Preventing Smishing Scams

Access this expert-led webinar instantly, available anytime on-demand.

Included in All-Access Membership
Live Webinar - no upcoming date
Customer Satisfaction Guarantee Learn with confidence. If you're not happy, we'll make it right. That's our guarantee.

Purchase Options

Select an attendee quantity to add to cart.

Recorded Webinar Only

$219.00
or

All Access Membership

The Aurora All Access Membership is designed to provide you with the training that you want when you want it. You will have 100% access to every live webinar, on demand webinar, professional alert, and podcast that Aurora Training Advantage offers with no additional cost.

Learn More About Our All Access Membership
$599.00
All Access Membership

While we all may be familiar with phishing scams. There has been a sharp increase in fraudulent text messages to consumers.

What is smishing? These texts are actually scams that have been dubbed “smishing” – combining “SMS” and “phishing” – and your employees are no doubt receiving them, too.

Impersonating reputable companies or vendors, possibly even your company. The link will often end up having unsuspecting malware downloaded to the mobile device, or will be lead to a legitimate-looking form to “log in” and voluntarily provide a trove of valuable data. Smishing attacks increased 24% in the U.S. alone and 69% globally last year. According to data from the Federal Trade Commission, 21% of fraud reports that were filed in 2021 involved smishing. That’s 377,840 out of the total 1,813,832 reports that identify a contact method. Of those hundreds of thousands of claims, a total of $131 million was lost, with an average of $900 per report. This impacts employers who provide devices to employees. Remote work makes this more problematic.

What can employers and employees do? 

  • Develop Strong BYOD Policies
  • Stay Up to Date
  • Keep Things Need-to-Know
  • Enable Multi-Factor Authentication
  • Annual Training 
  • Brett P. Owens

ATAHR Credit

Aurora Training Advantage is offering continuing education points designed to recognize dedication to training and excellence in human resources.

Customer Satisfaction Guarantee
Invest in your future with confidence! Our Customer Satisfaction Guarantee eliminates all risk, letting you focus purely on mastering new skills and advancing your career. If you're not completely satisfied, we'll ensure you are. Your satisfaction is not just a promise; it's our guarantee.

Frequently Asked Questions

Smishing — a portmanteau of SMS and phishing — is a form of social engineering fraud conducted through text messages rather than email, designed to trick recipients into clicking malicious links, downloading malware, or surrendering sensitive information. Smishing attacks increased 24% in the United States and 69% globally in recent years, making it one of the fastest-growing cybersecurity threats facing both individuals and organizations. According to the FTC, smishing accounted for 21% of fraud reports in 2021, representing $131 million in losses at an average of $900 per report. For employers, smishing is a serious organizational risk because employees receive these fraudulent texts on both personal and employer-provided devices — and in remote and hybrid work environments, the boundary between personal and professional communication is increasingly blurred. Attackers frequently impersonate reputable companies, government agencies, or even the victim's employer to create urgency and familiarity. When employees click malicious links on work-related devices, the consequences can include malware installation on corporate networks, credential theft that enables unauthorized system access, and data breaches that expose sensitive business and customer information. HR professionals who educate employees on smishing prevention and support the implementation of protective policies are critical frontline defenders against this growing threat.
Smishing attacks typically follow a pattern designed to bypass skepticism through urgency, authority, and apparent legitimacy. A fraudulent text might impersonate a bank claiming suspicious account activity and requesting immediate login, a delivery service claiming a package requires action before delivery, a government agency demanding response to avoid legal consequences, or even the employee's own employer claiming an urgent payroll or IT issue. The message typically includes a shortened or misleading URL designed to look legitimate but that redirects to a malicious site — where either credentials are harvested through a fake login page or malware is downloaded automatically when the link is opened. Warning signs employees should learn to recognize include: unexpected texts from organizations they did not initiate contact with, urgent language demanding immediate action, requests for personal information, login credentials, or payment via text, URLs that do not match the claimed sender's legitimate domain, and grammatical errors or unusual phrasing. Employees should never click links in unsolicited text messages — instead, independently navigate to the organization's official website or call their official customer service number if the message seems plausible. For employer-issued devices, forwarding suspicious texts to the IT security team enables investigation and potential blocking of the malicious domain for all employees.
Bring Your Own Device (BYOD) policies are a critical organizational defense against smishing risk, particularly as personal smartphones increasingly handle business communications, email, and applications. An effective BYOD policy for smishing protection should require that personal devices used for business purposes have up-to-date operating systems and security patches, since vulnerabilities in outdated software are commonly exploited by malware delivered through smishing links. Enrolling personal devices in a Mobile Device Management (MDM) platform allows IT to enforce security configurations — including app restrictions, remote wipe capability, and monitoring for malware — without accessing personal data. Policies should prohibit the installation of apps from unofficial sources on any device used for business, as unofficial apps frequently contain malware. Requiring employees to use separate secure containers or work profiles for business applications isolates business data from personal apps that may have weaker security. BYOD policies should also define what happens when a personal device is compromised — including the employer's right to remotely wipe business data if a security incident is detected. Training employees on smishing recognition should be delivered at BYOD onboarding and annually thereafter, reinforcing that the security of employer data is a shared responsibility regardless of device ownership.
Multi-factor authentication (MFA) is one of the most effective technical controls against smishing-enabled credential theft, because it requires attackers to obtain a second verification factor beyond a stolen username and password before gaining account access. When an employee falls for a smishing link and enters their credentials into a fake login page, the attacker captures those credentials — but if MFA is enabled, they still cannot access the account without the second factor, such as a one-time code sent to the employee's registered device, a push notification requiring approval, or an authenticator app code. This makes MFA a powerful backstop that limits the damage of a successful credential-phishing smishing attack. However, it is important to note that sophisticated smishing attacks can attempt to bypass MFA through techniques such as real-time phishing proxies that capture the MFA code as the victim enters it, or SIM-swapping attacks that redirect the victim's phone number to attacker-controlled devices. These risks make authenticator-app-based or hardware-token MFA more secure than SMS-based one-time codes for high-risk accounts. Employers should require MFA for all business systems accessible remotely — email, VPN, HR systems, financial platforms — and educate employees to never share or approve MFA prompts they did not personally initiate. Annual cybersecurity training that covers MFA best practices is a practical HR and IT collaboration that significantly reduces organizational risk.
Annual cybersecurity awareness training that covers smishing is an essential and often legally required organizational control — many data protection regulations and cyber insurance policies mandate documented employee security training. Effective training on smishing should cover what smishing is and how it differs from phishing, common attack scenarios employees are likely to encounter (including impersonation of employers, banks, delivery services, and government agencies), specific warning signs that distinguish fraudulent texts from legitimate communications, and the exact steps employees should take when they receive a suspicious text — including not clicking the link, reporting to IT security, and deleting the message. Training should also address the organizational policies that apply — BYOD rules, acceptable use policies, and incident reporting procedures — so employees understand not just the threat but the expected response. Simulated smishing exercises — where IT security sends controlled test messages to employees and tracks who clicks — provide both a training moment and data on organizational vulnerability that informs future training priorities. Training effectiveness improves with short, scenario-based modules delivered more frequently than once annually, rather than a single long annual session. HR's role in driving training completion, integrating cybersecurity content into onboarding, and maintaining documentation of training completions is essential for both organizational protection and regulatory compliance.