Security Glossary

What is Smishing?

Smishing is phishing delivered by SMS. Messages impersonate banks, parcel carriers, IT help desks, or executives and push victims to fake login pages or callback numbers. Mobile screens hide full URLs, which makes hasty taps especially dangerous.

How a Smishing Attack Works

1

Harvest phone numbers and roles

Staff directories, conference apps, and data brokers supply mobile numbers tied to job titles.

2

Craft a time-sensitive text

Delivery failures, payroll issues, and MFA resets are common pretexts because they feel urgent.

3

Capture credentials or codes

A mobile-optimized fake portal collects passwords and one-time codes.

4

Pivot to email or finance systems

Stolen sessions open the door to BEC or account takeover.

Real-World Example

Finance staff at a mid-market firm received texts claiming their ACH batch failed, referencing the real payroll provider name scraped from a careers page. Several entered credentials on a lookalike mobile site within minutes.

How AiVERSARY Detects Smishing Risk

AiVersary highlights which employees and public channels make SMS pretexts easy to personalize — so you can prioritize who needs stricter verification habits.

Is your organization exposed to smishing?

AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.

Get Your Threat Report

Related Terms

Vishing

Vishing — short for "voice phishing" — is when attackers use phone calls instead of emails to manipulate people into sharing sensitive information or taking harmful actions. Phone calls create a sense of immediacy and personal connection that emails can't match, and they bypass all of your email security filters. With AI voice cloning now widely available, attackers can even impersonate specific people your team knows and trusts.

Spear Phishing

Spear phishing is a targeted email attack where criminals research a specific person and craft a message designed just for them. Unlike mass spam, these emails reference real details about your job, your colleagues, or recent company events to appear legitimate. They are the number one way attackers breach organizations today.

MFA Fatigue

MFA fatigue is an attack where a criminal who already has your password repeatedly triggers multi-factor authentication prompts — the push notifications on your phone — until you approve one just to make them stop. It exploits the very security measure designed to protect you by turning it into an annoyance that people instinctively dismiss. This technique has been used in several high-profile breaches.

Credential Stuffing

Credential stuffing is when attackers take usernames and passwords leaked from one breach and automatically try them on other services. Because most people reuse passwords, a breach at a shopping site or social network can give attackers working credentials for your corporate email, VPN, or cloud platforms. It is automated, fast, and alarmingly effective.