June 8, 2026

What is smishing? How to spot phishing via text message and phone calls

Phishing and digital fraud don’t just happen via email. Scammers also use text messages, phone calls, and messaging apps to trick employees into clicking on links, sharing information, authorizing payments, or…

Phishing and digital fraud don’t just happen via email. Scammers also use text messages, phone calls, and messaging apps to trick employees into clicking on links, sharing information, authorizing payments, or logging into fake websites. When phishing occurs via text message, it’s called smishing. When it happens via phone call, it’s often called vishing or phone phishing.

For businesses, this is a real risk because employees use their cell phones throughout the workday. A fake text message about a package, a payment, MitID, MFA, or an account can arrive in the middle of a busy period, when the employee has less time to pause and check the sender.

Here you’ll find a clear explanation of what smishing is, how phishing via text message and phone works, and how you can train your organization to respond correctly and avoid falling victim to scams. 


What is smishing?

Smishing is a form of phishing in which scammers use text messages or messaging apps to trick the recipient. The word “smishing” is a portmanteau of “SMS” and “phishing.”

The goal is typically to get the recipient to click on a link, enter login credentials, share payment information, download a fake app, or call a phone number where the scammer will try to obtain more information.

Smishing is similar to phishing emails, but can be harder to spot because text messages are often short and appear on a smaller screen. Many people also respond more quickly to text messages than to emails, especially if the message concerns a package, an account, a payment, or an access that is about to expire.


What is the difference between smishing, phishing, and vishing?

Smishing, phishing, and vishing are related forms of digital fraud. The main difference lies in the channel the scammer uses.

TermChannelExampleTypical goals
PhishingEmailFake Microsoft 365 loginStealing passwords
SmishingText message or messaging appFake PostNord Text MessageGet clicks, payments, or information
VishingPhone callsFake calls from a bank or support serviceGet information or make a payment over the phone

Phishing via text message is known as "smishing." Phishing via phone or phone calls is often called "vishing" or "phone phishing." In practice, these methods can overlap. For example, an employee might first receive a text message and then get a call from someone trying to appear trustworthy.

How does smishing work?

Smishing works by having scammers pose as a trustworthy sender. This could be a bank, PostNord, MitID, SKAT, a supplier, a coworker, or a well-known digital service.

The message often creates a sense of urgency or concern. The recipient is told that an account is being suspended, that a package cannot be delivered, or that a payment is missing. The recipient is then asked to click on a link, call a number, or confirm information.

The link typically leads to a fake website that looks like a legitimate login or payment page. If the employee enters their information, the scammer can gain access to accounts, payments, or the company’s systems. 

Typical examples of smishing

Smishing messages are often written to resemble something the recipient is already familiar with from everyday life.


A classic example is a fake PostNord phishing text message in which the recipient is told that a package cannot be delivered or that payment for shipping or customs duties is outstanding. It seems credible because many people are expecting packages and respond quickly to delivery notifications.


Smishing can also appear to be a message from a bank, MitID, a supplier, or an internal department. For example, an employee might receive a message stating that an account has been locked, that an invoice is overdue, or that a shared document must be opened via a link.


Example of a smishing message

Your package cannot be delivered until the outstanding postage is paid. Pay here: [fake link]
The message is short, to the point, and prompts immediate action. That is precisely why smishing often works: The recipient doesn’t always have time to stop and consider whether the message makes sense.


Smishing in the Workplace

Smishing isn’t just a personal problem. Many employees use their cell phones for work, including approvals, MFA, messaging, calendars, emails, and internal systems. As a result, a fake text message can quickly become a gateway to a company’s data or systems.


In the workplace, smishing often targets situations where employees are accustomed to acting quickly. Finance may receive a fake message regarding payment or changes to account information. HR may be targeted by messages about payroll or personnel information. IT and employees may receive fake messages regarding login, MFA, or password resets. Management may receive messages that appear to be urgent requests from colleagues, suppliers, or business partners.


That is why smishing should be included in the company’s awareness and phishing training programs. Employees should not only learn to spot fake emails; they should also be able to recognize scams via text message, phone calls, and other messaging channels.


What should employees do if they receive a suspicious text message?

When an employee receives a suspicious text message, the process should be simple.

Stop and don’t click.
Don’t reply to the message.
Don’t share personal information.
Don’t call the phone numbers in the message.
Go directly to the sender’s official website or app.
Contact the sender through a known channel if the message seems important.
Report the message internally to IT or the security officer.
The most important thing is that employees shouldn’t have to guess. There must be a clear internal process for where suspicious text messages, calls, and messages should be reported.

What should you do if an employee clicks?

If an employee clicks on a link in a smishing message, the most important thing is to respond quickly and calmly.

  1. Stop what you're doing immediately.
  2. Contact IT or the security officer.
  3. Change your password if your login credentials have been entered.
  4. Check MFA and active sessions.
  5. Check to see if an app has been installed or if permissions have been granted.
  6. Check to see if other employees have received the same message.
  7. Document the incident and the actions you have taken.
  8. Use this incident as a learning opportunity in your next awareness or phishing training session.


A slip-up doesn’t have to turn into a serious incident if the employee reports it promptly and the company has a clear process in place. A strong safety culture isn’t about assigning blame. It’s about identifying mistakes early and responding appropriately.


How Businesses Can Protect Themselves Against Smishing

Smishing cannot be eliminated with a single tool alone. It requires a combination of technical measures, clear processes, and employees who know how to respond.


The first step is to clearly outline how employees should handle text messages and phone calls requesting login credentials, payments, or personal information. If the message concerns money, access, or data, the employee should always be able to verify it through a trusted channel.

Next, smishing should be included in awareness training. This will help employees better recognize scams when they don’t come in the form of a traditional email. The training should use real-life examples, such as fake package notifications, MFA messages, supplier messages, and phone calls.


Companies should also have clear approval processes in place for payments, changes to account information, and access to systems. The clearer the process is, the easier it is for employees to spot when a message deviates from the norm.


Here's how you can train your employees to recognize smishing

Smishing should be included in your overall awareness and phishing training efforts. Employees should not only learn to recognize fake emails, but also fraud attempts via text messages, phone calls, and messaging apps.


Training should be based on situations that employees actually encounter in their daily work. These might include fake package notifications, messages about MitID, MFA, payments, suppliers, HR, or internal approvals. The more recognizable the examples are, the easier it will be for employees to pause before clicking.


It is also important that the training makes it clear what employees should do in case of doubt. They should know how to verify a message through a trusted channel, who to contact internally, and how to report suspicious text messages or calls.
Good training should therefore combine three elements: concrete examples, clear internal processes, and ongoing follow-up. That way, smishing doesn’t just become something employees have heard about once, but a part of their daily security habits.


With SecureFirst, you can consolidate awareness training, phishing simulations, reporting, and documentation in one place. This makes it easier to take a structured approach to employee behavior and track progress over time.

Book a demo or try our phishing module for free.

Dion Grydell

Introductory Meeting – SecureFirst

Questions?

Should you have any questions, please do not hesitate to contact us by phone or email.  

What is ransomware, and why do companies choose to pay millions to cybercriminals?

What is ransomware, and why do companies choose to pay millions to cybercriminals?

Ransomware has become one of the most serious cyber threats facing modern businesses. These attacks are no longer just about locking files; they increasingly involve extortion, data theft, and threats to a company’s operations and reputation. When the consequences become severe enough, even well-protected organizations may find themselves in a situation where paying a ransom becomes a real consideration.

But why does this happen, and what can companies do to reduce the risk?

How phishing training works

How phishing training works

Phishing remains one of the most common ways for cybercriminals to gain access to businesses. Even though spam filters, firewalls, and security systems are getting better, fake...