Smishing is phishing moved to the phone’s messaging channel — SMS, iMessage, or RCS — luring you to tap a malicious link, call a fraudulent number, or hand over a code or payment by impersonating a bank, carrier, delivery service, or agency inside a short, urgent message. The channel change is itself the attacker’s advantage: texts are read almost immediately and with little scrutiny.
The medium is dominated by legitimate short alerts — delivery updates, bank notices, verification codes — so a fraudulent message hides inside an expected class. The small screen truncates or hides a link’s true destination, removing the hover-to-inspect check that email allows, and link shorteners further obscure where a tap leads. Common templates impersonate a parcel carrier (“your package is held, pay a small redelivery fee”), a bank (“suspicious charge — verify now”), or a toll or tax authority.
A distinct and dangerous variant is the one-time-code intercept: the attacker triggers a real login or reset on your account, then texts posing as the “fraud department” to talk you into reading back the code that just arrived. Another is the “wrong number” opener that warms a stray text into a long-con investment or romance fraud. The constant: an unexpected message creating urgency and pointing to a link, number, or code you did not initiate.