Skip to main content
SMiShing

The Five Most Common SMiShing Scams: Social Engineering News 

By June 28, 2023No Comments

The Federal Trade Commission (FTC) recently released data on the five most common SMiShing scams that cost consumers over $330,000,000. These five SMiShing scams have at least two things in common: The scams impersonate well-known businesses; They create a sense of urgency.

Smishing scams

Phony bank fraud prevention alerts

You may get a text message similar to the one Kelli Hinton received from a scammer posing as a bank fraud investigator:

“Freemsg: Chase, Did you attempt wire transfer amount of $7500. Reply Y if recognized, Or NO to stop fraud.”

The bad actor followed up with a vishing phone call and ended up clearing two of her bank accounts of $15,000.

Bogus “gifts”

There is no such thing as a free lunch, and fake gift/reward smishing scams prove that adage to be true. There is always a catch to receive your gift or reward, usually it is a request to enter your payment information to cover a small shipping charge. According to the Better Business Bureau, these texts may read something like, “Your bill is paid for June. Thanks, here’s a little gift for you,” followed by an unfamiliar link to click.

Fake package delivery problems

Are you expecting a delivery to your business or home? You may receive a text message from a bad actor posing as the U.S. Postal Service, FedEx, or UPS. The message will usually say that there is an issue with the delivery and that immediate action is necessary. That is what happened to Teresa Owen. She was expecting a shipment of medical equipment and received a delivery update text message from the U.S. Postal Service (USPS). The link in the message took her to a USPS website that looked legitimate, the correct looking logo, post office information and tracking number. To avoid a delivery problem, she was told to pay 30 cents in postage. Teresa promptly entered her debit card number. Fortunately, Owen’s bank alerted her in time, and she did not lose any cash.

Phony job offers

If you post your resumes to any employment website, do not be surprised if you receive a phony text message claiming to offer employment. The big tip-off that it is not legitimate is the offer to send you a check with instructions to send some of the money to a different address for materials, training, or something similar.

Amazon security alerts

You may receive a text message from Amazon alerting you to a suspicious transaction or to verify the purchase of a big-ticket item. The message may include a link or phone number to call.

The Five Most Common SMiShing Scams

Image: Tech.co

Why Scammers are SMiShing

Why are scammers using this attack vector? There are a few reasons. Bad actors realize that people just cannot seem to resist the ‘ding’ of an incoming text. In fact, more than half of all consumers text daily, making texting more common than voice or email communication. In addition, the appeal and nature of text communication is speed. So, scammers are counting on their targets replying quickly, without thinking about what the message is saying.

Educate. Test. Protect.

Would your employees be able to recognize the five most common SMiShing scams? With many accessing corporate information and accounts from their personal phones, if they fall victim to SMiShing on their personal phone, the attacker could get access to corporate information. The risks are simply too high to ignore, and the solution is attainable. Effective employee education and testing is the key to identifying risk and assessing vulnerabilities within your organization’s human network.

Our Managed SMiShing Service measures and tracks how your employees respond to text-based phishing attacks. Our engagements focus on simulation of social engineering attacks and determine the potential for corporate assets being breached and compromised. With this service you can increase your reporting metrics by testing corporate managed SMS-capable devices with data driven targeting and training. Please contact us today to schedule a consultation.

Security Assessment Case Study
Learn more about the importance of a Social Engineering Risk Assessment.
Security Assessment Case Study
Learn more about the importance of a Social Engineering Risk Assessment.
What Makes Us Different
At Social-Engineer, we pride ourselves on what we do and how we do it. We are a security services provider, focusing on four primary attack vectors. This case study will go through how we can protect your company and what makes us different.
What Makes Us Different
At Social-Engineer, we pride ourselves on what we do and how we do it. We are a security services provider, focusing on four primary attack vectors. This case study will go through how we can protect your company and what makes us different.
Woman vs Machine
Technology is providing new, more innovative ways to enhance our world. Scientists are constantly developing smarter, faster and more intelligent machines, systems and robots. There is no doubt that each of these has evolved beyond their clockwork origins.
Woman vs Machine
Technology is providing new, more innovative ways to enhance our world. Scientists are constantly developing smarter, faster and more intelligent machines, systems and robots. There is no doubt that each of these has evolved beyond their clockwork origins.
Vishing and Phishing Must Be Ongoing to Be Effective
Most companies have a security awareness program in one form or another. If they don’t, it should be on the short list of programs to start as soon as possible. In our experience, many of these programs take the form of computer-based training.
Vishing and Phishing Must Be Ongoing to Be Effective
Most companies have a security awareness program in one form or another. If they don’t, it should be on the short list of programs to start as soon as possible. In our experience, many of these programs take the form of computer-based training.
A Case Study in Vishing
Vishing (voice-based phishing) has been a problem for quite a long time. There are many vendors in the marketplace that offer vishing services. However they tend to use robo-callers or call centers for large volume engagements. If they are using trained humans to make calls, it is likely in very low numbers.
A Case Study in Vishing
Vishing (voice-based phishing) has been a problem for quite a long time. There are many vendors in the marketplace that offer vishing services. However they tend to use robo-callers or call centers for large volume engagements. If they are using trained humans to make calls, it is likely in very low numbers.
Benefits of a Social-Engineering Risk Assessment Engagement
Your company is important. Indeed, the data you hold for your clients or employees is very valuable and attackers seek to capitalize on that data any way they can. This is where a Social Engineering Risk Assessment (SERA) engagement can help uncover possible vulnerability to attackers.
Benefits of a Social-Engineering Risk Assessment Engagement
Your company is important. Indeed, the data you hold for your clients or employees is very valuable and attackers seek to capitalize on that data any way they can. This is where a Social Engineering Risk Assessment (SERA) engagement can help uncover possible vulnerability to attackers.
The Business Value of the Social-Engineer Phishing Service
Cybercriminals are targeting the human element of organizations. Additionally, they are developing techniques to use an organization’s employees as the first point of entry. According to the 2021 Verizon DBIR report, of the 3,841 security breaches reported using social engineering, phishing was the key vector for over 80% of them.
The Business Value of the Social-Engineer Phishing Service
Cybercriminals are targeting the human element of organizations. Additionally, they are developing techniques to use an organization’s employees as the first point of entry. According to the 2021 Verizon DBIR report, of the 3,841 security breaches reported using social engineering, phishing was the key vector for over 80% of them.