SOCIAL ENGINEERING | MOBILE SECURITY
10 min read

Smishing in the Enterprise: How SMS Phishing Bypasses Email Defenses and What to Do About It

3x
higher click-through rate on SMS phishing links versus email phishing links — mobile users are conditioned to tap, not scrutinize
76%
of organizations experienced smishing attacks targeting employees in 2025 — Proofpoint State of the Phish
$2.9B
in BEC and related social engineering losses reported to the FBI in 2025 — SMS-initiated attacks are an increasing share
0
email security gateways, DMARC policies, or anti-spam filters that apply to SMS messages — the channel is unguarded by default

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

Email phishing has a well-developed defense stack: gateways, sandboxing, DMARC, spam filters, and user training calibrated to email-specific cues. SMS phishing has none of this. Text messages bypass every email security control and arrive on devices — often personal phones in BYOD environments — that have no corporate security tooling.

The smishing threat model for enterprises is distinct from consumer smishing. Attackers target employees with texts impersonating internal IT systems ('Your VPN access expires in 2 hours — click to renew'), HR platforms ('Your benefits enrollment closes Friday'), package delivery services with embedded credential-harvesting links, and executive assistants requesting urgent gift card purchases or wire transfer authorizations. The same social engineering techniques that work in email work better via SMS because the channel feels more personal and less scrutinized.

Current enterprise smishing attack patterns

Knowing the specific templates attackers use makes it easier to build relevant user training.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Why standard controls don't apply to SMS

Before covering what works, it's worth being precise about what does not work for SMS threats.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Controls that reduce smishing exposure

Despite the channel limitations, a layered approach reduces smishing success rates significantly.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

Incident response when an employee clicks a smishing link

When an employee reports clicking a suspicious SMS link or entering credentials on a linked page, the response must move quickly because smishing victims often don't report immediately.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The bottom line

Smishing is the fastest-growing social engineering vector for enterprises in 2026 because the defense gap is wide and attackers know it. Your email security investment provides zero protection against SMS phishing. The practical controls — MTD on enrolled devices, clear channel policies, SMS-specific training, and verified in-app channels for security communications — close a significant fraction of the gap without requiring new enterprise platform purchases.

Frequently asked questions

What is the difference between smishing and vishing?

Smishing is phishing via SMS text message. Vishing is phishing via voice call. Both bypass email security controls. They are often combined — a smishing text asks the recipient to call a number, connecting to a vishing actor who completes the social engineering. The Scattered Spider group used this combination extensively in their 2023-2026 enterprise breaches.

Can mobile carriers block smishing attacks?

Mobile carriers in the US have deployed anti-spam filtering for SMS at the network level and have A2P (application-to-person) messaging regulations that require business senders to register. However, attacker-controlled SIM cards, grey-route SMS aggregators, and international messaging gateways allow sophisticated attackers to bypass many carrier-level controls. Carrier filtering reduces commodity smishing volume but does not stop targeted enterprise smishing campaigns.

Are QR codes in SMS more dangerous than regular links?

QR codes in SMS are more dangerous from an analysis perspective because mobile users typically cannot see the destination URL before scanning, mobile browsers don't show full URLs prominently, and QR codes bypass simple URL inspection training ('look before you click' advice doesn't apply when the URL isn't visible). Train employees to treat any unsolicited QR code in SMS with the same skepticism as an unexpected link.

Sources & references

  1. Proofpoint 2025 State of the Phish
  2. Lookout Mobile Phishing Report 2025
  3. FBI IC3 2025 Internet Crime Report

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.