You have probably recently seen a wave of SMS messages being received around you about a Crit’Air sticker to be collected within 48 hours or the expiry of your health insurance card via Ameli. These were SMiShing campaigns. With open and click-through rates 8 times higher than email phishing, SMiShing has become cybercriminals’ preferred communication channel.
What is SMiShing?
SMiShing, or SMS phishing, is a scam method in which a cyberattacker sends an SMS message to hundreds of recipients using a “SIM bank,” a device containing dozens of SIM cards. The goal is to exploit people’s curiosity (parcel delivery), guilt (an unpaid bill), or offer them a quick gain (CPF – Personal Training Account) in order to obtain actions that can compromise a user’s data or an organisation’s infrastructure. The number of such attacks increased by more than 37% in 2021, and for good reason: it is much faster to set up an SMS phishing campaign than an email one. Indeed, an SMS message does not require as much personalisation to be credible, and protection tools are less widespread. Furthermore, users are less informed about the risks associated with SMS phishing than with email phishing. According to the State of the Phish report, awareness of cybersecurity-related terminology declined between 2020 and 2021. In 2021, only 23% of study participants identified the definition of SMiShing in a multiple-choice questionnaire. It is therefore essential to stay informed and raise awareness about SMS phishing in order to limit the harmful impact of these attacks.
“While 2020 taught us the need to be agile and responsive in the face of change, 2021 showed us the need to better protect ourselves,” said Loïc Guézo, Director of Cybersecurity Strategy SEMEA at Proofpoint France. “Although email remains cybercriminals’ preferred attack method, it is clear that we need to establish a security culture. In this constantly evolving threat landscape, and as remote work becomes commonplace, it is essential for organisations to empower their employees and support their efforts to learn and apply new cyber skills and behaviours—at the office, at home, and now... from anywhere!”

How can you protect yourself against SMiShing?
You can only protect yourself against SMiShing if you learn to identify the attack. Here are a few ways to spot it:
- Check the sender of the SMS message you receive. If you do not know them, do not click on any links in the message. Unlike opening an email on a computer, it is impossible to hover over a link on a smartphone. If in doubt, do not click.
- Pay particular attention to what the message is asking you to do. As with email phishing, attackers exploit urgency, greed, or curiosity to encourage victims to click on a malicious link.
- If you receive a message from a service (password update, etc.) that you have not just used, there is a strong chance that it is a SMiShing attempt.
The BlueSecure solution
BlueSecure offers SMiShing awareness services through e-learning training and SMiShing campaigns, or combined email and SMS phishing campaigns. Protect your organisation by training your employees on all the risks associated with cybercriminal attacks. Make people the strongest link in your information security.
Feel free to contact us for further information:



