A fraud which targets the users of mobile phones using text messages is referred to as a ‘SMiShing’ scam. Scammers aim to obtain private and confidential information from individuals or encourage them to ring a number or click on a link for more information. Fraudsters may spoof the message onto a genuine message thread.
Each smishing attack uses similar methods, while the presentation may vary significantly. Attackers can use a wide variety of identities and premises to keep these SMS attacks fresh.
Typically, an attacker will claim there is an error with your account and give you steps to resolve it. The request can be as simple as using a fraudulent login page, while more complex schemes may ask you to provide a real account recovery code in an attempt to reset your password. Warnings of a support-based smishing scheme include an issue with billing, account access, unusual activity, or resolving your recent customer complaint.
SMS phishing attacks primarily spread uninterrupted and unnoticed due to their deceptive nature. Smishing deception is enhanced due to users having false confidence in text message safety.
Firstly, most people know about the risks of email fraud. You’ve probably learned to be suspicious of generic emails that say “Hi—check out this link.” The exclusion of an authentic personal message tends to be a substantial red flag of email spam scams.
When people are on their phones, they are less wary. Many assume that their smartphones are more secure than computers. But smartphone security has limitations and cannot always directly protect against smishing.
Another risk factor is that when you’re on your smartphone and on the go, often you’re distracted or in a hurry. This means you’re more likely to get caught with your guard down and respond without thinking when you receive a message asking for bank information or to redeem a coupon.
Regardless of the means being used, these schemes ultimately require very little beyond your trust and a lapse in judgment to succeed. As a result, smishing can attack any mobile device with text messaging capabilities.
Gift smishing suggests the promise of free services or products, often from a reputable retailer or other company. These can be giveaway contests, shopping rewards, or any number of other free offers. When an attacker elevates your excitement by proposing the idea of “free,” this serves as a logic override to get you to act faster. Signs of this attack can include limited time offers or exclusive selection for a free gift card.
Invoice or Order Confirmation Smishing
Confirmation smishing involves a false confirmation of a recent purchase or billing invoice for a service. A link may be provided for a follow-up to manipulate your curiosity or prompt immediate action to trigger fear of unwanted charges. Evidence of this scam may involve strings of order confirmation texts or the absence of a business name.
Customer Support Smishing
Customer support smishing attackers pose as a trusted company’s support representative to help you resolve an issue.
As with phishing attacks, spotting smishing attacks isn’t always easy. Look for something that’s off or unusual. Here is some advice when receiving a suspicious text:
At present, Bank of St Helena do not use SMS texting to contact customers.
|wpl_user_preference||sainthelenabank.com||WP GDPR Cookie Consent Preferences||1 year||HTTP|
|_ga||sainthelenabank.com||Google Universal Analytics long-time unique user tracking identifier.||2 years||HTTP|
|_gid||sainthelenabank.com||Google Universal Analytics short-time unique user tracking identifier.||1 days||HTTP|
|_wpfuuid||sainthelenabank.com||Online Forms||11 years||---|