What is a 'smishing' attack and what makes SMS a particularly effective phishing vector on mobile?
- A.Smishing is effective only on Android; iOS users cannot receive malicious SMS
- B.Smishing (SMS phishing) exploits the fact that mobile browsers truncate URLs making deception easier, SMS lacks the visual phishing indicators email clients provide, carrier infrastructure appears trusted, and SMS delivery bypasses corporate email filters that might catch phishing emails
- C.Smishing requires the attacker to know the victim's phone number in advance
- D.Smishing is less effective than email phishing because users are always suspicious of SMS
Why B is correct
SMS phishing vectors: (1) URL shorteners and truncated displays hide malicious domains, (2) SMS lacks sender authentication (spoofing is trivial), (3) SMS typically bypasses enterprise email security gateways, (4) mobile browsers skip the full URL bar, (5) users are conditioned to act on bank/package delivery SMS alerts. Combined, these factors make smishing conversion rates often higher than email phishing.
Know someone studying for Mobile Security Fundamentals? Send them this one.