Smishing

What is Smishing? 

Smishing is a deceptive technique used by malicious actors to trick individuals into revealing sensitive information such as passwords, credit card numbers, or personal data by posing as a trustworthy entity via text messages. It exploits cognitive biases like authority and urgency to bypass rational decision-making and prompt quick, often risky, actions. In the digital landscape, phishing also undermines user trust and can significantly impact website credibility and SEO performance.

The Basic Idea

The other day, I got a text that said: “Your package is arriving! Track it here,” along with a very suspicious link. The thing was, I had actually ordered something. Though I feel like I do a good job of not over-ordering things online, in retrospect, the odds that I’m waiting for a package at any given time—whether it’s a postcard, a prescription, or my monthly delivery of vegan protein powder—are higher than not. At that moment, I felt like it must be about the package I was waiting on; I had just been wondering when it would arrive, so it was probably a sign! I nearly clicked, but something stopped me. That second of hesitation is exactly what scammers count on. In a world where our phones buzz constantly with updates, alerts, and appointments, a well-timed text message can slip through our mental defenses and lead us somewhere dangerous before we’ve even had breakfast.

Welcome to the world of smishing, a word which mashes together “SMS” and “phishing,” and describes a form of cybercrime that uses text messages to deceive recipients into revealing personal information, clicking malicious links, or downloading harmful software. Smishing is a social engineering tactic, meaning it exploits human psychology rather than technical vulnerabilities. Much like phishing emails, smishing messages are designed to appear urgent, trustworthy, or enticing, often mimicking banks, delivery services, tech companies, or government agencies to manipulate the recipient into taking immediate action.

Smishing attacks have grown rapidly in recent years, driven by the ubiquity of smartphones and the increasing reliance on SMS for tasks like two-factor authentication, appointment reminders, and customer service interactions.1,2 These scams often exploit the intimacy and immediacy of text messaging—most of us check and respond to texts far faster than emails, and we tend to trust them more. Scammers take advantage of this speed and trust, crafting texts that blend seamlessly into the flood of legitimate messages we receive every day.

Unlike spam emails, smishing often escapes detection by traditional filters and firewalls, and because it targets individuals directly, it can be harder to identify and block in advance. What makes smishing especially dangerous is how it blends the personal with the technical. A convincing smish can trick even tech-savvy users if it appears at the right time, like during a service outage or a busy holiday season, and asks just enough to trigger concern, curiosity, or compliance. Understanding smishing isn't just a matter of cybersecurity, it's a matter of digital literacy, public policy, and consumer protection.2 As attackers continue to evolve their tactics with AI-generated texts, spoofed phone numbers, and fake apps, the need to educate and empower users is more urgent than ever. 

“

“Phishing remains unsolvable—there’s no patch for human gullibility.”


― Mike Danseglio, Security Program Manager, Microsoft

Key Terms

Spoofing: A deceptive tactic where a scammer disguises their identity by faking emails, phone numbers, or websites to trick individuals into revealing sensitive information or taking harmful actions. Common in phishing attacks and cyber fraud, spoofing undermines trust in digital communications.1

Phishing: A cyberattack method that uses deceptive messages to trick individuals into revealing sensitive information.

Spear Phishing: A highly targeted form of smishing where attackers tailor their messages to a specific individual or organization, often using personal information to make the message more convincing.1

Social Engineering: A broad set of manipulative tactics that exploit traits of human psychology (like feelings of trust or urgency) to trick individuals into revealing sensitive information.1

Business Email Compromise (BEC): A phishing scam where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring money or sensitive information, typically via email.1

Malware: Any software intentionally designed to cause damage, steal data, or gain unauthorized access to systems. The name comes from “malicious software,” and it includes viruses, worms, spyware, trojans, and other harmful programs often delivered through spoofed or deceptive means.2

Ransomware: A type of malware that encrypts a victim’s files or locks them out of their system, demanding payment (often in cryptocurrency) to restore access. It frequently enters through spoofed emails or malicious websites and is used in both individual and large-scale attacks.2,3

History

The term “smishing,” a portmanteau of SMS and phishing, first emerged in the early 2000s, introduced by McAfee’s David Rayhawk as mobile phones became more widespread and text messaging became a common form of communication.4,5 Like email-based phishing, smishing is a form of social engineering that exploits human psychology to trick individuals into revealing sensitive information or downloading malicious content. While phishing began on platforms like AOL and evolved through email and websites, smishing represents a newer frontier in the same digital deception, adapted to mobile environments.3 

Smishing rose in popularity as smartphones became ubiquitous and mobile banking, e-commerce, and two-factor authentication via SMS became standard. Scammers began sending fraudulent text messages that appeared to come from trusted sources like banks, delivery services, or government agencies.3,4 These messages often urged users to click on malicious links or call fake customer service numbers. Because people tend to read and respond to text messages quickly, smishing exploits the urgency and intimacy associated with SMS communication—traits that make these scams particularly effective.

Early smishing campaigns mimicked bank alerts or fraud warnings, tricking recipients into entering credentials on spoofed mobile websites. As with email phishing, attackers capitalized on low public awareness and the lack of standardized mobile security. Major incidents, like widespread fake messages from the IRS or those annoying package delivery texts, helped raise alarm about the rising threat of smishing. Over time, smishing techniques have evolved in sophistication. Attackers now use personalized messages, real-time spoofing of phone numbers, and even SMS sender ID spoofing, which makes fraudulent messages appear to come from legitimate businesses already in a user’s message history. Some smishing attacks also leverage prompt bombing, where there are repeated verification code messages followed by a phishing message, to create urgency and increase compliance.4

The COVID-19 pandemic marked a sharp increase in smishing activity, with scammers impersonating health authorities, vaccine providers, or government relief programs. In these cases, text messages preyed on heightened anxiety and a desire for timely information, directing users to fake sites or requesting personal data under the guise of pandemic response.6

Today, phishing and smishing attacks have evolved to incorporate artificial intelligence (AI), and as generative adversarial networks and machine learning improve the quality of AI-generated sound and video, experts warn of “deepfake phishing,” in which synthetic audio or video can impersonate trusted figures and customize large-scale attacks. Attackers now also use social media, text messages, voice calls, and fake websites to launch multi-platform phishing campaigns. Business Email Compromise (BEC) scams, where attackers impersonate executives to trick employees into sending money or data, have become one of the most financially damaging forms of phishing, with the FBI reporting losses in the billions annually.7 Generative AI can now craft convincing, localized messages at scale, making it easier for attackers to launch personalized smishing campaigns. Emerging threats include deepfake voice messages sent via text-to-speech links and synthetic SMS alerts designed to bypass traditional spam filters.

People

David Rayhawk

A cybersecurity researcher at McAfee who coined the term smishing in the early 2000s by merging "SMS" and "phishing." He recognized the emerging threat posed by fraudulent text messages and helped define this mobile-based form of social engineering designed to deceive users into revealing personal information or installing malware.5

Mary Aiken 

A renowned cyberpsychologist whose work explores the intersection of human behavior and technology, including the psychological manipulation involved in phishing. Her research has highlighted how cybercriminals exploit emotional triggers like fear, urgency, and trust, which are core tactics in successful phishing schemes. Aiken’s insights help explain why people fall for digital scams despite growing awareness and technological safeguards.8

Markus Jakobsson

A leading expert in phishing and online fraud, and co-author of the influential book Phishing and Countermeasures. His research helped establish the link between email spoofing and social engineering, offering scientific methods to detect and prevent such attacks. Jakobsson's contributions have shaped both academic research and practical anti-spoofing tools used today.2

John Lawford

The Executive Director and General Counsel of the Public Interest Advocacy Centre (PIAC), a Canadian consumer advocacy organization. He played a key role during the 2022 Rogers outage by calling for regulatory and policy responses, including a formal inquiry by the Canadian Radio-television and Telecommunications Commission (CRTC), highlighting infrastructure vulnerabilities and accountability in telecom services.17

behavior change 101

Start your behavior change journey at the right place

Impacts

Smishing isn’t just a technical problem; it’s a psychological and economic one. Its success hinges on the exploitation of human cognitive biases, resulting in both personal devastation and large-scale financial and reputational damage, but deciding who is responsible for enforcing and monitoring smishing scams is an entire problem in itself. 

Why texting specifically? 

Why do there seem to be so many phishing schemes that take place over text? One of the key ways that phishers and scammers exploit people is through an urgency bias; the requests sent over text are often paired with an “act now or lose access!” message or even suggest an immediate emergency. Meanwhile, more than 90% of SMS messages are opened in less than three seconds, which further perpetuates the sense of urgency that can be exploited in cyberattacks.9 There’s something about seeing a message arrive that makes it feel necessary to address right away versus noticing an email that’s been sitting in your inbox for a few days; if a message has already gone unopened for a while, there’s less of a rush when the “immediate response is needed” window has already closed. 

Compared to other common phishing tactics, people are also more likely to respond to text messages; research conducted by CallHub has demonstrated that the response rate to SMS messages significantly surpasses that of email.9 Perhaps that’s because we’ve been so thoroughly trained to be skeptical of “fishy” emails and because most people have their phone on or near them almost all the time. Although we typically respond to (or at least check) our texts right away, most people aren’t constantly refreshing their email inbox. 

At this point, many people are also rightfully suspicious of calls from unknown numbers. While many phishing attempts have historically taken place over the phone with scammers spoofing a trusted individual, the popularity of caller ID has made these impersonation attempts much less believable. Meanwhile, smishers can send a message and ensure you’ll read the contents without you even needing to pick up the phone. Even if you might’ve rejected a call from them, once the message is already on the screen, you’re much more likely to give them a bit of your attention. 

Smishers are also able to hide behind the screen in a way they didn’t have to before; whereas you might’ve picked up on a few suspicious qualities in someone’s voice or their speech (or perhaps the background sounds of a busy scamming call center) when they tried to call, there’s a much higher level of anonymity in a text message. It’s easy for scammers to pretend to be any age, gender, or ethnicity over text message, and they can play into whatever seems most relevant for the situation. For smishing attempts from overseas, it’s also easier for scammers to use translator apps to communicate, masking their foreign status if they’re pretending to be someone you trust. In a voice or video call, it might be nearly impossible to have a convincing conversation in a language you don’t speak without the use of AI. Even then, a native speaker might quickly pick up on something being off about the call. 

Collective behavior and social contagion

What makes smishing distinct from other forms of phishing is that it all takes place over text messages. Historically, phishing scams have usually involved suspicious emails or deceptive websites. While these common spoofing tactics still exist, phishing increasingly operates through social channels where peer-to-peer communication accelerates its spread. When people receive a direct message or a link from their friend or family member, they’re obviously far more likely to trust the message. Again, thanks to the impact of urgency, when the message is framed as highly emotional, people often engage with the message with less skepticism than usual. Some studies by researchers like Markus Jakobsson have found that smishing campaigns on social media sites like WhatsApp often exploit pre-existing trust within networks, spreading in patterns that mirror epidemiological contagion.2,10 Thus, smishing isn’t just about technical viruses—it’s also a behavioral issue that thrives on our human social habits.

Smishing’s viral success on social platforms is also explained by psychological principles like social proof, which is our tendency to assume that behaviors or information are correct if others around us endorse them. When users see that a link has been liked, shared, or commented on by others (especially if those others are people in our social circle), they infer legitimacy, even when the content is malicious. 

If this reminds you of the way rumors tend to spread at school or work, you’ve caught on to a key pattern. The dynamics of rumor propagation, where repetition and familiarity increase perceived truthfulness, are very similar to the way phishing schemes and fake news can spread.1,8 Attackers often craft phishing and smishing messages to mimic the hottest trends or memes, which makes it even more challenging to identify what’s real and what’s not. Even the most tech-savvy among us may fall victim if a message taps into our pre-existing beliefs (due to confirmation bias) or strong emotions like political outrage or our fear of missing out.

Who is responsible for preventing smishing? 

Determining who bears responsibility for preventing smishing is a contentious and unresolved question, with blame often shifting among telecom providers, tech platforms, and end users. Mobile carriers have come under increasing scrutiny for their sluggish implementation of safeguards like SMS Sender ID protection, spam filtering, and number authentication protocols. Critics argue that because telcos serve as the gatekeepers of SMS infrastructure, they are uniquely positioned to detect and block fraudulent traffic before it reaches the user. Yet many providers have delayed adopting advanced fraud detection systems, citing cost, technical complexity, or legal ambiguity about their role in content moderation. In the meantime, cybercriminals continue to exploit SMS systems that remain largely unregulated, taking advantage of the fact that, unlike email, text messaging lacks standardized sender verification protocols such as SPF, DKIM, or DMARC.11

At the same time, tech platforms, including job boards, messaging apps, and social media companies, also play a role in enabling or deterring smishing. Many smishing campaigns begin with fraudulent job ads or phishing links posted on legitimate platforms, making their way to victims via direct messages or texts. These companies, critics argue, have a responsibility to vet listings and detect coordinated abuse of their systems, but platform accountability is complicated by questions of scale, privacy, and jurisdiction. Some companies have pursued necessary change anyway: the instant messaging platform WhatsApp, for example, actually implemented such measures after misinformation-fueled violence in India. The platform limited the number of times a message can be forwarded (which has also been shown to help slow phishing).10 

Once again, smishing thrives not just because of individual technical error, but because it leverages collective social dynamics. Unfortunately, public awareness campaigns tend to shift the burden to users, encouraging individuals to scrutinize messages and avoid suspicious links. While digital literacy is an important layer of defense, relying too heavily on user vigilance overlooks the structural failures that allow these scams to proliferate in the first place. A comprehensive solution requires shared responsibility across all stakeholders (including us as users, along with the designers of the platforms and the regulators) to create a more secure messaging ecosystem.

Controversies

Smishing might seem like it’s about simple scam texts, but it sits at the intersection of digital inequality, cybercrime, and human trafficking. Those most vulnerable, including older adults, low-income users, and digitally underserved communities, are disproportionately targeted, while many of the messages themselves are sent by trafficking victims trapped in scam compounds, forced to commit fraud under threat of violence. As law enforcement struggles to dismantle these highly networked, transnational operations, it’s clear that smishing isn’t just a technical issue; it’s a global justice crisis demanding structural solutions.

Digital inequality and vulnerability to smishing

Digital inequality is the uneven access to and ability to use digital technologies, and it plays a critical role in shaping who is most at risk of falling for smishing attacks. While anyone can receive a fraudulent text, those with limited digital literacy, fewer technological resources, or who face any number of other socioeconomic disadvantages are disproportionately vulnerable. For example, older adults, who may be less familiar with smartphone settings or online scams, are more likely to trust messages that appear authoritative or urgent. Factors like cognitive aging, lack of exposure to online safety protocols, and unfamiliarity with smishing tactics combine to make this group a frequent target of SMS-based fraud.12

Beyond age, educational attainment and economic resources strongly influence one’s capacity to detect and respond to smishing attempts. Individuals with minimal internet experience or limited formal education may not recognize common warning signs, such as suspicious URLs or uncharacteristic language. Moreover, communities facing systemic disadvantages, whether related to income, race, geography, or language, often lack access to cybersecurity education or tools like multifactor authentication and password managers. This makes them more susceptible not only to the initial deception but also to the longer-term impacts of identity theft or financial fraud.13

The COVID-19 pandemic starkly illustrated these dynamics. While wealthier users quickly adapted to remote work with secure systems and received regular fraud alerts, many lower-income individuals had to rely on shared devices or outdated phones with minimal protections. During this time, smishing attacks surged, often disguised as messages about government relief programs, job offers, or urgent health information, targeting precisely those who were most economically and socially vulnerable.6,12,13 Once scammed, people with greater financial means could often recover more easily, hiring digital investigators or leveraging institutional support, while those without such resources faced longer-lasting disruptions to their lives.11 

Addressing this inequity requires us to rethink how cybersecurity awareness and protections are distributed. Public health-style campaigns like those we saw during COVID-19, simplified security tools (so that even grandparents can understand), and community-based digital literacy programs are key to reaching underprotected populations.6 We can also leverage the power of behavioral science by designing default protections (like browser phishing filters and AI-based threat detection) that minimize user burden, particularly for those unable to recognize threats on their own.12 Scholars like Mary Aiken have argued for a more inclusive “cyber-psychology” approach that considers social and psychological vulnerabilities alongside technical ones.8 As smishing attacks continue to evolve, any serious response must include structural efforts to close the digital divide and ensure that cybersecurity is not a privilege, but a baseline right for all.

Large-scale forced smishing centers 

I recently listened to a podcast where a caller posed an ethical dilemma: he often got texts from unknown numbers (as many of us do), which were clearly smishing attempts. He liked to mess with the people on the other end of the line, going back and forth with them until they finally gave up and moved on to another potential victim. This person was wondering if it was okay to lead the scammers on, as he felt they deserved to be messed with as retribution for the harm they were causing other people. 

The podcast hosts, however, had an interesting response: first, they discouraged everyone from responding to obvious smishing attempts, as any time you respond you not only increase your risk for getting involved in that particular scam, but you also indicate to scammers that your phone number is active and you’re a good target. But secondly, they discouraged people from responding because they explained that, while we may picture those on the other end of smishing attacks as evil cyber-villains who deserve to be messed with, this isn’t always the case. Recent reporting has uncovered an entire network of human trafficking dedicated to forcing people to perpetrate tech scams. 

This new form of cyber-enabled human trafficking has taken root in so-called “fraud factories,” which are scam compounds where victims are forced to participate in large-scale digital fraud, often through smishing. These individuals aren’t perpetrators, but coerced workers, many of whom were recruited under false pretenses and now endure conditions indistinguishable from modern slavery. The victims are often young, educated, and tech-literate, drawn from countries with high unemployment and limited economic mobility, like Ghana, Nigeria, Myanmar, the Philippines, Brazil, and India.14 Many are proficient in multiple languages or have basic IT experience, skills that traffickers actively seek out to lend credibility to their scams.

The pathways into the scam centers are as deceptive as the scams themselves, because the recruitment process typically begins with fraudulent online job postings that advertise high-paying opportunities in digital marketing, tech support, or customer service. These advertisements are often polished and professional, and some victims report going through multiple rounds of realistic interviews, speaking to “HR personnel” who seem knowledgeable and trustworthy. Once the victim accepts the offer and arrives at the job site (often in Southeast Asia), they’re met not with office cubicles but with armed guards, confiscated passports, and locked gates. From that point forward, their lives become tightly controlled. Victims are typically forced to conduct scams around the clock, including sending smishing messages, catfishing targets, or harvesting personal information through fake links, all while under constant surveillance.14 

Inside these compounds, scam operations are often highly systematized, mimicking the structure of legitimate tech companies. Victims are divided into teams and assigned roles based on their skills: some handle customer-facing communication, others manage cryptocurrency wallets, and more tech-savvy individuals may be forced to build the very software and platforms that enable the scams. In one documented case, a computer engineer trafficked from Myanmar was ordered to develop artificial intelligence tools for more convincing scam content, later stating the systems she was forced to build were “more advanced than anything [she] had seen in the world.” In many compounds, those who refuse to work or fail to meet scam quotas are beaten, starved, or sold to other criminal groups. What’s more, many of the people being trafficked (particularly young women) are forced into digital sex work, trying to lure in male targets with sexually explicit phone calls, nude images, or promises of sexual favors.14 

Catching and prosecuting the criminals behind smishing scam centers

Bringing the perpetrators of smishing and scam centers to justice presents one of the most complex challenges in modern transnational crime enforcement. These operations are not run by isolated actors but by highly networked criminal syndicates with ties to human trafficking, cybercrime, and financial fraud. The individuals running these centers often operate from legal gray zones, regions where government oversight is weak, corruption is widespread, or where officials are directly complicit. In countries like Myanmar and Cambodia, scam centers have thrived in special economic zones or border territories controlled by militias or non-state actors, shielding them from state intervention and complicating external legal action.14

Many of the masterminds behind these operations rely on layers of plausible deniability. Properties are often owned by a landlord-esque figure (a head criminal who often doesn’t even speak the same language as the victims but rents to other groups), creating distance between those profiting and those perpetrating the daily abuses. On paper, these compounds may be registered as call centers or tech hubs, obscuring their true function. Criminals often use fake identities, offshore shell companies, and cryptocurrency to obfuscate financial trails, making traditional money laundering investigations ineffective. Even when evidence exists, extradition is rare, and prosecutions across jurisdictions are fraught with diplomatic and procedural hurdles.14

Despite enduring coercion and abuse, many victims of scam centers are misidentified as perpetrators rather than survivors of trafficking. Because they are often caught mid-scam (sending the smishing messages or managing fraudulent accounts), they may not fit the stereotypical image of a victim in the eyes of authorities. Legal protections vary widely across jurisdictions, and only a few Southeast Asian nations have explicitly adopted the UNODC’s non-punishment principle, which affirms that trafficking victims should not be prosecuted for crimes they were forced to commit.14 Without clear survivor-centered frameworks, victims risk detention, deportation, and further trauma, while critical investigative leads are lost, hindering efforts to dismantle the operations that exploited them.

Catching and prosecuting the organizers behind smishing centers is especially difficult because these networks are transnational, digitally sophisticated, and often operate in legally murky or politically unstable regions. Unlike street-level scams, these operations involve encrypted communication platforms, cryptocurrency laundering, and layered corporate ownership structures designed to shield leadership from exposure. Prosecuting the masterminds requires not only cross-border collaboration but also advanced digital forensics, access to financial data, and victim cooperation, often in the face of language barriers, psychological trauma, and fear of reprisal. Although cybercrime and anti-trafficking units are working to build this capacity, many lack the resources or jurisdictional reach to pursue high-level actors.

Some progress is being made: countries like Thailand and the Philippines are partnering with INTERPOL and ASEAN to strengthen regional enforcement frameworks, while legal experts and advocacy groups call for international recognition of scam centers as organized criminal enterprises.6,14 This could open the door to stronger legal tools such as asset freezes, targeted sanctions, and broader application of international anti-slavery laws. These developments offer hope, but the reality remains stark: the global machinery that enables digital fraud and human trafficking is still far more agile and resourced than the systems designed to combat it. Closing that gap will require not only better laws, but also coordinated technological innovation and survivor-centered justice.

Case Studies

The 2021 Flubot attack and smishing research 

The Flubot malware campaign, which was most active from 2021 to 2022, stands out as one of the most prolific global examples of smishing in action. Targeting primarily Android users across Europe, Australia, Japan, and the United States, the attack relied on deceptive SMS messages impersonating trusted delivery services like DHL and FedEx. These messages urged recipients to click a link to track a package, playing on the surge in online shopping during the COVID-19 pandemic. Once clicked, users were prompted to install a seemingly legitimate tracking app, which was, of course, actually a sophisticated form of malware.15 This fake app didn’t just compromise the device it was installed on, it also used the victim’s contact list to send out additional infected messages, allowing Flubot to spread virally and autonomously from one phone to the next.

What made Flubot particularly dangerous was its combination of social engineering and technical exploitation. Flubot, like any other smishing campaign, used the directness and immediacy of SMS to bypass spam filters and reach users instantly. It also exploited Android's flexibility in app installation, and specifically the ability to side-load apps from unofficial sources, a vulnerability not as prevalent in Apple’s more locked-down iOS ecosystem. Beyond spreading itself, Flubot sought to harvest banking credentials, passwords, and personal information, posing a serious financial and privacy risk. The campaign demonstrated the growing convergence of mobile malware and smishing and served as a wake-up call for both individual users and mobile security experts, underscoring the need for greater platform-level safeguards and user education on how to detect threats to stem the spread of such scalable cyberattacks.15

In another research project, scientists designed fake smishing messages and sent them to 265 users to measure the efficacy of smishing attacks. They sent eight fake text messages to participants and recorded their responses (whether they clicked on the links, replied to the message, etc.) along with their feedback in a post-test survey. The results showed that 16.92% of the people who received the messages would’ve likely fallen for the smishing attack. Unfortunately, when they tested a repeat smishing attempt, sending the same participants a different message than the one they received in the first round, nearly 12.82% potentially fell for the attack again.16

A refund? Roger that

In July 2022, Rogers Communications, one of Canada’s largest telecommunications providers, experienced a massive, nationwide service outage that disrupted mobile, internet, and emergency services for over 12 million people. In the wake of this highly publicized event (and amid a lot of justified public frustration and confusion), a wave of smishing attacks swiftly followed. Cybercriminals sent fraudulent SMS messages to Rogers customers, claiming they were eligible for a refund due to the outage. The messages appeared to come from legitimate sources and included a link to a spoofed refund portal that mimicked Rogers’ branding and website design.17

Victims who clicked the link were prompted to enter personal and financial information, believing they were receiving compensation. In reality, the data was harvested by attackers for use in identity theft and financial fraud. This social engineering tactic succeeded not by technical sophistication alone, but by manipulating people’s emotions, which we know are powerful motivators. Those emotions included, for example, intense anger, a distaste for inconvenience, and trust in a known company during a chaotic time. Because the outage was widely reported in the media, the scam had an air of legitimacy that lowered users' suspicion and increased their likelihood of engaging with the fraudulent message.17

Experts like John Lawford, who works at the Public Interest Advocacy Centre in Ottawa, have criticized Rogers and the Canadian Radio-television and Telecommunications Commission (CRTC) for taking two full years to deliver a report on the outage.17 He argues that these major organizations have underemphasized the impact of their missteps and haven’t done enough to protect people from future smishing schemes. The Rogers smishing incident illustrates how attackers can capitalize on real-world events to dramatically increase the effectiveness of phishing campaigns. Rather than randomly targeting users, these scams are precisely timed to exploit heightened emotions, uncertainty, and expectations of institutional response. It also reveals a growing trend in smishing: pairing impersonation with contextual opportunism. As such events become more common, organizations are being urged to prepare crisis communication protocols that include fraud alerts, while users must remain wary of any unsolicited message (even those that seem helpful) following a public disruption.

Related TDL Content

How to Protect An Aging Mind From Financial Fraud 

Because older generations are so often the targets of financial fraud, and are often more susceptible to smishing schemes, it’s extra important for aging minds to protect themselves from fraud. This article outlines why older populations are more susceptible to financial fraud, as well as research on how to alter our decision-making environments to protect ourselves from such attacks. 

The Human Error Behind Fake News with David Rand 

Smishing attempts are often about deceit, and the rise of the internet has led to an abundance of new scams and misinformation. In this podcast episode, David Rand, professor of Management Science and Brain and Cognitive Sciences at MIT, discusses his research on misinformation, aiming to understand why people believe fake news, why it is spread in the first place, and what people can do about it.

References

  1. Alkhalil, Z., Hewage, C., Nawaf, L., & Khan, I. (2021). Phishing attacks: A recent comprehensive study and a new anatomy. Frontiers in Computer Science, 3. https://doi.org/10.3389/fcomp.2021.563060
  2. Jakobsson, M., & Myers, S. (2006). Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Theft. MIT Press.  
  3. Rader, Marc & Rahman, Shawon. (2015). Exploring Historical and Emerging Phishing Techniques and Mitigating the Associated Security Risks. International Journal of Network Security & Its Applications. 5. 10.5121/ijnsa.2013.5402.  
  4. Blancaflor, E., Romero, M. A., Nacu, I., & Golosinda, D. R. (2023). A case study on smishing: An assessment of threats against mobile devices. In Proceedings of the 2023 9th International Conference on Computer Technology Applications (pp. 172–178). Association for Computing Machinery. https://doi.org/10.1145/3605423.3605446 
  5. Blau, J. (2006, August 27). Beware of ‘SMiShing’ attacks, McAfee tells cell phone users. IT World Canada. https://www.itworldcanada.com/article/beware-of-smishing-attacks-mcafee-tells-cell-phone-users/6637
  6. Interpol. (2020). INTERPOL report shows alarming rate of cyberattacks during COVID-19. https://www.interpol.int/en/News-and-Events/News/2020/INTERPOL-report-shows-alarming-rate-of-cyberattacks-during-COVID-19 
  7. Federal Bureau of Investigation. (2022, May 4). Business Email Compromise: The $43 billion scam (I-050422-PSA). https://www.ic3.gov/PSA/2022/psa220504
  8. Aiken, M. (2016). The cyber effect: A pioneering cyber-psychologist explains how human behavior changes online. Spiegel & Grau.
  9. Xu, H., Qadir, A., & Sadiq, S. (2025). Malicious SMS detection using ensemble learning and SMOTE to improve mobile cybersecurity. Computers & Security, 154, 104443. https://doi.org/10.1016/j.cose.2025.104443
  10. Newton, C. (2020, April 7). WhatsApp puts new limits on message forwarding to fight spread of misinformation. The Verge. https://www.theverge.com/2020/4/7/21211371/whatsapp-message-forwarding-limits-misinformation-coronavirus-india 
  11. Nightingale, J. (2017), Email Authentication Mechanisms: DMARC, SPF and DKIM, Technical Note (NIST TN), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.TN.1945
  12. James, B. D., Boyle, P. A., & Bennett, D. A. (2014). Correlates of susceptibility to scams in older adults without dementia. Journal of elder abuse & neglect, 26(2), 107–122. https://doi.org/10.1080/08946566.2013.821809 
  13. Ogunola, A., Sonubi, T. O., & Toromade, R. O. (2024, November). The intersection of digital safety and financial literacy: Mitigating financial risks in the digital economy. International Journal of Science and Research Archive, 13(2), 673–691. https://doi.org/10.30574/ijsra.2024.13.2.2183 
  14. Miller, C., & Koser, K. (2024, June 12). Cyber scamming goes global: Sourcing forced labor for fraud factories. Center for Strategic and International Studies (CSIS). https://www.csis.org/analysis/cyber-scamming-goes-global-sourcing-forced-labor-fraud-factories 
  15. National Cyber Security Centre. (n.d.). Scam “missed parcel” SMS messages: Advice on avoiding malware. https://www.ncsc.gov.uk/guidance/scam-missed-parcel-sms-messages
  16. Rahman, M. L., Timko, D., Wali, H., & Neupane, A. (2023). Users really do respond to smishing. In Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy (pp. 49–60). Association for Computing Machinery. https://doi.org/10.1145/3577923.3583640 
  17. Zimonjic, P. (2024, July 5). Human error caused 2022 Rogers outage, system ‘deficiencies’ made it worse: report. CBC News. Retrieved June 23, 2025, from https://www.cbc.ca/news/politics/rogers-outage-human-error-system-deficiencies-1.7255641

About the Author

A smiling woman with long blonde hair is standing, wearing a dark button-up shirt, set against a backdrop of green foliage and a brick wall.

Annika Steele

Talent Acquisition Specialist, GiveWell

Annika completed her Masters at the London School of Economics in an interdisciplinary program combining behavioral science, behavioral economics, social psychology, and sustainability. Professionally, she’s applied data-driven insights in project management, consulting, data analytics, and policy proposal. Passionate about the power of psychology to influence an array of social systems, her research has looked at reproductive health, animal welfare, and perfectionism in female distance runners.

About us

We are the leading applied research & innovation consultancy

Our insights are leveraged by the most ambitious organizations

Image

“

I was blown away with their application and translation of behavioral science into practice. They took a very complex ecosystem and created a series of interventions using an innovative mix of the latest research and creative client co-creation. I was so impressed at the final product they created, which was hugely comprehensive despite the large scope of the client being of the world's most far-reaching and best known consumer brands. I'm excited to see what we can create together in the future.

Heather McKee

BEHAVIORAL SCIENTIST

GLOBAL COFFEEHOUSE CHAIN PROJECT

OUR CLIENT SUCCESS

$0M

Annual Revenue Increase

By launching a behavioral science practice at the core of the organization, we helped one of the largest insurers in North America realize $30M increase in annual revenue.

0%

Increase in Monthly Users

By redesigning North America's first national digital platform for mental health, we achieved a 52% lift in monthly users and an 83% improvement on clinical assessment.

0%

Reduction In Design Time

By designing a new process and getting buy-in from the C-Suite team, we helped one of the largest smartphone manufacturers in the world reduce software design time by 75%.

0%

Reduction in Client Drop-Off

By implementing targeted nudges based on proactive interventions, we reduced drop-off rates for 450,000 clients belonging to USA's oldest debt consolidation organizations by 46%

Read Next

Notes illustration

Eager to learn about how behavioral science can help your organization?