What is a 'smishing' attack and what makes SMS a particularly effective phishing vector on mobile?
- A.Message phishing may be less effective than the mail equivalent, and a recipient reads a text with more care than an inbox item (the channel carries fewer messages a day), leaving the conversion rate lower for an operator working this way across a large list, and the effort rarely repaid, and the channel largely abandoned
- B.Smishing (SMS phishing) exploits the fact that mobile browsers truncate URLs making deception easier, SMS lacks the visual phishing indicators email clients provide, carrier infrastructure appears trusted, and SMS delivery bypasses corporate email filters that might catch phishing emails
- C.The technique may require the operator to know the recipient's number ahead of the campaign, and a list has to be purchased or harvested first (the sending platform rejects a generated sequence), leaving reconnaissance the limiting factor, and the effectiveness a function of list quality rather than of anything in the channel