A Single Text Message Cost This Company $15 Million

In 2022, Twilio disclosed that a coordinated smishing campaign tricked employees into entering credentials on a fake login page. Attackers used those credentials to access internal systems and compromise data for over 100 customers. The whole thing started with a text message that looked like it came from IT.

I've been tracking smishing attack examples for years, and they keep getting more convincing. These aren't the poorly worded scam texts from a decade ago. Today's threat actors use personalized data, spoofed sender IDs, and urgency triggers that fool even security-aware employees. If your organization isn't training against these threats, you're already behind.

This post breaks down real smishing attack examples across multiple categories, explains exactly how they work, and gives you concrete steps to stop them.

What Is a Smishing Attack?

Smishing is phishing delivered by SMS or text message instead of email. The attacker's goal is the same: trick you into clicking a malicious link, handing over credentials, or installing malware. The difference is the delivery channel — and that channel is devastatingly effective.

SMS messages have a 98% open rate compared to roughly 20% for email. People trust their phones. They respond faster and with less scrutiny. That's exactly what threat actors count on.

Why Smishing Is Harder to Detect Than Email Phishing

Email clients have years of built-in spam filtering, link scanning, and banner warnings. Most SMS apps have almost none of that. There's no "hover over a link to preview" on a phone. Sender IDs can be spoofed trivially. And shortened URLs — standard in text messages — hide the real destination entirely.

5 Real Smishing Attack Examples You Need to Recognize

Let me walk you through the categories I see most often in the wild. Each one exploits a different psychological trigger.

1. The Fake Delivery Notification

Example text: "USPS: Your package has a delivery issue. Update your address here to avoid return: [shortened URL]"

This smishing attack example exploded during the pandemic and hasn't slowed down. The FBI's Internet Crime Complaint Center (IC3) has repeatedly warned about package delivery scams. The link leads to a convincing replica of the USPS or FedEx site that harvests your name, address, and credit card number. I've seen versions that also install spyware on Android devices.

2. The Bank Fraud Alert

Example text: "[Bank Name] ALERT: Suspicious login detected on your account. If this wasn't you, verify now: [shortened URL]"

The urgency here is the weapon. You see "suspicious login" and your brain shifts into panic mode. The link goes to a pixel-perfect clone of your bank's login page. Once you enter your username and password, the attacker has your credentials — and they'll use them within minutes, often draining accounts before the real bank can intervene. This is credential theft at its most efficient.

3. The IT Department Impersonation

Example text: "IT Security: Your corporate account password expires today. Reset it immediately to maintain access: [link]"

This is the exact pattern used in the Twilio breach. The attacker researches the target organization, identifies the SSO or identity provider, and clones the login page. Employees, especially those working remotely, comply without a second thought. This type of social engineering bypasses perimeter security entirely because the employee willingly hands over the keys.

4. The Tax Refund or Government Scam

Example text: "IRS: You are eligible for a tax refund of $1,384.00. Submit your information to claim: [link]"

The IRS has stated repeatedly that it does not initiate contact via text message. Yet these smishing attacks surge every tax season. The linked page typically asks for Social Security numbers, bank routing numbers, and other data that enables full identity theft. CISA has published detailed guidance on avoiding social engineering and phishing attacks like this.

5. The Multi-Factor Authentication Bypass

Example text: "Your verification code is 847291. If you did not request this, reply STOP or click here to secure your account: [link]"

This is one of the more sophisticated smishing attack examples I've encountered. The attacker is actively trying to log into your account in real time. They trigger a legitimate MFA code, then immediately text you pretending to be the service, hoping you'll click the phishing link and enter both your password and the code. It's a real-time relay attack that defeats multi-factor authentication — the very control you thought was protecting you.

How Smishing Attacks Fit Into Larger Campaigns

Smishing rarely operates in isolation. In my experience, it's usually one phase of a multi-stage attack. Here's a pattern I've seen repeatedly:

  • Stage 1: Smishing text harvests employee credentials.
  • Stage 2: Attacker uses credentials to access VPN or cloud services.
  • Stage 3: Lateral movement and data exfiltration.
  • Stage 4: Ransomware deployment or data sold on dark web markets.

The Verizon 2024 Data Breach Investigations Report found that the human element was involved in 68% of breaches. Smishing is one of the primary vectors making that statistic possible. You can review the full findings at Verizon's DBIR page.

How Do You Protect Against Smishing Attacks?

Here's the direct answer: layered defense combining technology, policy, and ongoing training. No single control stops smishing.

  • Deploy mobile threat defense (MTD) solutions that can detect malicious URLs in SMS messages before users click them.
  • Implement phishing-resistant MFA such as FIDO2 hardware keys. SMS-based MFA codes are the exact weakness smishing exploits.
  • Adopt a zero trust architecture that verifies every access request regardless of where it originates. NIST's Zero Trust Architecture publication (SP 800-207) is the definitive reference.
  • Establish a clear reporting channel so employees can forward suspicious texts to your security team instantly.
  • Run regular phishing simulations that include SMS-based scenarios, not just email. If your training only covers email phishing, you're leaving a massive gap.

Training Is the Control That Actually Scales

Technology catches known threats. Training catches the novel ones — the ones crafted specifically for your organization. I've seen companies with excellent email filtering get burned by a single smishing text because nobody ever trained employees to question an SMS from "IT."

Effective security awareness training should include real-world smishing attack examples like the ones above. Your employees need to see what these messages look like on an actual phone screen, not just hear about them in a slide deck.

Our phishing awareness training for organizations includes SMS-based social engineering scenarios designed to build real recognition skills. For a broader foundation covering ransomware, credential theft, and data breach prevention, explore our cybersecurity awareness training program.

What to Do If You've Already Clicked

Speed matters. If you or an employee clicked a smishing link and entered any information:

  • Immediately change the compromised password from a known-safe device.
  • Revoke active sessions for the affected account.
  • Enable or reset MFA — preferably to a phishing-resistant method.
  • Report the incident to your security team and monitor for unauthorized access.
  • File a report with the FBI IC3 if financial loss or data breach occurred.

The $4.88M Lesson Most Organizations Learn Too Late

IBM's 2024 Cost of a Data Breach Report put the global average cost of a data breach at $4.88 million. A significant share of those breaches started with a social engineering attack — many of them via SMS. The math is simple: investing in training and controls now costs a fraction of what a breach costs later.

Smishing isn't going away. As organizations harden their email defenses, threat actors shift to channels with less protection. Your phone is now the front line. Treat it that way.

Start building recognition skills across your team today. The difference between a reported suspicious text and a compromised network often comes down to whether someone had seen a smishing attack example before it showed up on their screen.