishing Attacks
Financial Theft: Attackers drain bank accounts, steal credit card details, and make unauthorized wire transfers.
Identity Theft: Scammers harvest personally identifiable information in order to open lines of credit in the victim’s name. Alternatively, these hijacked accounts are repurposed as lures for other campaigns.
Account Takeover: Stolen login credentials give hackers access to enterprise networks. They take over social media or email accounts, escalate access, and lock the owners out. They often demand a ransom to restore access to the owners.
Malware Installation: Malicious links sent by SMS will often download spyware or ransomware to the user’s device. These programs track keyboards, steal photos, and hold data hostage.
How to Take Action
SURBL B.V. helps combat phishing and smishing by identifying and blacklisting malicious URLs found in unsolicited messages. It acts as a second-stage filter, analyzing message bodies for fraudulent links rather than just the sender’s IP, with updates every few minutes to block active threats. SURBL helps combat phishing and smishing in the following ways:
Phishing Protection: It scans incoming emails for links associated with phishing scams, alerting mail servers to block or divert them, preventing users from clicking malicious links.
Smishing Protection: SURBL provides highly effective datasets / intelligence to identify and blacklist malicious domains commonly sent via text messages (smishing).
Real-time Intelligence: SURBL provides continuously updated data (updated every 1-2 minutes!) on active phishing, malware, and botnet sites.
“Fresh” Domain Tracking: SURBL offers a “Fresh” list that identifies newly created domains. Because many new domains are used for malicious purposes, this enables proactive blocking of phishing sites immediately upon activation.
Integration with Security Systems: Large mailbox providers and security systems use SURBL’s data to automatically filter out or warn users about phishing sites before they can cause harm.
SURBL also offers a resource called Smish Report, a free, community-driven platform designed to combat smishing.
Smish Report collects and verifies malicious domains sent via text messages that are then fed into SURBL databases.
Users can anonymously submit suspicious text messages and URLs to Smish Report, which are then processed and used by email, web, and SMS security filters to block fraudulent links. Unlike traditional blacklists, SURBL evaluates the content of these messages and prevents users from clicking on harmful links, even if the scam is sent from a spoofed or legitimate number
Conclusion
Phishing and Smishing are a pervasive threat for over a decade and continue to increase in volume over the years. As attackers increasingly leverage automation and artificial intelligence to craft targeted, convincing lures, no industry or individual is immune. Combating these threats requires a layered approach—combining real‑time threat intelligence, coordinated law‑enforcement efforts, and continuous user education.
Tools like SURBL play a critical role in identifying, blocking, and disrupting malicious links and malicious infrastructure.
State of Smishing
Smishing is a specialized form of phishing that transmits malware or steals credentials through text messages. The nature of smishing has evolved in a short time from minor nuisance to enterprise-level threat, and is responsible for major breaches in the last few years.
This article will focus on smishing, its current state in web communications, and solutions for mitigating the threat it poses.
Key Takeaways:
State of Smishing
What is Smishing?
Smishing is a combination of “SMS” and “phishing.” It is a specialized form of phishing that uses text messages on mobile devices to carry out the scam. Smishing uses deceptive text messages to trick people into revealing sensitive information.
How Does Smishing Work?
People tend to trust text messages more than emails, and because phones are often in hand, users are more likely to click links quickly. Smishing also tends to pose as delivery services like FedEx or UPS, financial institutions, or government agencies like the IRS. The combined convenience of communication and the sense of urgency often lures in potential victims easily.
Current State of Smishing
Smishing has evolved from an occasional nuisance to an industrial-scale fraud economy in a few short years. It is responsible for millions of dollars in consumer losses and is becoming more favorable over email because SMS lacks the kind of built-in spam filters that protect email. This allows attackers to exploit the high trust and immediate attention users give to mobile notifications.
Residents of the United States are commonly bombarded with SMS messages about toll road violations (“Toll Scams”), purporting to be the Department of Transportation demanding a delinquent fee.
Top Targets of Smishing
Smishing works because it’s simple. It relies on the trust people place in text messages. SMS click-through rates are significantly higher than email phishing, and the smaller screen format also makes it harder to inspect URLs before clicking.
The impact it has on enterprises is more complex and extremely severe. High profile compromises at companies like Twilio, Uber, and MGM Resorts all track back to SMS-based social engineering as the initial breach. These coordinated campaigns resulted in hundreds of compromised accounts, unauthorized internal access, and losses exceeding $100 million.
Key Risks of Smishing Attacks
How to Take Action
SURBL also offers a resource called Smish Report, a free, community-driven platform designed to combat smishing.
Smish Report collects and verifies malicious domains sent via text messages that are then fed into SURBL databases.
Users can anonymously submit suspicious text messages and URLs to Smish Report, which are then processed and used by email, web, and SMS security filters to block fraudulent links. Unlike traditional blacklists, SURBL evaluates the content of these messages and prevents users from clicking on harmful links, even if the scam is sent from a spoofed or legitimate number
Conclusion
Phishing and Smishing are a pervasive threat for over a decade and continue to increase in volume over the years. As attackers increasingly leverage automation and artificial intelligence to craft targeted, convincing lures, no industry or individual is immune. Combating these threats requires a layered approach—combining real‑time threat intelligence, coordinated law‑enforcement efforts, and continuous user education.
Tools like SURBL play a critical role in identifying, blocking, and disrupting malicious links and malicious infrastructure.
Recent Posts
Recent Comments
Popular Categories
Popular Tags
Archives