ao link
Business Reporter
Business Reporter
Business Reporter
Search Business Report
My Account
Remember Login
My Account
Remember Login

Smishing is no longer just a security problem

Text messaging is a highly trusted channel for supporting customer engagement. It is also one of the most exploited. Dr. Marco Lafrentz at the Mobile Ecosystem Forum explains why fraud linked to messaging is increasing, and how organisations should defend themselves

Linked InXFacebook

When a customer receives a fraudulent text message pretending to be from your business, the damage begins long before anyone determines where the message came from.

 

The customer may call your contact centre. A payment may be delayed. An online account may be locked. Your fraud team starts investigating. Marketing wants to reassure customers. Security wants to understand how your brand was impersonated. None of those teams sent the message, yet all of them suddenly own part of the problem.

 

That’s what makes smishing different from many other forms of fraud. It isn’t confined to cyber-security. It affects customer communications, operations, fraud management and digital identity all at once.

 

The numbers reflect the scale of the problem. According to the US Federal Trade Commission, consumers reported losing $470 million to text-message scams in 2024, compared with less than $90 million in 2020. The scams ranged from fake package deliveries and unpaid toll notices to fraudulent banking alerts and job offers. The tactics continue to evolve because they continue to succeed.

 

Many discussions about smishing focus on helping consumers recognise suspicious messages. That’s important, but it addresses the problem only after the message has been delivered.

 

Businesses have far more control over what happens before that point.

 

Start by understanding your own messaging ecosystem

 

One question often reveals more than expected:

 

How many different systems send text messages in your name?

 

The answer is frequently, "More than we thought."

 

Marketing platforms, authentication services, appointment systems, customer support applications, and third-party providers may all send SMS messages independently. They may use different sender identities, different message formats and different approval processes. Some legacy tools have been in place for years. Others were introduced to solve a specific business problem and quietly became permanent.

 

That complexity creates opportunities.

 

The more inconsistent legitimate communications become, the easier it is for a fraudulent message to blend in.

 

Before investing in new security controls, take inventory. Know every platform that sends text messages, who owns it, which vendors are involved, and how those messages appear to customers. That exercise often uncovers unnecessary duplication, outdated services and inconsistent practices that deserve attention regardless of fraud.

 

 

Make legitimate messages predictable

Customers should not have to decide whether a message "looks right."

 

Legitimate communications should follow consistent patterns. Use recognisable sender identities where possible. Keep language and formatting consistent. Make it easy for customers to understand which types of requests will never arrive by text.

 

For example, if your business will never ask someone to reply with a password, payment card information or a one-time authentication code, say so clearly. Publish that guidance where customers are most likely to look for help, not just in security documentation that few people read.

 

Predictability works in your favour. Criminals depend on uncertainty.

 

 

Protect the identities your business uses

Fraudsters often succeed by making messages appear to come from a trusted business. Companies should therefore treat their phone numbers and sender identities as assets that require active protection.

 

Speak with your messaging and telecommunications providers about the protections available in each market. Ask whether your business numbers and sender identities can be registered, verified or provisioned through relevant industry registries and operator programmes. Where possible, use dedicated sender IDs rather than shared or frequently changing numbers.

 

Businesses should also know which providers and systems are authorised to send messages using their brand. Clear approval processes make it easier to identify unauthorised activity and respond when impersonation occurs. They may also wish to explore newer methods of authenticating users through their telephone number, such as Number Verify.

 

These measures will not stop every fraudulent message, but they can strengthen trust in legitimate communications and make it harder for criminals to misuse a company’s identity.

 

 

Decide who owns the response

Sooner or later, someone will report a fraudulent text message using your company’s name.

 

What happens next?

 

If the answer depends on which department receives the complaint, valuable time will be lost.

 

Fraud, security, customer support, communications, and legal teams all have a role to play when impersonation occurs. The responsibilities should be defined before an incident, not while one is unfolding. That includes deciding who investigates reports, who works with messaging providers, who communicates with customers and who determines when a broader warning is necessary.

 

Businesses should also share relevant reports and fraud data with industry bodies and organisations that exchange fraud intelligence. With the business’s consent, service providers may be able to submit this information on its behalf.

 

The businesses that respond most effectively are rarely improvising.

 

 

Train for the attacks people are receiving today

Internal security awareness training has traditionally centred on email.

 

But now employees receive fraudulent text messages claiming to come from executives, banks, delivery companies, technology providers, and internal IT teams. The objective is usually the same: create enough urgency for someone to click a link, approve a payment, or disclose sensitive information.

 

Training should reflect those tactics. Employees should know how to verify unexpected requests through trusted channels and how to report suspicious messages quickly. A report from one employee may reveal a campaign affecting hundreds of customers.

 

Smishing is unlikely to disappear. Criminals follow the channels that produce results, and text messaging remains one of them.

 

Businesses cannot control every message that reaches an employee’s or a customer’s phone. They can control how they communicate, how consistently they manage their messaging channels, and how prepared they are when their name is used by someone else.

 

Those aren’t simply cyber-security decisions. They’re business decisions, and they’re becoming more important every year. 

 


 

Dr. Marco Lafrentz is a Mobile Ecosystem Forum (MEF) Global Board Member and Chair of the Anti-Fraud Program

 

Main image courtesy of iStockPhoto.com and Jerome Maurice

Linked InXFacebook
Business Reporter

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis Park, London, N3 1HF

23-29 Hendon Lane, London, N3 1RT

020 8349 4363

© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543