
Smishing: Why your customers no longer trust SMS

Reading time: 15 min
SMS has become an essential channel for customer relations. Order confirmation, delivery tracking, appointment reminders, authentication codes, security alerts, or promotional offers: brands use it to quickly transmit information that will generally be viewed on a mobile phone.
This proximity is also its main weakness. Because a text message seems direct, personal, and sometimes urgent, it offers fraudsters a particularly favorable environment. Smishing , a portmanteau of SMS and phishing , hijacks the codes of legitimate communications to steal information, take control of an account, or trigger fraudulent payments.
Beyond cybersecurity, this phenomenon represents a real martech challenge . It affects the trust placed in messages, the reputation of senders, the performance of campaigns and, more broadly, the quality of the relationship between a brand and its customers.
What is smishing?
Smishing is a phishing technique spread via SMS or mobile messaging. A fraudster impersonates a well-known organization to trick the recipient into performing a dangerous action.
The message may seek to achieve:
- login credentials;
- a password;
- a bank card number;
- a one-time authentication code;
- personal information;
- a payment;
- the installation of a malicious application.
Cybermalveillance.gouv.fr defines smishing as sending a short message under a false identity and a false pretext, intended to push the victim to communicate personal, banking or login credentials.
Smishing therefore belongs to the phishing family. What distinguishes it is not necessarily the method of fraud employed, but the channel used to establish the first contact with the victim.
" Amateurs hack systems; professionals hack people. "
Bruce Schneier — American cryptographer, researcher, author, and cybersecurity expert
An attack based on social engineering
Smishing rarely exploits a technical vulnerability in the phone. Its effectiveness relies primarily on social engineering , that is, the manipulation of human behavior.
The fraudster seeks to create a situation in which the recipient acts before thinking . The message gives them the impression that an important event has just occurred and that an immediate response is required.
The most common scenarios include:
- a package that could not be delivered;
- an unusual or refused payment;
- an account that is reportedly about to be suspended;
- a bank card that was allegedly blocked;
- an unpaid toll, bill or fine;
- a refund to be claimed;
- a subscription renewal;
- a job offer;
- a gift or reward to collect.

These pretexts evolve according to current events, consumer habits, and commercial periods. A campaign can thus be adapted to sales periods, the end-of-year holidays, a tax filing period, or a mass delivery campaign.
In France, cybermalveillance.gouv.fr has also observed deliberately innocuous text messages, such as "Hello, are you home?". The aim is to obtain an initial response in order to start a conversation or to bypass mechanisms that block links from unknown numbers.
The typical course of an attack
A smishing attack usually begins with a message that appears to originate from a well-known company, government agency, bank, or service.
The SMS then contains a request for action. It may invite the recipient to click on a link, reply to the message, call a number, or install an application.
When a link is used, it often leads to a site that mimics the visual identity of the impersonated organization. Logo, colors, typography, login form, and reassuring statements are reproduced to make the fraud seem credible.
The fake website may ask for several pieces of information in succession:
- the client's identity and contact details;
- his/her login credentials;
- his bank details;
- a code received by SMS;
- the validation of an alleged security operation.
This progression allows the fraudster to gather enough data to access an account, make a transaction, or prepare a second phase of the attack.
The text message may also be followed by a phone call. A fake advisor then claims to intervene to secure the victim's account. In this case, smishing is combined with vishing , or voice phishing.
Why does SMS still inspire trust?
Email has long been associated with spam and phishing. Internet users have learned to be wary of attachments, unknown senders, and messages promising improbable winnings.
Text messaging retains a different perception. It is often associated with more personal communication, a real event, or a recent action. It also benefits from high visibility: the message appears directly on the lock screen and can trigger an immediate notification.
Several features enhance its effectiveness against fraudsters.
A quick read
The message is usually read in a few seconds, in a context of mobility or shared attention. The recipient may be commuting, at work, or performing another task.
He then checks the website address, sender's number, or the consistency of the request less carefully.
A small screen
Mobile screens don't always display the entire URL . Distinguishing between an official domain and a deceptive one becomes more difficult.
A fraudster might, for example, use a domain name containing the brand name, accompanied by reassuring words like secure , client , validation or support.
Incomplete sender identification
A typical SMS message mainly displays a number or alphanumeric identifier. For the user, it can be difficult to know if this identifier actually corresponds to an authorized company.
The GSMA points out that this limited identification makes it difficult for customers to distinguish between official communications and fraudulent messages. ( GSMA )
A culture of immediacy
Transactional messages have accustomed consumers to acting quickly: validating a connection, confirming an appointment, tracking a delivery, or using a temporary code.
Fraudsters adopt this logic in order to transform a useful habit into an exploitable reflex.
The psychological mechanisms of smishing
Smishing works because it stages an emotion strong enough to interrupt the recipient's normal reasoning.
- The urgency He makes him believe that he only has a few minutes to act.
- La fear is used to refer to bank fraud, account blocking, a sanction, or a debt.
- The authority is based on the usurpation of a bank, an administration, an operator or an employer.
- La curiosity can be stimulated by an incomplete message: a photo received, an unknown payment or a request made without context.
- La reward takes the form of a gift, a refund, a job, or a promotion.
- Finally, the familiarity is achieved by reproducing the vocabulary and communication habits of a well-known brand.
The objective is always the same: to reduce the time available between reading the message and the recipient taking action.

A threat with very real consequences.
The losses associated with SMS scams are difficult to measure, as not all victims report them. However, available data shows that their economic impact can be considerable.
In the United States, the Federal Trade Commission recorded $470 million in reported losses in 2024 from scams that began with text messages . This amount was more than five times higher than that reported in 2020, even though the number of reported cases had decreased. ( Federal Trade Commission )
Fake bank messages, fictitious delivery problems, fraudulent job offers, and toll payment requests are among the scenarios regularly observed. ( Federal Trade Commission )
Immediate financial loss is, however, only one possible consequence. An attack can also lead to:
- hacking a customer account;
- identity theft;
- the theft of a contact database;
- the compromise of an email system;
- the installation of malicious software;
- the hijacking of a phone number;
- the reuse of information in other frauds.
Data obtained during an initial attack can be enhanced and resold. A victim who has simply provided their name, phone number, and bank details can then receive a much more personalized message.
Why is smishing a martech topic?
Smishing lies at the intersection of cybersecurity, mobile marketing, data governance, and customer experience.
A company can perfectly secure its infrastructure while still suffering the effects of a fraudulent campaign conducted in its name. The fraudster doesn't necessarily need to hack the brand; they simply need to imitate its identity.
This usurpation produces several effects.
A decline in trust
When a consumer regularly receives fake messages attributed to a bank, carrier, or platform, they naturally become more suspicious.
This caution can then extend to the brand's actual communications. Even a legitimate text message can be ignored, deleted, or flagged.
A decline in marketing performance
Distrust can reduce click-through and conversion rates for campaigns. It can also limit the effectiveness of transactional messages, especially when the customer refuses to follow a necessary link.
Smishing thus creates a debt of trust : companies must devote more effort to proving the authenticity of their own communications.
An increase in customer service requests
Customers who encounter a suspicious message can contact support to verify its origin. A major fraud campaign can therefore lead to a sudden surge in calls, emails, and conversations with customer service representatives.
Teams must be able to quickly identify the campaign, respond consistently, and explain the procedure to follow.
A risk to the brand's reputation
The victim does not always distinguish between the responsibility of the fraudster and that of the company whose products were imitated. They may believe that the brand did not adequately protect their identity, data, or communication channels .
Reputation can therefore be affected even when the company has not suffered any direct intrusion.
Short links at the heart of the trust problem
Shortened links have a clear advantage in SMS messages: they limit the number of characters, simplify the layout, and often allow clicks to be measured.
However, they have one major flaw: they mask the true destination of the link.
A public and generic URL shortener does not allow the recipient to immediately know if the site belongs to the brand. This uncertainty reproduces one of the most common characteristics of smishing.
This doesn't mean all short links should be banned. A brand can use a custom short domain , clearly linked to its identity and reserved for its campaigns. The benefit is twofold: measurement remains possible, while the recipient receives an additional signal of recognition.
The domain must, however, be consistent, stable, and used regularly. Using multiple tracking domains, redirects, or providers makes communication more difficult to verify.
Inset — Best practices for trustworthy SMS campaigns
SMS marketing and trust
Best practices for reassuring SMS campaigns
An effective SMS should allow the recipient to immediately identify who is writing to them , why they are receiving the message and how to verify its authenticity.
Clearly identify the brand
Include the organization's name at the beginning of the SMS. Don't rely solely on the sender's name displayed by the phone.
Recall the context
Explain why the message is being sent: order, appointment, registration, or request initiated by the customer . Avoid vague and anxiety-inducing alerts.
Use a recognizable domain
Opt for the brand's official domain or a custom short domain. Public domain shorteners obscure the destination and can inspire mistrust.
Never ask for sensitive data
No SMS should ask for a password, cryptogram, full card number or the communication of an authentication code to an advisor.
Propose an independent verification
For a sensitive transaction, invite the customer to open the official application directly or to log in to their usual space.
Maintain editorial consistency
Consistently maintain a consistent tone, signature, subject matter, and message structure. This consistency helps clients recognize legitimate communications.
Establish a reporting channel
Indicate in your help center how to verify an SMS and where to forward a suspicious message using your brand name.
Testing trust as much as clicks
A variant generating slightly fewer clicks may be preferable if it better protects trust and long-term customer relationships.
The three-question rule: the customer must be able to determine immediately who is writing to them, why they are receiving the message, and how they can verify its authenticity without taking any risks.
RCS and verified senders: part of the answer
RCS, or Rich Communication Services , allows businesses to enrich mobile conversations with images, buttons, visual identity and, in some environments, a verified sender.
This verification can facilitate the identification of official communications. The GSMA , in fact, presents sender verification as one of the mechanisms for proving brand identity in RCS business messages.
However, RCS does not eliminate all risks. A richer interface can also become very persuasive when misused. Security must therefore rely on several layers: sender verification, domain control, campaign monitoring, customer education, and response procedures.
Artificial intelligence: a threat and a means of defense
Generative artificial intelligence allows fraudsters to quickly write credible messages, without apparent errors and adapted to different languages.
It also facilitates the creation of numerous variations of the same campaign. Messages can be modified to bypass filters based on keywords or known patterns.
When combined with compromised data, AI can help personalize attacks: person's name, employer, supposed bank, supplier, or recent event.
At the same time, operators and security vendors are using artificial intelligence to analyze sending volumes, sender behavior, and links within messages. Some solutions even compare received URLs with databases of malicious domains to warn users.
The fight against smishing thus becomes a confrontation between the industrialization of fraud and the automation of detection.
How to recognize a potentially fraudulent SMS?
No single indicator can definitively prove that a message is fraudulent. However, the combination of several signs should prompt caution.
A message is particularly suspicious when it:
- announces an unexpected situation;
- requires an immediate response;
- threat of a sanction;
- request for confidential information;
- uses a link whose domain is difficult to identify;
- prompts you to install an application from outside of an official store;
- request to provide a code to an advisor;
- contains an operation that the recipient never initiated.
The absence of spelling mistakes does not guarantee the authenticity of a message. Current campaigns can be well-written and accurately reflect an organization's tone.
Similarly, the name displayed as the sender should not be considered absolute proof.
How should I react to a suspicious text message?
The recipient must not click on the link or reply to the message. They must also not call the number indicated in the SMS.
To perform a verification, it is best to use the official application, enter the known website address yourself, or contact the organization using independently obtained contact details.
In France, suspicious SMS and MMS messages can be forwarded or reported to 33700 , a free service dedicated to combating unwanted and fraudulent messages.
A screenshot of the message, sender's number and destination site can be kept as evidence.
What should I do after clicking?
A single click does not automatically mean that the phone or account is compromised. The actions to be taken depend on the specific action performed.
When login credentials have been entered, the affected password must be changed immediately from a secure device. Other accounts using the same password must also be protected.
When banking details have been disclosed, the bank must be contacted immediately using its official contact information. Blocking the transaction and increased monitoring of transactions may be necessary.
When a security code has been transmitted, the associated account should be considered potentially compromised.
If an application has been installed, it must be removed and the device checked. In a professional environment, the incident must be reported immediately to the IT or security team, even if no consequences are yet apparent.
Towards a mobile trust-based governance
Combating smishing cannot rely solely on user vigilance. It requires cooperation between telecom operators, messaging platforms, advertisers, martech providers, financial institutions, and public authorities.
Operators are developing mechanisms for spam detection, link analysis, and combating sender ID spoofing. However, the GSMA emphasizes that preventing fraud requires shared responsibility across the entire digital ecosystem.
Brands also have a role to play. By standardizing their domains, limiting opaque links, explaining their practices, and facilitating reporting, they make imitation attempts more visible.
Conclusion
Smishing hijacks a channel designed to simplify and accelerate communication. By mimicking transactional messages, security alerts, and marketing campaigns, fraudsters exploit habits that brands themselves have helped to establish.
For marketing and customer relationship professionals, the challenge therefore goes beyond fraud detection. It's about preserving SMS's ability to remain a useful and credible channel.
A successful campaign shouldn't just aim for clicks. It should allow the recipient to clearly identify the sender, understand the context of the message, and verify its authenticity without taking any risks.
Trust is now a key performance indicator in mobile marketing. Excessive sales pressure, an opaque connection, or artificial urgency can temporarily improve click-through rates, but ultimately damage customer relationships.
In an environment marked by smishing, the best practice is ultimately never to ask the customer to choose between caution and conversion.
Some references
- « “Smishing” or SMS phishing " — Cybermalveillance.gouv.fr, GIP ACYMA — June 2023.
- « Phishing in 2025: a predominant threat to all audiences " — Cybermalveillance.gouv.fr, GIP ACYMA — June 2026.
- « What to do in case of phishing? " — Cybermalveillance.gouv.fr, GIP ACYMA — version consulted in July 2026.
- « New FTC Data Show Top Text Message Scams of 2024 » — Federal Trade Commission — April 2025.
- « Implementing Phishing-Resistant MFA — Cybersecurity and Infrastructure Security Agency — version accessed in July 2026.cisa.gov)
- « RCS Sender Verification Report "— GSMA — March 2019.
- « KDDI: SMS Phishing Countermeasures — GSMA — September 2025.
- « Scams: Public Policy "— GSMA — March 2026.
















