← Blog

$470M Lost: SMS to Email Phishing Tactics for Security Teams

$470M Lost: SMS to Email Phishing Tactics for Security Teams

Smishing is SMS phishing designed to steal credentials, extract payment, or install malware on a device through a text message. If a text asks you to click a link, verify an account, or confirm a payment, the correct response is to avoid the link, contact the organization through a number or website you already trust, and forward the message to 7726 if it looks fraudulent. Texts get opened within minutes of arrival, which is exactly why attackers favor this channel.


TL;DR:

  • Most smishing attacks rely on urgent language and unfamiliar URLs, often linked to fake login pages or malicious apps impersonating legitimate services.
  • Attackers use email-to-text gateways and spoofed numbers to hide their identity, making detection difficult and enabling scale.
  • Forward suspicious messages to 7726 and verify with official sources before clicking links or replying, as replying confirms your number is active.
  • Switching to authenticator apps or hardware keys for multi-factor authentication reduces the risk of credential theft via SMS intercepts.
  • Security teams need to implement reporting and analysis tools for text-based social engineering to close the visibility gap that existing email-focused defenses overlook.

SmishAlert
Close Your Mobile Visibility Gap
SmishAlert helps security teams collect, analyze, and correlate suspicious messages to identify coordinated social engineering campaigns.
Talk to the SmishAlert Team

Table of Contents

What smishing is and why SMS works as an attack vector

Smishing messages typically route victims to credential-phishing pages that mimic a bank, delivery service, or employer, or they push a malicious app disguised as tracking software. Some skip the link entirely and start a live text conversation designed to build trust before asking for money or account access.

Three smishing attack paths from text

The channel works because people treat texts as more urgent and more personal than email, and they act on them faster. Attackers have noticed. Consumers reported losing $470 million to scams that started with text messages in 2024, a significant increase from 2020. Fake package deliveries and fraud alerts were among the most common lures. Separately, imposter scams overall, many of which start with a text, accounted for $3.5 billion in reported losses in 2025. Email security tools do not see any of this traffic, which is the core visibility problem organizations now face.

How attackers exploit email-to-text gateways and spoofed numbers

The “SMS to email phishing” pattern usually refers to messages that originate from email infrastructure but land in a phone’s native messaging app, or to phishing pages that a text links out to. A few mechanisms make this possible and hard to trace:

  • Email-to-text gateways let a sender deliver a message to a phone number using only an email address, which the FCC has identified as a route for anonymous and hard-to-attribute scam texts.
  • Reassigned or spoofed phone numbers let attackers impersonate a legitimate short code or a colleague’s number, since caller ID and sender ID are not authenticated the way domain records can be.
  • Stolen or abused API keys tied to legitimate bulk messaging platforms let attackers send at scale while borrowing a sender’s reputation.
  • Chained campaigns move a target from a text to a spoofed login page, then to a follow-up email or social media message, reinforcing the same lure across channels for credibility.

The FCC’s Second Report and Order now requires terminating wireless providers to block texts from numbers identified as sources of illegal messaging, a direct response to these gateway and spoofing abuses.

Signs a text is a phishing attempt

Most smishing messages share a handful of traits once you know what to look for.

  1. An unsolicited link paired with urgent language about a suspended account, missed delivery, or unpaid toll.
  2. A request for a password, one-time passcode, or payment card number sent directly by text.
  3. A sender ID that looks like an email address, a random long number, or a short code that does not match the organization’s known number.
  4. A shortened or unfamiliar URL that hides the real destination domain.
  5. Small mismatches: wrong company name, odd punctuation, or a generic greeting instead of your name.

A few realistic examples: “Your package could not be delivered. Confirm your address here,” “We noticed unusual sign-in activity, verify your identity now,” “Your subscription payment failed, update billing,” “You have a toll violation, pay now to avoid fees,” and “Your direct deposit was rejected, update your info.” None require a click to make sense as a phone call or a login through the official app instead.

Pro Tip: Check the sender field before the message content. A legitimate bank or delivery service almost always texts from the same short code every time, never a shifting long number.

What to do immediately and how to report a suspicious SMS

The moment a text looks off, the sequence matters more than any single step.

  • Stop before tapping anything. Do not click the link, call a number in the message, or reply, since replying can confirm your number is active.
  • Screenshot the message so you have a record if you need to report it or show it to your IT or fraud team.
  • Verify independently by calling the organization at a number from its official website or your existing account statements, never a number supplied in the text.
  • Forward the message to 7726 (SPAM), which routes it to your carrier for filtering, and use the built-in report function in the Messages app on Apple or Android devices.
  • File a report at ReportFraud.ftc.gov if the message involves a financial request or looks like a scam, and notify your employer’s IT or security team if the text referenced work systems, payroll, or a company executive.
  • Block the sender and confirm your carrier’s spam filtering is turned on.

This reporting habit matters at scale. The FTC’s own consumer guidance treats forwarding to 7726 as a frontline defense, since it feeds carrier filtering systems that block similar messages before they reach other people.

Longer-term protections and defensive hygiene

A single good response to one text does not fix the underlying exposure. A few durable changes reduce risk over time.

  • Switch account recovery and multi-factor authentication away from SMS codes and toward an authenticator app or a hardware security key, since SMS codes can be intercepted or socially engineered out of a victim.
  • Keep the phone’s operating system and messaging apps current, since patches often close the vulnerabilities smishing payloads try to exploit.
  • Restrict which apps can be installed outside official app stores, and review app permissions periodically.
  • For organizations, build a formal reporting workflow so employees have one clear place to send a suspicious text, rather than guessing whether to call IT, forward it, or ignore it.
  • Treat mobile messaging as part of the enterprise attack surface, not a personal device issue, and route confirmed smishing reports into the same incident response process used for email phishing.

Email security stacks, spam filters, and security awareness training were all built around a channel attackers are increasingly bypassing. None of them see a text message.

Closing the visibility gap in messaging-based social engineering

Security teams that have solved email phishing visibility often discover they have none of it for SMS, iMessage, or other messaging apps. Attackers know this gap exists and increasingly route executive impersonation, payroll fraud, and credential-harvesting attempts through text precisely because no security tool is watching that channel.

Closing that gap requires the same building blocks used for email: a way to collect reports, analyze them, and correlate patterns across a population of users. SmishAlert was built around that requirement:

  • Frictionless reporting for employees, customers, members, and students, without requiring an app install for constituent-facing use cases.
  • Automated analysis of reported messages and senders for executive impersonation, credential phishing, payroll fraud, and brand impersonation.
  • Cross-user correlation that flags coordinated campaigns rather than treating each report as an isolated incident.
  • On-device filtering and reporting for managed and BYOD devices.

Security teams should triage incoming reports the way they triage email phishing submissions: confirm the pattern, check for related reports across the organization, and feed confirmed campaigns into SIEM and incident response playbooks rather than closing each ticket in isolation. More detail on this approach is available in SmishAlert’s guidance on phishing and smishing for enterprise security teams.

Sources

FAQ

Can someone hack my phone through SMS?

A text alone rarely compromises a phone, but a malicious link inside it can lead to a phishing page or trigger a malware download if you tap through and grant permissions. The greater risk is usually credential theft rather than a direct device hack, which is why avoiding the link matters more than any antivirus setting.

Can I get scammed if I respond to a text message?

Yes. Replying confirms your number is active and monitored, which can invite follow-up scam attempts, and if the reply includes personal or account information, that data can be used directly for fraud. The safer move is to avoid replying and instead verify the claim through a known, independent channel.

Is it safe to open an SMS message?

Opening a text to read it is generally safe since most smishing relies on you tapping a link or replying, not on the message simply appearing. Risk starts when you interact with a link, attachment, or reply field inside a suspicious message.

Can you give me an example of a phishing SMS?

A common example reads something like “Your package could not be delivered, confirm your address here” or “We detected unusual sign-in activity, verify your account now,” both paired with a shortened link. These mimic real delivery and account-security notifications, which is part of why they work so consistently.