What Is Smishing and How Does It Work?

what is smishing

In short: Smishing is text-message phishing, and understanding how it works helps people recognise suspicious requests before they share information, money or access. A smishing message may ask someone to follow a link, enter login or bank details, make a payment, reply or call a supplied number. The safe response is to stop, verify the request through an independently trusted contact route and report the message (Report Fraud, 2026a).

Effective smishing awareness focuses on the action a text requests, not whether the message looks obviously fraudulent. Employees need to recognise when an unexpected link, payment, login or process change requires an independent check.

A familiar sender name, polished wording or relevant situation cannot establish that a message is genuine because sender information can be spoofed.

Safe handling depends on a consistent response across personal and work phones: stop, verify through a trusted route and report, with prompt escalation if the recipient has already interacted.

How Does Smishing Work?

A smishing attempt usually starts with a believable reason for making contact. A criminal may refer to a delivery, an unusual payment, an account warning, a refund, a fine or a workplace request. The context is selected to make the message feel relevant enough to act on.

Pressure then reduces the chance of an independent check. The text may claim that a deadline is close, an account is about to be restricted or a senior colleague needs something immediately. Authority, urgency and emotion are common features of scam communications because they encourage action before reflection (NCSC, 2022a).

The requested action creates the route into the fraud. A link may lead to a fake website that collects login details or financial information. A reply may begin a longer fraudulent conversation. A supplied number may move the recipient into a fraudulent phone call. A download may expose the device to malicious software.

A familiar sender name, number or message thread does not establish who sent the text. Criminals can spoof sender information so that a fraudulent message appears alongside genuine messages (Report Fraud, 2026a). The aim may be to steal information or money, gain access to an account or compromise a device.

What Can Smishing Look Like?

Smishing can look like a routine delivery, banking, payment or workplace message. The four illustrative examples use no real organisations, telephone numbers or links because the scenario matters more than a particular brand or wording.

A Parcel or Delivery Message

A text claims that a parcel could not be delivered and that a small redelivery charge is due. The link leads to a page asking for payment and personal details. The pretext feels routine, especially if the recipient is expecting a delivery. The unexpected fee and unverified link are reasons to leave the text and check the delivery through the courier’s official website or app.

A Banking or Payment Alert

A message claims that an unusual transaction has been detected and tells the recipient to secure the account immediately through a link or supplied number. The pressure comes from the fear of financial loss. The safe check is to open the bank’s official app or use a trusted number, such as the one printed on the bank card, rather than following the route in the message.

A Fine Charge or Refund

A text claims that a charge will increase unless payment is made today, or that an unexpected refund is waiting to be claimed. Both versions use a consequence or reward to prompt quick action. The recipient should question whether the contact was expected and verify the position through the official organisation’s published route.

A Workplace Request

A message appears to come from IT support, a colleague or a manager. It asks the employee to confirm a login, share a security code, send information or bypass the usual approval process because the matter is urgent. The sender name may look familiar, but the change to normal working practice is the stronger warning. The request should be checked through the organisation’s established contact and authorisation route.

Official UK guidance describes the same broad patterns across delivery, banking, government-body and familiar-person scams (Ofcom, 2026a). No one example proves that every similar message is fraudulent. Each one gives the recipient a reason to pause and verify.

What Is the Difference Between Smishing and Phishing?

Smishing is a phishing technique delivered through text or mobile messages. Phishing is the wider category and is often associated with email, although official guidance also uses the term for fraudulent texts and calls. The delivery channel changes, but the attacker is still trying to trigger an unsafe action by presenting a false request as genuine (GOV.UK, 2023).

Feature Smishing Email Phishing
Primary channel SMS or mobile text message Email
Typical requested action Click, reply, call, pay or enter details Click, open, reply, log in, pay or enter details
Safe principle Stop, verify through a trusted route and report Stop, verify through a trusted route and report

How Can You Recognise a Smishing Message?

You can recognise a possible smishing message by looking for unexpected context, pressure and consequential requested actions. Any of these patterns is a reason to stop and check:

  • The contact, timing or context is unexpected.
  • The sender creates urgency, fear, secrecy or the prospect of an unusually attractive reward.
  • The request involves a password, security code, payment, bank detail, personal information or account access.
  • A link or telephone number has not been obtained independently from a trusted source.
  • The message changes a normal process or asks the recipient to bypass approval or verification.
  • The sender name, number or message thread looks familiar but cannot independently prove who sent the text.

Spelling, grammar and formatting can support suspicion, but polished language does not make a message safe. The NCSC notes that scam communications have become harder to identify by appearance alone (NCSC, 2022a).

The practical test is the request. An unexpected message that asks for a consequential action deserves an independent check, even when the wording and sender details look credible.

How Can You Avoid Smishing and Respond Safely?

You can reduce the likelihood of acting on a smishing message by using the same three-step response whenever a text makes an unexpected or consequential request.

  1. Stop before acting. Do not click the link, reply, call the number, make a payment or share information while the request is uncertain. Taking a moment creates time for an independent check.
  2. Verify through a trusted route. Open the organisation’s official app or type its known website address yourself. Use a number from an official website, an account statement, the back of a bank card or an existing contact record. If the text appears to come from a colleague, use contact details already held or speak to the person directly. Do not verify through the link, reply option or number in the suspicious message.
  3. Report the message. Follow the organisation’s reporting process when the message concerns work, a work device, work information or work access. Before blocking or deleting the message, retain the details your organisation or provider needs, in line with that process.

Suspicious SMS texts can be forwarded free of charge to 7726. Built-in phone reporting can also be used. Rich Communication Services (RCS), iMessage and app-based messages do not all follow the same route, so use the phone or app’s reporting feature where appropriate (Ofcom, 2026b).

What Should You Do If You Have Already Interacted?

If you have already interacted with a suspected smishing message, end the contact and report what happened promptly. The immediate response depends on the action taken, but the employee should not be expected to diagnose the incident or investigate it alone.

Action Taken Immediate Response
Clicked a link but entered nothing Close the page and report promptly. Contact IT or cyber security if a work device, work account or work context is involved.
Replied or called End the contact, provide no further information and report what happened.
Entered a password or security code Notify the relevant internal or service support route. Change the password through the official app or website and address any reuse on other accounts. Human Focus guidance on password security provides the wider account-security context.
Shared bank or card details, made a payment or lost money Contact the bank or payment provider immediately through trusted details. Make a police report through Report Fraud in England, Wales or Northern Ireland. In Scotland, contact Police Scotland on 101 (Report Fraud, 2026b).
Downloaded or installed something Contact the organisation's IT team or the mobile provider for assessment. Avoid using banking or other sensitive services on the device until it has been checked.
Shared personal or work information Report internally so the responsible security or data-protection team can assess the exposure and decide whether wider notification duties apply.

The NCSC gives action-specific guidance for compromised passwords, banking details, work devices and software installation (NCSC, 2022b). Where personal data may have been exposed, the responsible organisational function should assess the incident and decide whether notification is required. The employee who received the text should report the facts rather than decide whether a legal reporting threshold has been met (ICO, 2025).

How Can Organisations Reduce Smishing Risk?

Organisations can reduce smishing risk by combining clear verification and reporting processes with appropriate technical controls, secure account access and incident response. Employee awareness supports this arrangement but is not a complete control system. The NCSC recommends a layered approach to phishing that combines people, process and technology, while planning for messages that may still get through (NCSC, 2024).

Organisations can strengthen that system by:

  • giving employees a quick, clear and non-punitive route for reporting suspicious messages and mistakes
  • defining trusted verification routes for payments, account changes, access requests and identity checks
  • making normal processes clear enough for an unexpected request or attempted bypass to stand out
  • using appropriate account security, access controls, supported devices, updates and protective technology to limit the effect of one interaction
  • including realistic mobile-message scenarios in relevant awareness training
  • practising incident response so that a report leads to prompt containment and support

A process that depends on every employee identifying every fraudulent message cannot provide a reliable defence. A stronger arrangement makes high-impact actions difficult to complete from an unverified text and makes it safe to report uncertainty. The same system-led principle applies across common cyber security threats and wider digital fraud in the workplace.

Training supports recognition, verification and reporting. It does not replace technical controls, clear working practices or incident response.

What Should You Remember About Smishing?

Smishing is phishing through text messages, and the request matters more than surface appearance. Unexpected links, payments, login requests and changes to normal process should be checked through a trusted route independent of the message. Prompt, non-blaming reporting enables the organisation or service provider to respond, including when someone has already interacted.

How Can Human Focus Support Smishing Awareness?

Organisations seeking to give employees a consistent baseline for recognising suspicious mobile requests and following an agreed verification and reporting process can use Human Focus Cyber Security Awareness Training to support that need. The online course is certified by the CPD Certification Service and covers phishing messages, including fake texts, alongside voice phishing, password security and reporting responsibilities as one part of wider organisational cyber security arrangements.

About the author(s)

Human Focus Editorial Staff comprises a dedicated collective of workplace safety specialists and content contributors. The team shares practical guidance on human factors, risk, and compliance to support safer, more effective workplaces.

Share with others
You might also like

Popular Courses

IOSH Managing Safely
IOSH Managing Safely
View Course Details
GDPR Awareness Training Course
GDPR Training
View Course Details
LOTOTO online training course
Safe Isolation – Lock Out, Tag Out, Try Out (LOTOTO) Training
View Course Details
spill kit training
Spill Kit Hazardous Substances Training
View Course Details
Legionella-Risk-Assessment-Training
Legionella Risk Management Principles for Responsible Persons
View Course Details

Recent Articles

what is ransomware
Ransomware: What It Is and How Businesses Can Reduce the Risk and Impact
social engineering attacks
Social Engineering Attacks: Types, Examples and Prevention
what is phishing
What Is Phishing? Phishing Training for Employees: What Should Staff Know?
fire safety competence framework industry standards
Fire Safety Competence Expectations in England and Wales: Can Your Organisation Evidence the Right Capability?
LOLER lift plan requirements
What Must a LOLER Lift Plan Include? A Guide for Duty Holders

Current Offers

BSA course
Building Safety Act Training

Original price was: £35.00.Current price is: £28.00. +VAT

PUWER
PUWER Leadership Skills for Supervisors

Original price was: £125.00.Current price is: £100.00. +VAT

PUWER
PUWER Inspector Training

Original price was: £495.00.Current price is: £396.00. +VAT

PUWER
PUWER Essentials for Maintenance and Support Staff

Original price was: £125.00.Current price is: £100.00. +VAT

carbon literacy course
Carbon Footprint Reduction

Original price was: £95.00.Current price is: £76.00. +VAT