Make Smishing Measurable: 2026 Statistics and KPIs for Security Teams

Smishing reports rose sharply in early 2026, with contributor telemetry from the APWG showing telephone-based fraud climbing and consumer losses to text scams already topping $470 million annually by the most recent full-year count. For security teams, the implication is direct: mobile messaging now carries significant attack volume and conversion risk that justify dedicated telemetry, reporting, and budgeting, rather than being treated only as a minor part of email security programs.
TL;DR:
- Smishing reports increased by roughly 40% from Q1 to Q2 2026, with social media and SMS as growing delivery vectors.
- Consumer losses to text scams reached 470 million dollars in 2024, with the share of reports resulting in monetary loss rising from 5% in 2020 to 11% in 2024.
- The human element is present in 62% of breaches, and mobile-specific phishing simulations show click rates about 40% higher than email, indicating greater mobile risk.
- Most security programs still under-measure mobile messaging threats because dashboards focus primarily on email telemetry, underestimating actual exposure.
- Effective defense requires channel-specific reporting, quick threat detection, and integration into existing security tools, rather than relying solely on traditional email security measures.
- ✓Collect suspicious messages
- ✓Analyze reported messages and senders
- ✓Correlate reports across users
- ✓Identify coordinated campaigns
Table of Contents
- Executive Summary: Key 2026 Smishing Statistics
- Key Numbers and Trends From APWG, Verizon, FTC, and IC3
- How Smishing Converts: From Delivery to Financial Loss
- The Most Common Smishing Lures and Which Sectors They Hit Hardest
- Priority Defenses and Metrics Security Leaders Should Adopt Now
- How to Evaluate Smishing Statistics Before You Rely on Them
- How SmishAlert’s Reporting Closes Visibility Gaps in the Data
- Turning These Statistics Into a Pilot
- FAQ
- Sources
Executive Summary: Key 2026 Smishing Statistics
Security leaders building a briefing deck need numbers they can defend in front of a budget committee. The figures below come from primary sources and are grouped by what they actually measure, because conflating volume, conversion, and loss data is one of the most common ways smishing statistics get misused.
Volume and growth
- Contributor reports tracked by APWG show smishing increasing by roughly 40% from Q1 to Q2 2026, alongside a broader rise in phishing volumes across the first half of the year.
- Telephone-based fraud, which APWG tracks as a combined category of voice and text scams, rose notably in the same period, reflecting attackers’ shift toward channels outside traditional email gateways.
- The FBI’s IC3 2025 Annual Report places smishing within broader phishing and spoofing complaint categories, which remain among the largest complaint types the bureau tracks.
Conversion and loss
- The FTC reported $470 million in consumer losses to text scams in 2024, a fivefold increase over 2020.
- The share of FTC text-scam reports that resulted in monetary loss rose from 5% in 2020 to 11% in 2024, meaning conversion to loss is climbing even in periods when raw report counts fluctuate.
- The 2026 Verizon DBIR found the human element present in 62% of breaches, with social engineering accounting for 16% of breaches overall.
- Verizon’s mobile-centric phishing simulations produced a median click rate about 40% higher than equivalent email simulations, a gap that matters directly for risk modeling.
Sector and targeting signals
- APWG’s Q2 2026 report notes growth in social media and SMS as delivery vectors, with sector targeting shifting toward telecom and SaaS or webmail providers.
- FTC data identifies fake delivery notifications and bogus job offers among the top text-scam lures, both of which exploit routine employee and consumer behavior rather than technical vulnerabilities.
What this means operationally: the gap between email-reported phishing metrics and actual mobile exposure is widening, and dashboards built only on email telemetry are undercounting the problem.
Key Numbers and Trends From APWG, Verizon, FTC, and IC3
Each of these four sources measures a different slice of the smishing problem, and none of them, alone, gives a complete picture. Treating them as interchangeable is a common analytical mistake that leads to either overstated or understated risk assessments.
APWG’s quarterly trends reports track phishing activity contributed by member organizations, including brand abuse and phishing site takedowns. The Q1 2026 report documented rising phishing totals in early 2026 alongside a measurable increase in telephone-based fraud, the category that groups vishing and smishing together. By the time the Q2 2026 report was published, contributor data showed smishing reports up roughly 40% quarter over quarter, with social media and SMS cited explicitly as growing delivery vectors. This telemetry reflects what contributing organizations observe and report, not a census of every smishing attempt sent globally, so absolute totals should be read as directional trend signals rather than exhaustive counts.
Verizon’s 2026 Data Breach Investigations Report approaches the problem from the breach-investigation side rather than raw message volume. That gap suggests employees who have been trained for years to scrutinize email links apply less skepticism to a text message, even when the underlying social engineering technique is identical.
The FTC’s consumer-complaint data captures a different population entirely: people who reported being targeted or victimized by a text scam. Its April 2025 release found that consumers lost $470 million to text-message scams in 2024, a fivefold increase since 2020, while explicitly cautioning that reported losses understate total harm because many victims never file a report. The companion data spotlight adds a conversion metric that deserves more attention than it gets: the share of text-scam reports involving any monetary loss rose from 5% in 2020 to 11% in 2024. That trend line, loss conversion rather than report volume, is arguably the more important number for a security team trying to judge whether text-based fraud attempts are getting more effective.
IC3’s 2025 Annual Report rounds out the picture with FBI complaint data, but it groups phishing and spoofing into a single category that spans email, voice, and text. IC3 figures are useful for understanding the scale of impersonation and fraud complaints the bureau receives, but they cannot be treated as a smishing-specific denominator since the category is not broken out by channel.
| Source | What it measures | 2026 headline figure |
|---|---|---|
| APWG Q1/Q2 2026 | Contributor-reported phishing and telephone-based fraud | Smishing reports up roughly 40% Q1 to Q2 2026 |
| Verizon DBIR 2026 | Breach investigation data and phishing simulations | Human element in 62% of breaches; mobile simulation click rate about 40% higher than email |
| FTC text-scam data | Consumer-reported losses to text scams | $470 million lost in 2024, a fivefold increase over 2020 |
| IC3 2025 report | FBI complaint counts across phishing and spoofing categories | Phishing and spoofing remain among the largest complaint categories tracked |
For teams building internal visualizations, the practical guidance is straightforward:
- Plot APWG and FTC trend lines separately rather than summing them into a single “phishing” figure, since their populations and methods differ.
- Use channel-labeled funnels (delivered, clicked, credential submitted, loss) instead of a single conversion percentage.
- Build sector heatmaps from APWG’s targeting data rather than IC3’s complaint categories, which are not broken out by channel.
How Smishing Converts: From Delivery to Financial Loss
Raw message counts tell a security team almost nothing about actual risk. What matters is the funnel: how many delivered messages get clicked, how many clicks lead to credential submission, how many submissions result in an MFA bypass attempt, and how many of those convert to measurable loss. Each stage compresses the population further, and the compression ratio is where the real signal lives.
Verizon’s mobile-centric simulation data is the clearest conversion benchmark available: median click rates on mobile-oriented phishing simulations ran about 40% higher than equivalent email simulations. The report groups voice and text together in parts of its telephone-based fraud analysis, which limits how precisely the click-rate gap can be attributed to SMS alone, but the direction is consistent with what the FTC’s loss-conversion data shows independently.
That FTC data matters because it isolates a different stage of the funnel: loss per reported incident rather than click behavior. The rise from 5% to 11% in reports resulting in monetary loss between 2020 and 2024 means attackers are getting better at moving targets from initial contact to financial harm, not just getting louder. IC3’s complaint and loss totals add scale context but cannot be broken into a text-specific loss-per-message figure, since its categories span multiple channels.
For a security dashboard, the following conversion metrics matter more than aggregate message volume:
- Delivery rate by channel, tracked separately for SMS, iMessage, and third-party messaging apps rather than lumped into a single mobile category.
- Click-through rate, benchmarked against the mobile-versus-email gap Verizon documented rather than assumed equal to email baselines.
- Credential submission rate, which indicates how often a click actually results in data exposure rather than a bounce.
- MFA bypass attempts, which signal attackers moving beyond simple credential theft into session hijacking or real-time phishing kits.
- Time-to-report, measuring how quickly an employee or customer flags a suspicious message after receipt, a metric that directly affects how fast a campaign can be contained.
- Escalation rate, the share of reported messages that trigger a formal incident response versus those closed as noise.
Pro Tip: Label every smishing metric by channel, population, and collection method before it goes into a dashboard. A number that silently blends voice, SMS, and email will mislead the people making budget decisions from it.
The Most Common Smishing Lures and Which Sectors They Hit Hardest
Attackers do not need novel techniques when routine business processes already give them cover. FTC’s coded top text-scam categories show the same handful of lures repeating year over year, each one tuned to exploit a predictable human response.
- Fake delivery notifications remain one of the most reported lures, exploiting the near-universal experience of expecting a package and prompting a quick, low-scrutiny click.
- Bogus job offers and task scams target people actively looking for income, often escalating into advance-fee fraud or money mule recruitment once initial trust is established.
- Fraud alert impersonation, where a message appears to come from a bank or payment provider, exploits urgency and often leads directly to credential harvesting on a spoofed login page.
- Unpaid toll notifications have become a recurring lure, combining a small, plausible dollar amount with a short deadline to discourage verification.
- Wrong-number messages frequently serve as an opening move in longer-running pig butchering or relationship-based investment scams, starting low-pressure before escalating over days or weeks.
APWG’s sector data shows targeting concentrated in telecom, financial services, and SaaS or webmail providers, largely because these sectors sit at the center of identity verification and account recovery workflows that attackers want to compromise. A stolen telecom credential, for instance, can enable SIM swap attacks that defeat SMS-based MFA entirely.
Inside an organization, these lures map directly onto specific attack surfaces. Fake delivery and fraud-alert lures tend to hit general employee populations and customer bases alike, which is why customer and member reporting channels matter as much as employee-facing ones. Job and task scams disproportionately target HR and recruiting workflows. Executive impersonation and fraud-alert styled messages concentrate on finance and payroll teams, where a convincing urgent request can trigger a wire transfer or payroll redirection before anyone verifies the sender. Control owners in each of these functions should treat smishing reporting as part of their own operational risk picture, not solely a security team concern.
Priority Defenses and Metrics Security Leaders Should Adopt Now
The data points to a clear operational gap: mobile messaging carries rising volume and rising conversion risk, but most security programs still instrument email far more thoroughly than SMS, iMessage, or other messaging channels. Closing that gap requires both new controls and new measurement discipline.
- Stand up a frictionless reporting channel for employees first, since time-to-report is one of the strongest levers for containing a campaign before it spreads across an organization.
- Extend reporting to customers and members, not just staff, since FTC data shows consumers are a primary target population for text scams and organizations that never see those reports lose critical early warning signal.
- Add on-device filtering or analysis for high-risk users, particularly executives and finance staff, where impersonation lures carry outsized financial consequences.
- Harden MFA against SMS-based bypass, moving toward app-based or hardware authentication where feasible, since smishing increasingly targets the same credential-and-code flow that SMS MFA depends on.
- Feed mobile threat reports into the SIEM, so a smishing campaign targeting ten employees shows up as a correlated event rather than ten disconnected help desk tickets.
- Build an incident reporting template specific to messaging-based social engineering, distinct from email phishing playbooks, since attacker infrastructure, lure timing, and escalation paths differ.
Dashboards should track time-to-detect a campaign (not just a single message), the percentage of employees who report versus simply delete or ignore a suspicious text, and loss-per-reported-incident as a conversion metric rather than raw volume.
When building the budget case, the strongest justification is the combination of rising conversion (FTC’s move from 5% to 11% loss conversion) and the mobile-specific click-rate gap Verizon documented. Procurement will reasonably ask for a pilot period with defined success metrics: number of campaigns detected that email security missed entirely, median time-to-report before and after deployment, and reduction in help desk tickets tied to unresolved suspicious messages. A 30-day pilot structure, common in this product category, gives enough time to observe at least one real campaign cycle without committing to a full annual contract upfront.
Pro Tip: Treat the pilot period itself as a data-collection exercise. The campaigns detected during a 30-day window often become the clearest internal evidence for budget approval, more persuasive than any external statistic.
How to Evaluate Smishing Statistics Before You Rely on Them
Not every smishing statistic deserves equal weight, and treating them interchangeably is one of the easiest ways to misjudge risk. Before citing a figure in a risk assessment or board presentation, check how it was collected.
Consumer complaint data, like the FTC’s, reflects self-reported incidents and explicitly undercounts actual activity since many victims never file a report. Contributor telemetry, like APWG’s, reflects what member organizations observe and submit, which skews toward sectors and regions with strong reporting relationships rather than a representative global sample. Breach investigation data, like Verizon’s, reflects confirmed incidents that reached the investigation stage, which excludes the much larger population of attempts that were blocked, ignored, or never escalated. Each method has a legitimate use, but none of them is a census.

Channel grouping is another common source of distortion. APWG’s telephone-based fraud category combines voice and text, which means a reported increase could reflect vishing, smishing, or both, and the published figures do not always allow a clean split. Complaint categories like IC3’s phishing and spoofing classification mix email, voice, and text under one label, making it impossible to isolate a smishing-only total from that data alone.
A practical checklist for evaluating any smishing statistic:
- Confirm what channel the figure actually covers: SMS only, voice and text combined, or all social engineering regardless of channel.
- Check the reporting period and whether it reflects a full year, a quarter, or a rolling window.
- Identify the collection method: consumer complaints, contributor telemetry, or confirmed breach investigations.
- Look for an explicit under-reporting disclosure, since most primary sources acknowledge their figures are a floor, not a ceiling.
How SmishAlert’s Reporting Closes Visibility Gaps in the Data
Public statistics from the FTC, APWG, Verizon, and IC3 establish that smishing volume and conversion are both rising, but none of them give a single organization visibility into what is actually landing in its own employees’ or customers’ message inboxes. That gap, between population-level trend data and organization-specific telemetry, is exactly where enterprise reporting and correlation tools are designed to operate.
This platform is designed to address that gap rather than treating smishing solely as a consumer awareness problem. Its capabilities demonstrate what such a platform needs to do to convert public trend data into actionable organizational signals:
- Collect suspicious messages from employees and high-risk users without requiring a separate awareness campaign to drive adoption.
- Enable customers, members, and students to report suspicious text messages without installing an app, extending visibility beyond the employee population that most mobile security tools stop at.
- Analyze reported messages and senders for known attack patterns, including executive impersonation, credential phishing, payroll fraud, and brand impersonation.
- Correlate reports across a user population to identify coordinated campaigns that would otherwise appear as isolated, unrelated incidents.
- Integrate with enterprise security infrastructure, giving security teams a path to feed messaging-based threat data into existing SIEM and incident response workflows.
In practitioner terms, organizational reporting shortens the gap between when a campaign starts and when a security team notices it. A public dataset like APWG’s can confirm that telephone-based fraud is rising industrywide months after the fact; an internal reporting channel can surface the same campaign the week it starts, with enough context (sender number, message content, targeted department) to support immediate triage. That combination, public trend data for strategic planning and internal telemetry for operational response, is what a mature mobile messaging security program needs.
Turning These Statistics Into a Pilot
The numbers in this briefing point to one operational conclusion: mobile messaging has become a measurable, growing share of the social engineering problem, and most organizations still lack the reporting infrastructure to see it clearly. Closing that gap does not require replacing an existing email security stack. It requires adding a channel-specific reporting and correlation layer that covers employees, customers, and members alike, which is the visibility gap SmishAlert is built to close.
For security teams ready to move from statistics to operational coverage, the SmishAlert product page outlines how detection, investigation, and campaign correlation work together for enterprise deployments, and the threat intelligence page shows live campaign examples that illustrate how reporting and correlation surface coordinated attacks in practice.
Before scoping a pilot, three questions are worth raising directly with sales or engineering:
- What message channels and user populations does coverage actually include: employees only, or customers and members as well?
- How does reported data flow into existing reporting and incident response workflows?
- What does SIEM and IR system integration look like during and after the pilot period?
Organizations evaluating this category typically start with a paid 30-day pilot, with the pilot fee credited toward the first annual subscription if the team moves forward. For readers building out a broader defense strategy, SmishAlert’s answers library covers related questions on employee protection, customer reporting, and campaign response in more depth.
FAQ
What are the expected phishing statistics for 2026?
Early 2026 data from APWG shows phishing volumes rising, with smishing reports up roughly 40% from Q1 to Q2 2026 within contributor telemetry. The Verizon DBIR 2026 adds that the human element remains present in 62% of breaches, reinforcing that social engineering, across channels, stays a dominant attack method.
Is it true that most cyberattacks start with phishing?
Phishing and social engineering are consistently among the most common entry points in breach investigations, and Verizon’s 2026 DBIR found the human element present in 62% of breaches analyzed. A specific claim that a fixed share of “all cyberattacks” begin with phishing is not supported by a single authoritative figure, so it is more accurate to say social engineering is a leading, well-documented factor rather than citing one universal percentage.
What are the latest statistics on phishing?
The clearest recent figures come from primary sources tracking different parts of the problem: the FTC reported $470 million in consumer losses to text scams in 2024, while APWG’s Q1/Q2 2026 reports documented rising phishing totals and a roughly 40% quarter-over-quarter increase in smishing reports. Each figure measures a different population and method, so they should be cited separately rather than combined into one number.
How common is smishing compared to email phishing?
Smishing has grown fast enough that contributor telemetry now tracks it as a distinct, rising category rather than a minor offshoot of email phishing, with APWG reporting a roughly 40% increase in smishing reports between Q1 and Q2 2026.
Sources
- 2026 Data Breach Investigations Report (Verizon DBIR)
- New FTC data show top text message scams of 2024; overall losses to text scams hit $470 million
- Consumer protection data spotlight: Top text scams of 2024 (FTC)
- APWG Trends Report Q1 2026
- 2025 IC3 Annual Report