Your phone buzzes.
A message from what appears to be your bank, and the message reads: ” Unusual activity detected on your account; verify immediately, or it will be suspended.
There’s a link. You click on it and get redirected to a site that looks like your bank, or you’re asked to download a new file or app.
Your card has been genuinely useful to you this week, and the timing feels plausible. You have about four seconds to act on instinct before your thumb decides.
That’s a smishing attack, and it works far more often than most people would like to believe. Because they can scale and be paired with customer data dumps to fool users into thinking it’s part of their usual security measures, Smishing attacks can be very profitable for hackers.
Defining Smishing
Smishing — a contraction of SMS and phishing — is a social engineering attack delivered by text message. The attacker sends a message designed to provoke an immediate response: clicking a malicious link, calling a fraudulent number, downloading an application, or replying with sensitive information.
The mechanics are the same as email phishing or Wi-Fi phishing. The goal is identical: harvest credentials, install malware, or manipulate the victim into authorising a payment. What changes is the channel, and the channel changes everything about how effective the attack is.
Why Text Messages Are Unusually Effective
Open rates are extraordinary. Text messages are read within minutes of arrival in most cases. Email sits unread for hours. Attackers reach their target almost immediately, which matters when the attack depends on manufactured urgency.
Mobile screens hide the warning signs. On a desktop, you hover over a link and read the destination in the status bar. On a phone, you can’t hover. Link shorteners obscure destinations entirely. The address bar in a mobile browser truncates URLs, so a convincing lookalike domain displays exactly like the real thing.
Text feels more legitimate than email. People have been trained for two decades to be sceptical of email. SMS still carries residual trust — partly because legitimate institutions genuinely do use it for one-time PINs, delivery notifications, and security alerts.
Security tooling is thinner. Corporate email passes through filtering, sandboxing, link rewriting, and attachment scanning. Text messages arrive on a personal device, over a mobile network, with none of that in the path. The employee is the entire security control.
Context collapses on mobile. People check messages while walking, in meetings, between tasks. Attackers are deliberately exploiting divided attention, and divided attention is the natural state of phone use.
How Are These Attacks Constructed?
Smishing attacks can use a host of ploys to get you to act, from impersonating your bank, a government institution, a courier service, or a supplier invoice, and much more.
Impersonating financial institutions
The most common pattern. A message purporting to come from a bank warns of a suspicious transaction, a blocked card, or a login from an unrecognised device. The link leads to a convincing replica of the bank’s login page, capturing the username, password, and often the one-time PIN in real time as the attacker enters them into the genuine site.
Fake delivery notifications
A parcel could not be delivered. A customs fee is outstanding. Reschedule delivery here. These succeed on sheer probability — a meaningful proportion of recipients genuinely are expecting a package, and the message costs the attacker nothing to send at volume.
Impersonating SARS, municipalities, or government
A refund is available. An outstanding amount must be settled. A penalty has been issued. Official-sounding language combined with financial consequences drives compliance, especially when the message arrives during a period when people expect official contact.
Executive impersonation
A message arrives claiming to be from a senior executive, often explaining that they’re using a personal number because they’re travelling or their phone was replaced. The request follows: an urgent payment, gift card purchases, or updating a supplier’s banking details. This variant specifically targets finance and administrative staff and exploits organisational hierarchy.
Fake IT support
A message from IT Support claims the recipient’s corporate account will be suspended, or that a password reset is required following a security incident. The link harvests corporate credentials, which the attacker then uses to access email, cloud storage, and business systems.
Malicious application installation
Less common but more damaging, some attacks direct victims to install an application — often framed as a security tool, a banking app update, or a required delivery tracker. The installed application harvests credentials, intercepts one-time PINs, or provides ongoing remote access to the device.
Smishing in the South African Context
Several local conditions make these attacks particularly potent here.
Mobile-first banking is the norm. A large proportion of South Africans manage their finances primarily through mobile apps and receive legitimate SMS alerts for transactions, which normalises the format an attacker is imitating.
Bring-your-own-device is widespread. Employees routinely access corporate email, Teams, and business applications from personal phones. A credential harvested through a personal-device attack becomes a corporate breach without ever touching a company-owned asset.
SIM swap fraud compounds the risk. South Africa has a well-documented SIM swap problem, and smishing frequently serves as the reconnaissance step — gathering the personal details needed to convince a mobile operator to port a number, after which one-time PINs go directly to the attacker.
Mobile number portability and prepaid SIMs make attacker attribution difficult and make sending numbers effectively disposable.
What It Costs a Business
A single successful attack rarely stops at one compromised account. Harvested corporate credentials give an attacker access to email, which gives them access to password reset flows for other systems, which gives them a foothold to move laterally.
From there, the consequences are familiar.
Fraudulent payment instructions sent from a genuine internal mailbox, business email compromise targeting your customers and suppliers, exfiltration of personal information triggering POPIA notification obligations, and in the worst cases, ransomware deployed from a legitimate account that security tooling has no reason to question.
The initial text message costs the attacker nothing. The response costs the business a great deal.
Recognising an Attack
Certain characteristics recur across almost all smishing attempts.
Urgency with a deadline — act now, within 24 hours, or the account closes. Legitimate institutions rarely, if ever, compress decision windows this aggressively.
A link in an unsolicited message. Most South African banks explicitly state they will never send a link asking you to log in. That policy exists precisely because of these attacks.
Requests for information the sender should already have. Your bank knows your account number. It does not need you to text it back.
Slightly wrong details — a shortened or unfamiliar domain, a generic greeting where a name would be expected, subtle grammatical errors, or a sender number that doesn’t match previous legitimate messages from that organisation.
A message that arrives with no context, referencing a transaction you didn’t make, a parcel you didn’t order, or an account you don’t hold.
A request to move the conversation to another channel — call this number, message this WhatsApp account — which takes the target away from any record and into a live conversation where pressure can be applied directly.
Practical Defences
Set a verification rule and stick to it. Never act on a link in an unsolicited message. Navigate independently — open the banking app, type the known URL, or call the number printed on the back of your card. This single habit neutralises most attacks.
Deploy phishing-resistant multi-factor authentication. SMS-based one-time PINs can be intercepted through SIM swap or relayed in real time by an attacker. Authenticator applications are better; hardware security keys and passkeys are better still, because they cryptographically bind authentication to the legitimate domain and simply will not work on a lookalike site.
Require out-of-band confirmation for payments. Any instruction to make a payment, change banking details, or purchase vouchers must be confirmed by voice on a number already held in company records — never a number supplied in the message itself. Make this a documented policy, not an expectation.
Secure personal devices that touch corporate data. Mobile device management, conditional access policies, and remote access revocation limit how far a compromised personal phone can reach into business systems.
Train specifically on SMS, not just email. Most security awareness programmes focus entirely on email. Employees who would scrutinise a suspicious email will click a text without hesitation because nobody ever told them the same rules apply. Include realistic SMS scenarios in training.
Build a blame-free reporting channel. The most valuable thing an employee can do after clicking a malicious link is tell someone within minutes. That only happens in organisations where reporting a mistake is treated as helpful rather than embarrassing. Make reporting easy, acknowledge it positively, and act on it fast.
Monitor for the aftermath. Assume some attacks will succeed. Detect anomalous logins, impossible travel, unusual mailbox rules, and unexpected data access to turn a compromised credential into a contained incident rather than a breach.
If Someone Has Already Clicked
Speed matters more than anything else. Change the password for the affected account immediately, and any account sharing that password. Revoke active sessions so an existing login is terminated rather than left running. Check the mailbox for forwarding rules or filters the attacker may have created to hide their activity.
Contact the bank directly if you entered financial credentials. Notify your IT or security provider so they can review access logs and assess scope. If personal information may have been exposed, assess your POPIA notification obligations early rather than late.
Then — and this matters for everyone else in the organisation — communicate. If one employee received the message, others almost certainly did too.
Where Kinetix Fits Into Your Security Protocols
Smishing succeeds because it targets people on devices that sit outside most corporate security controls, using a channel most awareness training ignores. Defending against it requires technical controls, clear policy, and employees who know what to look for.
Kinetix Group helps South African businesses secure their data and communications — deploying authentication services, securing the personal devices that access your systems, building payment verification processes that fraud can’t talk its way past, and running awareness training that covers how attacks actually arrive rather than only how they arrived a decade ago.
Get in touch for an assessment of how exposed your business is to phishing and its mobile variants.

