Smishing — SMS phishing
Qué es Smishing?
Esta entrada está disponible actualmente solo en inglés.
Smishing is phishing carried out over SMS: a text that impersonates a trusted brand and pushes a lookalike link or callback number, aiming to steal credentials, payment details, or personal data. SMS is an effective smishing vehicle because messages arrive in the same inbox as legitimate bank alerts and delivery updates, so a spoofed sender ID or lookalike domain inherits trust it never earned. Smishing waves also damage the impersonated brand, not just the recipients.
More detail
SMS works for attackers because the channel is personal, high-open, and accustomed to short links: recipients expect their carrier, bank, or a retailer to text them, so a well-disguised lure reads as routine until it harvests a password or card number. Sender-ID spoofing and lookalike domains do the disguise; the smishing keyword is the message.
Devotel Orbit's brand-impersonation scanner screens candidates you observe — domains, sender IDs, and display names — against your watchlist of legitimate brand names, registered domains, and protected sender IDs. Each candidate scores into a clean, suspicious, or malicious band with a matching recommendation, which is what separates your own validly-composed traffic from a lookalike candidate worth a takedown case.
Defenses pair sender authentication with content inspection. Registering your brands and sender IDs (A2P 10DLC, alphanumeric sender IDs, RCS verified senders) makes impersonation harder to pass undetected; SMS firewalls and spam filters flag lure content in transit; and when a wave still impersonates your brand, the response is a takedown filed with the registrar or carrier abuse desk — not stopping your legitimate sends.
Preguntas frecuentes
- What is smishing?
- Smishing is phishing over SMS — a text message that impersonates a trusted brand to trick the recipient into opening a lookalike link or calling a fraudulent number. The disguise rides on sender-ID spoofing and lookalike domains, which is why screening both against a watchlist of your legitimate assets matters.
- Why is SMS a common smishing vehicle?
- SMS is personal, has near-total open rates, and recipients are accustomed to legitimate short links from banks, carriers, and retailers — so a spoofed sender inherits trust it never earned. Short message bodies also hide the destination domain until the link is tapped.
- How does Orbit's brand-impersonation scan band a candidate?
- Each candidate — a domain, sender ID, or display name — is fuzzy-compared against your watchlist of brand names, protected domains, and protected sender IDs. The score sums named findings such as homoglyph spoofing, exact-label-on-wrong-TLD, and typosquat closeness into a clean (monitor), suspicious (investigate), or malicious (urgent takedown) band.
See also
Build it on Orbit
Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.