S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.9
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Smishing

Messaging Vector · Text-Message Phishing · Very High
Red Flag
How It WorksSEC 01

Smishing is phishing moved to the phone’s messaging channel — SMS, iMessage, or RCS — luring you to tap a malicious link, call a fraudulent number, or hand over a code or payment by impersonating a bank, carrier, delivery service, or agency inside a short, urgent message. The channel change is itself the attacker’s advantage: texts are read almost immediately and with little scrutiny.

The medium is dominated by legitimate short alerts — delivery updates, bank notices, verification codes — so a fraudulent message hides inside an expected class. The small screen truncates or hides a link’s true destination, removing the hover-to-inspect check that email allows, and link shorteners further obscure where a tap leads. Common templates impersonate a parcel carrier (“your package is held, pay a small redelivery fee”), a bank (“suspicious charge — verify now”), or a toll or tax authority.

A distinct and dangerous variant is the one-time-code intercept: the attacker triggers a real login or reset on your account, then texts posing as the “fraud department” to talk you into reading back the code that just arrived. Another is the “wrong number” opener that warms a stray text into a long-con investment or romance fraud. The constant: an unexpected message creating urgency and pointing to a link, number, or code you did not initiate.

Warning SignsSEC 02
  • An unexpected text with a link — about a package, payment, account, toll, or fine you weren't tracking.
  • Shortened or look-alike domains and odd URL structures you cannot inspect on the small screen.
  • Urgency or threat in a few words — "final notice," "verify to avoid suspension."
  • A request to reply, call a number, or read back a code that arrived on your phone.
  • Unusual sender numbers — long strings, foreign, or email-to-SMS gateways.
  • A "wrong number" text that quickly turns warm and steers toward money.
Frequently Paired WithSEC 03
  • Phishing · T14.2
    Parent technique, email channel
  • Vishing · T14.8
    Voice channel, often paired for callback
  • Package / Delivery Scams · T24.9
    The most common smishing payload
  • Fake Support Portals · T14.22
    The look-alike landing page
How the Attack UnfoldsSEC 04
  • Stage 01 · Delivery
    An unexpected text with an urgent hook — held parcel, locked account, unpaid toll — lands and is read within minutes.
  • Stage 02 · The Tap
    The small screen hides the link's real destination and urgency compresses the pause, so a reflexive tap opens a look-alike page or dials a fraud line.
  • Stage 03 · Harvest
    The fake portal or "fraud department" call captures card details, a login, or the one-time code — completing theft or account takeover.
Counter-ProtocolSEC 05
Defense: Don't tap the link — verify with the organization directly.
  • Withhold the tap. Reach any bank, carrier, or account through its official app or a bookmarked site; track parcels only via the carrier's own site with your own number.
  • Never share a code. Never read back or forward a one-time code — legitimate providers never ask for it.
  • Don't call the number in the text. Use the number on your card or bill instead.
  • Report and block. Forward spam texts to your carrier's reporting service; enable carrier and OS spam filtering.
  • Harden with passkeys. Phishing-resistant MFA makes a phished code or password insufficient.