The mobile high-tech threat: Smishing

Mon Apr 20, 2009 9:55AM EDT

See Comments (123)

What's the best way to disguise a phishing attempt so no one can tell where a request for personal information or a password really came from? Easy: Send it via text message.

"Smishing" is the name being given to the not-entirely-new but growing practice of sending phishing come-ons and scams via SMS message. And spammers are apparently finding it an increasingly easier proposition to text a phishing message to you rather than to email it traditionally.

Why's that? You've probably received hundreds or thousands of phishing emails and immediately saw through the ruse: Images were broken, the "from" address was wrong, words were misspelled, or links in the message were obviously directing you to phony websites. There are dozens of things that phishers have to get right for an email scam to fool anyone, and that's apparently quite difficult to do. Making things even tougher, many of those emails are now blocked by ISPs and spam filters and never make it to their intended targets.

Those problems don't really exist at the SMS level: Very few SMS messages are blocked, and since they are composed entirely of text, no images required, it's often impossible at a glance to determine if a message is real or fake.

One popular smish threatens the user that he is about to be charged for something unless he cancels it, with a message like: "We're confirming you've signed up for our dating service. You will be charged $2/day unless you cancel your order by clicking here: phonysite.com." Of course there are no pending charges, and the site you're directed to is completely fake, its goal being to collect your credit card number (which you will helpfully enter in order to "cancel" the charges), or install a bit of malware on your computer (or even, someday, on your phone).

Smishing messages may instead direct you to call a toll-free number in order to complete or cancel some financial transaction, the only difference being that a human operator will handily take down your credit card or bank account number for you, to save you the trouble of typing it online. Of course, the number you called is phony, too.

What should you do if you receive a message you fear is a smish attack? The answer should be pretty obvious but bears repeating: Virtually no credible financial institution, utility, or other business will communicate with you via SMS with the exception of your cell phone provider. Don't recognize the website or phone number being sent to you? Don't call it. If you're worried about an upcoming charge, contact the service provider or bank directly via means you know are legitimate and ask them directly about the message. They'll likely tell you what you already know: Just ignore it.

Comments on The mobile high-tech threat: Smishing

Post a Comment

Join in the discussion. Here you'll see the comments in the order they were posted.

  • 1 Posted by tinkerleah on Thu Sep 3, 2009 10:10PM EDT Report Abuse

    I did some researching for my son and all heck broke out. I get 30 to 50 emails per day now. I dont know what to do and I never signed or gave a credit card but emails to Loan Modification co to help me. HELP tink

  • 2 Posted by dgslethal on Thu Sep 3, 2009 3:42PM EDT Report Abuse

    there's also a way for companies to bill you for a service just for opening the text message. If it happens contact your provider.

  • 3 Posted by p_hall@rocketmail.com on Thu Sep 3, 2009 8:23PM EDT Report Abuse

    Wow. You are a Godsent. I got one of these messages and was about to call the number... Thank you Jesus.

  • 4 Posted by ramon461 on Thu Sep 3, 2009 8:27PM EDT Report Abuse

    Extremely simple solutions: 1) Don't use a cell phone. 2) If you use a cell phone, block all text messages. 3) Use common sense

  • 5 Posted by qbrendi on Thu Sep 3, 2009 8:23PM EDT Report Abuse

    If your child not knowingly signs up for premium messages, you can reply to Spamming text messages with the word STOP in the body of the messages

More Posts: First Prev 1 2 3 4 5 Next Last

Post a Comment


My Tech

Please enable your browser's cookies to activate the My Tech column.

Also on Yahoo! Tech

Computers Home Office Wi-Fi & Networking Phones & PDAs Cameras & Camcorders TV & Home Theater Portable Audio
 

Question and Answer content at Yahoo! Tech is written by Yahoo! users at Yahoo! Answers. Yahoo! does not evaluate or guarantee the accuracy of any Yahoo! Answers content. For more information, read the Full Disclaimer.

Opinions expressed by the Advisors are their own and do not necessarily reflect the views of Yahoo! Inc. Yahoo! receives no compensation from any manufacturer or distributor nor does it compensate any Advisor for the coverage of any product or service in any Advisor's content.