Smishing in cyber security is phishing carried out over SMS text messages: a message engineered to look like the bank, a parcel carrier, the boss or the IT provider, carrying a link or a request designed to harvest a credential or move money. The word is a contraction of SMS and phishing, and the technique matters to a small organisation for one structural reason: text messages bypass every filter the organisation has. The mail gateway inspects email, the web filter inspects browsing, and the text message arrives on a personal phone with no gateway in front of it at all. That is why smishing is where a policy earns its keep rather than a product: the defence is what people are agreed to do when a message asks for a credential, a gift card or a payment change, and agreement is a written thing. This page explains how the con is built, which two policy lines blunt it, and where the free sheet on this site counts those policies into your set.
How the con is built
A smishing message manufactures urgency and authority in one or two sentences: your account is locked, the delivery failed, this is the owner and I need gift cards before the meeting. The link leads to a credential page dressed as a real login, or the reply starts a conversation that ends in a payment. The sender field proves nothing, because numbers are cheap and spoofable, and the message arrives outside business systems on a device the organisation may not manage. Everything about the technique is aimed at one person acting alone in the moment, which is exactly what a written procedure removes.
The two policy lines that blunt it
The first line belongs in the acceptable use or access policy: credentials are never entered from a link in a message, only from a bookmark or a typed address. The second belongs in the finance or payments procedure: no payment, payment change or purchase of value on the strength of a message alone, however senior the apparent sender; the request is confirmed on a known number by voice. Neither line costs anything to adopt, both survive every new variant of the con, and the free policy sheet on this site counts the documents they live in and what the set costs to draft at your own hourly figure.
What software can and cannot do about SMS
Carrier-level filtering removes some bulk smishing, and a personal device policy can require the phone's own protections on any device that touches organisational accounts, which is one of the facts the policy sheet asks about. But no product the organisation deploys inspects a personal inbox the way a mail gateway inspects email, which is why the guides on this site treat smishing as a policy and training matter first. The paid plan generates the personal device policy and the payment confirmation procedure with your names and numbers in them, and files each with a review date.
Questions people ask about what is smishing in cyber security
What does smishing mean in cyber security?
Phishing over SMS: a text message impersonating a bank, carrier, boss or IT provider, carrying a link or request built to steal a credential or move money. The name contracts SMS and phishing. It matters because texts arrive with no organisational filter in front of them.
How is smishing different from phishing?
The channel and the filter. Email phishing passes through a mail gateway that can quarantine it; a text lands directly on a phone, often a personal one. The defences are written procedure, credentials only from typed addresses, payments confirmed by voice on a known number, rather than a gateway product.
What should a small organisation do about smishing?
Adopt two lines of policy: no credentials entered from message links, and no payment or payment change on a message alone. Put them in the access policy and the payments procedure, train to them once a year, and the free sheet on this site counts those documents into your policy set.