Blog
Guide 2026-07-07 8 min read

Smishing: Fake Text Messages and How to Defend Against Them

CERT Polska blocked close to 1.9 million malicious text messages in 2025. We explain why this channel works so well, which scenarios keep repeating, and where to report a suspicious message.

Texts get opened almost always, and almost immediately. The same property that makes the channel convenient makes it effective for fraud. The decision takes seconds, on a small screen, usually on the move and with no headers to inspect.

What is smishing?

Smishing is phishing over SMS, from "SMS" and "phishing". The victim gets a short message impersonating a bank, a courier, a government body or a telecom provider, meant to prompt a click or a call back to a given number.

Compared with email the attacker holds several advantages at once. No headers to inspect. No URL preview. No corporate filter. What there is instead is trust in a channel that normally carries genuine bank notifications. It is one of the more common variants covered in our guide to types of phishing, and for a few years now it has increasingly targeted employees rather than only private individuals.

The scale in Poland

Poland has an unusually well documented picture of this, because there is a dedicated reporting channel on the number 8080. CERT Polska figures for 2025:

  • Over 350,000 messages analysed from reports sent to 8080
  • Over 80,000 identified as harmful
  • 790 smishing patterns developed and used to block campaigns
  • Around 1.88 million malicious texts blocked, 27% more than in 2024

Those 790 patterns exist because ordinary users forwarded the messages. Worth remembering, because reporting to 8080 takes about fifteen seconds and measurably shortens a campaign's life.

Why SMS is effective

This channel has properties that work in the attacker's favour:

  • Texts get opened far more often and far faster than emails
  • The short format leaves no room for details that might raise suspicion
  • Shortened links are normal here, so they do not look out of place
  • Phones rarely carry protection comparable to a corporate workstation
  • Sender IDs can be spoofed so the message drops into the same thread as genuine bank texts
  • We read them on the move, usually while doing something else

How the attack works

Phase 1

Sending the message

The attacker sends texts with a spoofed sender ID. The message can then drop into the same thread that holds genuine notifications from a bank or courier.

Phase 2

Manufacturing urgency

The content creates time pressure and a small stake. A minor parcel surcharge, a blocked account, an unpaid invoice. The amount is deliberately low, because at a low amount nobody calls to check.

Phase 3

The fake page

The link opens a page imitating a payment gateway or a bank login. On a phone the address is truncated, so a swapped domain rarely stands out.

Phase 4

Draining the account

Credentials and the authorisation code reach the attacker in real time. They then approve their own transaction instead of the surcharge on offer, usually for a much larger sum.

The most common scenarios

Campaigns recycle a handful of proven templates. Knowing them in advance handles most of the problem:

Parcel surcharge

The most common variant. A supposed courier says a small additional payment is needed to release a package. It works because at any given moment a decent share of recipients really is waiting for something.

Account blocked

The message reports a suspicious transaction or blocked access and demands an immediate login through the supplied link. It plays on fear of losing money, which shortens the time available for thinking.

Outstanding official fee

Impersonation of a government office or utility provider, citing an underpayment and threatening interest or disconnection. Effective because few people track those settlements closely.

How to recognise a fake text

A few signals filter out most fraud before any click:

  • The message contains a link and demands immediate action
  • The amount owed is suspiciously small, which is deliberate
  • The address is shortened or puts an institution's name inside an unrelated domain
  • A bank asks you to log in through a link, which in practice they never do
  • It concerns a delivery you never ordered
  • The sender shows a company name but the reply number is an ordinary mobile
  • A request to send back an authorisation code

KEY TAKEAWAYS

  • 1
    Email protection does not cover SMS, so this channel sits outside the corporate filter
  • 2
    The small amount is a technique rather than a coincidence, because nobody verifies a small amount
  • 3
    Banks never ask you to log in through a link in a message
  • 4
    Do not call back the number in the text, use the number on your card or the official site
  • 5
    Reporting to 8080 takes about fifteen seconds and measurably shortens a campaign

Where to report a fake text

Poland has a free reporting channel, and it is the source of the 790 patterns mentioned above:

  • Forward the suspicious message to 8080, the free CERT Polska reporting channel
  • Report the incident through the form at incydent.cert.pl
  • Notify your bank if the message impersonated a financial institution
  • Contact the police if money was lost
  • Inside a company, escalate to your security team or SOC
  • Keep the message and a screenshot, both help with the report

How to protect your organisation

Smishing aimed at employees is awkward, because corporate controls usually stop at the work laptop:

  • Include SMS scenarios in your phishing simulation programme instead of limiting it to email
  • Establish that company business never travels by text with a link
  • Deploy phishing-resistant authentication instead of one-time SMS codes
  • Apply security policy to phones that have access to company data
  • Give the team a fast route to report suspicious messages, including personal ones
  • Monitor the environment around the clock, for example through SOC-as-a-Service, to catch the fallout of a successful takeover
  • Warn people about active campaigns, because an alert in the right week beats a training session once a year
  • The wider picture of social engineering in finance is in our Social Engineering Report 2026

Conclusion

Smishing works not because it is sophisticated. It works because it catches a moment of inattention on a device nobody protects. As long as security in a company stops at the laptop, this channel stays open. Extending simulations to SMS is the cheapest way to check it, before someone else does.

Your firewall cannot see text messages. Your employees see all of them, and they are the ones deciding.

See how your team handles a text

Most training programmes stop at email. We also test smishing and vishing with voice cloning, the channels where employees are least prepared.

Explore Arsen

SECURE YOUR
FUTURE TODAY

Cyber threats don't sleep, and neither do we. Whether you need an immediate response to a breach or a long-term strategic security partner, ZeroLayer is ready.

Book a 30-minute call

Pick a time that works for you and talk directly to our security team.