The Text Message That Cost One Company $15 Million
In 2022, Twilio disclosed that a sophisticated smishing campaign tricked several employees into handing over their credentials via text messages impersonating the company's IT department. The attackers then used those stolen credentials to access internal systems and customer data. It was a textbook case of how a simple SMS can unravel an entire organization's security posture.
Smishing — SMS phishing — is now one of the fastest-growing threat vectors I track. The FBI's Internet Crime Complaint Center (IC3) has seen phishing complaints, including smishing, surge year over year. And unlike email phishing, smishing catches people off guard because most of us inherently trust our text messages more than our inboxes.
This post breaks down real smishing attack examples, explains why they work, and gives you concrete steps to protect your organization. If you've ever gotten a suspicious text and wondered whether it was legit, this is for you.
What Is a Smishing Attack, Exactly?
A smishing attack is a form of social engineering where a threat actor sends a fraudulent text message designed to trick the recipient into clicking a malicious link, surrendering credentials, or transferring money. The "sm" comes from SMS; the "ishing" comes from phishing. Same concept, different channel.
The reason smishing works so well is simple: SMS open rates hover around 98%, compared to roughly 20% for email. When your phone buzzes with an urgent message, you react before you think. Threat actors know this, and they exploit it ruthlessly.
5 Real Smishing Attack Examples You Need to Recognize
I've collected these from real-world incidents, public breach disclosures, and threat intelligence feeds. These are the patterns you and your employees will actually encounter.
1. The Fake Delivery Notification
"USPS: Your package has a delivery issue. Update your address here: [malicious link]"
This is one of the most common smishing attack examples in the wild. The U.S. Postal Service has issued multiple warnings about these texts. The link takes victims to a convincing replica of the USPS site, where they're asked for personal information, credit card numbers, or login credentials. CISA has flagged this pattern repeatedly in their social engineering advisories.
2. The Bank Fraud Alert
"[Bank Name] Alert: Suspicious activity detected on your account. Verify now: [malicious link]"
This one preys on fear. The victim clicks the link, lands on a cloned banking login page, and enters their username and password — handing credential theft to the attacker on a silver platter. Some variants even ask for multi-factor authentication codes, which the attacker uses in real time to hijack the session.
3. The IT Department Impersonation
"IT Helpdesk: Your VPN access expires today. Re-authenticate at [malicious link] to avoid lockout."
This is the exact template used in the Twilio breach and in the 2022 Uber compromise, where a threat actor used SMS-based social engineering to gain access to internal systems. It targets employees specifically, making it a top concern for any organization with remote workers.
4. The Tax Refund Scam
"IRS: You are eligible for a $1,200 tax refund. Claim now: [malicious link]"
The IRS has stated publicly that they never initiate contact via text message. Yet every tax season, this smishing variant floods phones across the country. The links lead to data harvesting forms that collect Social Security numbers, bank routing numbers, and other personally identifiable information.
5. The CEO or Executive Impersonation
"Hey, this is [CEO name]. I need you to purchase gift cards for a client event ASAP. Text me back for details."
This isn't a link-based attack — it's a conversation-based smishing scam. The attacker impersonates a senior executive and pressures an employee into buying gift cards or wiring money. I've seen this hit small and mid-size businesses especially hard because the informal tone feels believable.
Why Smishing Is Harder to Stop Than Email Phishing
Your email gateway probably catches a lot of phishing. Spam filters, DMARC policies, and sandboxing technology screen out millions of malicious emails before they reach inboxes. Text messages don't get the same treatment.
Most mobile carriers have basic spam filtering, but it's nowhere near as mature as email security. There's no equivalent of DMARC for SMS. There's no URL sandboxing on your phone's native messaging app. And when a text arrives from a spoofed number that looks local, your brain's default is to trust it.
This is exactly why security awareness training matters so much for this specific threat. Technology alone won't save you here — your people are the last line of defense.
How to Spot a Smishing Text: The Red Flags
- Urgency or threats: "Act now or your account will be locked." Real companies rarely impose deadlines via text.
- Unknown or spoofed numbers: Messages from random 10-digit numbers or short codes you don't recognize.
- Suspicious links: URLs with misspellings, extra characters, or unfamiliar domains. Hover (long press) before you tap.
- Requests for sensitive data: No legitimate organization asks for passwords, SSNs, or MFA codes via SMS.
- Too-good-to-be-true offers: Refunds, prizes, and giveaways you never signed up for.
If you see any of these signals, don't tap the link. Forward the text to 7726 (SPAM), which reports it to your carrier, and delete it.
What Your Organization Should Do Right Now
Hoping your employees "just know" how to handle a smishing text is not a strategy. Here's what actually works.
Run Phishing and Smishing Simulations
The most effective way to prepare your team is through realistic simulations that test their response to social engineering attacks, including SMS-based ones. Our phishing awareness training for organizations includes scenario-based exercises that train employees to spot the exact patterns outlined above.
Implement Multi-Factor Authentication That Resists Smishing
SMS-based MFA is better than no MFA, but it's vulnerable to the exact attacks I've described. Push-based MFA, hardware security keys, or FIDO2 passkeys are far more resistant. NIST's identity and access management guidance now recommends phishing-resistant MFA for all critical systems.
Adopt a Zero Trust Mindset
Zero trust means never assuming a request is legitimate just because it arrived on a trusted device or from a familiar name. Every access request gets verified. Every unusual message gets questioned. This mindset shift is the foundation of modern security, and it starts with training.
Build a Security-Aware Culture
One training session per year won't cut it. You need ongoing, engaging education that keeps threats like smishing top of mind. Our cybersecurity awareness training program covers smishing, ransomware, credential theft, and dozens of other real-world attack scenarios — updated continuously to match the current threat landscape.
The $4.88M Lesson Most Organizations Learn Too Late
According to IBM's 2024 Cost of a Data Breach Report, the global average cost of a data breach hit $4.88 million. A significant percentage of those breaches started with some form of phishing or social engineering — including smishing. The math is brutal: one employee tapping one malicious link can cost your organization millions in incident response, regulatory fines, legal fees, and reputational damage.
That's not hypothetical. That's actuarial data.
Smishing Is Only Going to Get Worse
Threat actors are now using AI to generate highly convincing smishing messages at scale, with perfect grammar and personalized details scraped from social media and data broker sites. The days of spotting a scam text by its bad spelling are over.
I've also seen a rise in "conversational smishing," where the attacker sends a harmless-looking initial message — "Hey, is this still your number?" — and builds rapport before making the ask. It's patient, it's sophisticated, and it works.
Your organization's best defense is a workforce that knows what to look for, questions everything, and reports suspicious messages immediately. That doesn't happen by accident. It happens through deliberate, ongoing training.
Your Next Step
Review the smishing attack examples in this post with your team this week. Flag the red flags. Talk through what the correct response looks like. And if you don't have a structured training program in place, now is the time to start — before one text message becomes a seven-figure problem.