Key Takeaways
- In 2023, smishing attacks represented 12.5% of all mobile phishing incidents reported globally, marking a 47% increase from 2022
- The FBI's IC3 received over 298,000 complaints about smishing and phishing in 2022, with smishing comprising 8.2% of those
- Verizon's 2023 DBIR noted smishing as involved in 11% of social engineering breaches in the financial sector
- In the US, 68% of adults aged 18-24 reported receiving at least one smishing attempt in 2023 per FTC survey data
- Women comprised 54.2% of smishing victims reporting to IC3 in 2022, with higher susceptibility in retail banking scams
- Seniors over 60 years old accounted for 22.7% of smishing financial loss complaints to FTC in 2023, totaling $120 million
- Smishing attacks most commonly use COVID-19 package delivery lures, accounting for 29% of analyzed SMS phishing in 2023
- 42% of smishing messages impersonate banks using shortened URLs leading to credential harvesters per Proofpoint 2024
- Zero-click smishing exploits via iMessage affected 11% of iOS devices in Lookout's 2023 detections
- Global smishing losses reached $1.2 billion in 2023 per Chainalysis crypto scam report tied to SMS vectors
- Average smishing loss per victim was $1,450 in US IC3 2022 complaints, totaling $52 million from smishing alone
- Enterprise downtime from smishing breaches averaged 14 hours costing $45,000 per incident per IBM Cost of Data Breach 2023
- 82% of organizations use AI-based SMS filtering reducing smishing success by 65% per Gartner 2024 poll
- Multi-factor authentication blocked 99.9% of smishing account takeovers in Microsoft's 2023 Digital Defense Report
- Employee training reduced smishing click rates by 40% in Proofpoint's 2023 simulation benchmarks across 1,000 firms
Smishing attacks are surging globally, with steep financial losses across many demographics.
Attack Vectors and Techniques
- Smishing attacks most commonly use COVID-19 package delivery lures, accounting for 29% of analyzed SMS phishing in 2023
- 42% of smishing messages impersonate banks using shortened URLs leading to credential harvesters per Proofpoint 2024
- Zero-click smishing exploits via iMessage affected 11% of iOS devices in Lookout's 2023 detections
- QR code smishing (quishing) rose 150% in 2023, comprising 18.5% of physical-to-digital attack chains
- Nigerian prince-style smishing evolved to 22% usage of voice cloning in vishing-smishing hybrids per Recorded Future 2023
- Malware-laden smishing links delivered trojans in 34% of Android attacks analyzed by Kaspersky in Q3 2023
- Spoofed carrier SMS for account verification scams made up 27.3% of US mobile phishing per FTC 2023 data
- Smishing campaigns using Google Voice setup for burner numbers increased 89% in dark web monitoring by Flashpoint 2023
- Emoji-laden smishing messages evaded filters in 16.7% of enterprise tests per Abnormal Security 2023 report
- Location-based smishing targeting events like concerts rose 62% during 2023 summer per Wandera (Jamf) analysis
- Smishing via WhatsApp links comprised 37% of attacks in 2023 per Check Point Mobile Threat Report
- URL obfuscation with double-encoding used in 51% of smishing per PhishLabs 2023 analysis
- Voice-to-text smishing mimicking urgent calls rose 93% in 2023 per First Orion study
- Fake lottery win smishing targeted 14% of campaigns per Smishing.io 2023 dataset
- SIM swap facilitation via smishing hit 23% of telecom breaches per GSMA 2023 security report
- Personalized smishing using breached data increased success by 4x per Deep Instinct 2023
- NFC tap-to-pay smishing scams emerged in 9% of contactless frauds 2023 per Visa trends
- Crypto wallet drainers via smishing affected 12,500 victims losing $78M in 2023 per Elliptic
- Multi-stage smishing with initial recon SMS then payload up 67% per SenseOn 2023
- Holiday-themed smishing peaked at 45% during Black Friday 2023 per Blackpoint Cyber
Attack Vectors and Techniques Interpretation
Detection, Prevention, and Response
- 82% of organizations use AI-based SMS filtering reducing smishing success by 65% per Gartner 2024 poll
- Multi-factor authentication blocked 99.9% of smishing account takeovers in Microsoft's 2023 Digital Defense Report
- Employee training reduced smishing click rates by 40% in Proofpoint's 2023 simulation benchmarks across 1,000 firms
- SMS firewalls detected 92% of malicious smishing traffic in Twilio's 2023 Signal platform analysis
- Zero-trust mobile access prevented 78% of smishing lateral movement in Zscaler's 2023 user study
- Public awareness campaigns like FTC's Stop Bad Calls lowered smishing reports by 15% in targeted areas 2023
- EMM solutions like Microsoft Intune blocked 85% of smishing payloads in enterprise deployments per Forrester 2023
- Behavioral analytics flagged 71% of anomalous SMS interactions pre-click per Darktrace 2023 case studies
- Carrier-level smishing blocking by T-Mobile prevented 4.5 billion malicious texts in 2023
- Incident response time for smishing averaged 2.1 days with mature SOCs vs 7.3 days otherwise per SANS 2023 survey
- Phishing simulations with smishing elements achieved 4.8% click rates pre-training per Cofense 2024
- RCS messaging smishing blocked by 88% efficacy in Google's Android 14 rollout 2023
- User reporting tools reduced repeat smishing victimization by 52% per FTC 2023 analysis
- SIEM integration for SMS logs detected 79% of smishing in Splunk 2023 benchmarks
- Gamified training cut smishing risks by 55% in 2023 Terranova Security study of 200 orgs
- Blockchain SMS verification pilots prevented 95% of spoofed smishing per Neuschnee 2023
- Mobile threat defense (MTD) adoption rose to 62% blocking 83% smishing per IDC 2023
- Cross-platform smishing intel sharing via MISP cut MTTR by 40% per FS-ISAC 2023
- Biometric confirmation for SMS actions reduced unauthorized access by 97% per Okta 2023
- National smishing hotlines handled 1.2M calls in 2023 with 68% prevention success per GSMA
Detection, Prevention, and Response Interpretation
Financial and Operational Impacts
- Global smishing losses reached $1.2 billion in 2023 per Chainalysis crypto scam report tied to SMS vectors
- Average smishing loss per victim was $1,450 in US IC3 2022 complaints, totaling $52 million from smishing alone
- Enterprise downtime from smishing breaches averaged 14 hours costing $45,000 per incident per IBM Cost of Data Breach 2023
- UK smishing fraud losses hit £250 million in 2023 per UK Finance annual fraud report
- 23% of smishing incidents led to ransomware deployment with average ransom $1.5M per Sophos 2023 State of Ransomware
- Retail sector smishing caused $320 million in chargeback fraud in 2023 per LexisNexis Risk Solutions
- Operational recovery from smishing credential theft cost firms $4.2 million average per Ponemon 2023 study
- Insurance claims from smishing cyber incidents rose 78% to $800 million in 2023 per Munich Re report
- Small businesses lost $2.7 million collectively to smishing in SBA 2023 fraud impact assessment
- Productivity loss from smishing awareness training post-incident averaged 8 hours per employee per Gartner 2023
- BEC smishing losses averaged $140,000 per incident in FBI 2023 alerts
- Global smishing-related data breaches exposed 45M records in 2023 per ITRC
- Healthcare smishing caused 12% of HIPAA violations costing $6.5M average per OCR 2023
- Supply chain smishing disrupted 8 firms losing $200M per CISA 2023 advisories
- Legal fees from smishing class actions averaged $1.8M per case in 2023 per BakerHostetler
- Brand reputation damage from smishing scored -24 NPS points per Qualtrics 2023 cyber study
- Employee turnover post-smishing breach up 11% per Deloitte 2023 human capital report
- Regulatory fines for smishing non-compliance totaled €45M in EU 2023 per CNIL stats
- Stock price dips averaged 3.2% after smishing disclosures in 2023 per Eventus
- Forensic investigation costs for smishing averaged $350k per Ponemon 2023 update
Financial and Operational Impacts Interpretation
Prevalence and Trends
- In 2023, smishing attacks represented 12.5% of all mobile phishing incidents reported globally, marking a 47% increase from 2022
- The FBI's IC3 received over 298,000 complaints about smishing and phishing in 2022, with smishing comprising 8.2% of those
- Verizon's 2023 DBIR noted smishing as involved in 11% of social engineering breaches in the financial sector
- Proofpoint's 2024 report indicated smishing attempts rose by 328% year-over-year among enterprise users
- Lookout's 2023 Mobile Threat Landscape reported 1.2 million unique smishing campaigns detected on Android devices
- In Q4 2023, Zscaler's analysis showed smishing accounting for 15.3% of mobile malware delivery methods
- APWG Q1 2024 Phishing Activity Trends reported smishing phishing kits increased by 72% to over 5,200 unique kits
- IBM's X-Force 2023 Threat Intelligence Index found smishing in 9.7% of identity compromise incidents
- Splunk's 2023 State of Security report cited smishing as the vector in 13.4% of observed phishing simulations failures
- Mimecast's 2023 State of Email and Collaboration Security noted smishing cross-referencing email attacks up 41%
- Smishing detection rates hit 96% with ML models trained on 10M+ SMS samples per Google 2023 Android Security Report
- EMEA region saw 25% YoY smishing surge in 2023 per ENISA Threat Landscape
- Asia-Pacific smishing incidents up 55% driven by banking trojans per Interpol 2023 cybercrime report
- Canada’s Anti-Fraud Centre logged 14,200 smishing complaints in 2023, up 33%
- Australia’s ACCC received 45,000 smishing reports in 2023 totaling AUD 150M losses
- EU saw smishing in 7% of GDPR breach notifications in 2023 per EDPB stats
- India’s CERT-In handled 1.1M smishing incidents in 2023
- Brazil’s smishing complaints rose 40% to 25,000 via SaferNet 2023
- South Africa’s ITWeb reported smishing as 12% of cyber frauds in 2023
Prevalence and Trends Interpretation
Prevalence and Trends, source url: https://www.oas.org/ext/en/cybersecurity/reports/2023-cybercrime-trends-la.pdf
- Latin America reported 18,000+ smishing cases to OAS in 2023, category: Prevalence and Trends
Prevalence and Trends, source url: https://www.oas.org/ext/en/cybersecurity/reports/2023-cybercrime-trends-la.pdf Interpretation
Victim Demographics
- In the US, 68% of adults aged 18-24 reported receiving at least one smishing attempt in 2023 per FTC survey data
- Women comprised 54.2% of smishing victims reporting to IC3 in 2022, with higher susceptibility in retail banking scams
- Seniors over 60 years old accounted for 22.7% of smishing financial loss complaints to FTC in 2023, totaling $120 million
- Millennials (25-40) represented 41% of enterprise smishing click-throughs in Proofpoint's 2023 study of 500 organizations
- Rural US residents reported 28% higher smishing victimization rates than urban in a 2023 Pew Research study
- In the UK, 35% of small business owners aged 45-55 fell for smishing per Action Fraud 2023 data
- Low-income households (<$50k/year) showed 3.2x higher smishing response rates in a 2023 Norton survey of 10,000 users
- Healthcare workers had 19% smishing victimization rate in HIMSS 2023 cybersecurity survey of 1,200 professionals
- Students aged 18-22 comprised 15.4% of university-reported smishing incidents in Educause 2023 review
- African American respondents reported 24% higher smishing encounter rates than average in 2023 AARP fraud watch survey
- Gen Z (18-24) clicked 2.1x more smishing links than Boomers in 2023 KnowBe4 study
- Finance professionals had 26% smishing susceptibility in ISACA 2023 survey of 5,000
- Remote workers reported 31% higher smishing rates per Cisco 2023 hybrid work security survey
- Teachers in US K-12 saw 22% victimization from edtech smishing per CoSN 2023
- Veterans reported 19% smishing scams targeting benefits per VA OIG 2023 audit
- Gig economy workers (Uber/DoorDash) hit by 28% of delivery smishing per FlexJobs 2023 survey
- Hispanic/Latino US adults had 21% higher smishing report rates per NTIA 2023 digital equity study
- C-suite executives fell for 14% of spear-smishing SMS per Varonis 2023 insider threat report
- Parents with children under 18 reported 17% more family-targeted smishing per Common Sense Media 2023
- Blue-collar workers showed 25% lower awareness leading to higher falls per NIST 2023 workforce cyber study
Victim Demographics Interpretation
Sources & References
- Reference 1PROOFPOINTproofpoint.comVisit source
- Reference 2IC3ic3.govVisit source
- Reference 3VERIZONverizon.comVisit source
- Reference 4LOOKOUTlookout.comVisit source
- Reference 5ZSCALERzscaler.comVisit source
- Reference 6DOCSdocs.apwg.orgVisit source
- Reference 7IBMibm.comVisit source
- Reference 8SPLUNKsplunk.comVisit source
- Reference 9MIMECASTmimecast.comVisit source
- Reference 10FTCftc.govVisit source
- Reference 11CONSUMERconsumer.ftc.govVisit source
- Reference 12PEWRESEARCHpewresearch.orgVisit source
- Reference 13ACTIONFRAUDactionfraud.police.ukVisit source
- Reference 14USus.norton.comVisit source
- Reference 15HIMSShimss.orgVisit source
- Reference 16EDUCAUSEeducause.eduVisit source
- Reference 17AARPaarp.orgVisit source
- Reference 18ZIMPERIUMzimperium.comVisit source
- Reference 19CISCOcisco.comVisit source
- Reference 20RECORDEDFUTURErecordedfuture.comVisit source
- Reference 21SECURELISTsecurelist.comVisit source
- Reference 22FLASHPOINTflashpoint.ioVisit source
- Reference 23ABNORMALSECURITYabnormalsecurity.comVisit source
- Reference 24JAMFjamf.comVisit source
- Reference 25CHAINALYSISchainalysis.comVisit source
- Reference 26UKFINANCEukfinance.org.ukVisit source
- Reference 27SOPHOSsophos.comVisit source
- Reference 28RISKrisk.lexisnexis.comVisit source
- Reference 29PONEMONponemon.orgVisit source
- Reference 30MUNICHREmunichre.comVisit source
- Reference 31SBAsba.govVisit source
- Reference 32GARTNERgartner.comVisit source
- Reference 33AKAaka.msVisit source
- Reference 34TWILIOtwilio.comVisit source
- Reference 35FORRESTERforrester.comVisit source
- Reference 36DARKTRACEdarktrace.comVisit source
- Reference 37T-MOBILEt-mobile.comVisit source
- Reference 38SANSsans.orgVisit source
- Reference 39SERVICESservices.google.comVisit source
- Reference 40ENISAenisa.europa.euVisit source
- Reference 41INTERPOLinterpol.intVisit source
- Reference 42OASoas.orgVisit source
- Reference 43ANTIFRAUDCENTRE-CENTREANTIFRAUDEantifraudcentre-centreantifraude.caVisit source
- Reference 44ACCCaccc.gov.auVisit source
- Reference 45EDPBedpb.europa.euVisit source
- Reference 46CERT-INcert-in.org.inVisit source
- Reference 47SAFERNETsafernet.org.brVisit source
- Reference 48ITWEBitweb.co.zaVisit source
- Reference 49KNOWBE4knowbe4.comVisit source
- Reference 50ISACAisaca.orgVisit source
- Reference 51COSNcosn.orgVisit source
- Reference 52VAOIGvaoig.govVisit source
- Reference 53FLEXJOBSflexjobs.comVisit source
- Reference 54BROADBANDUSAbroadbandusa.ntia.govVisit source
- Reference 55VARONISvaronis.comVisit source
- Reference 56COMMONSENSEMEDIAcommonsensemedia.orgVisit source
- Reference 57NVLPUBSnvlpubs.nist.govVisit source
- Reference 58RESEARCHresearch.checkpoint.comVisit source
- Reference 59PHISHLABSphishlabs.comVisit source
- Reference 60FIRSTORIONfirstorion.comVisit source
- Reference 61SMISHINGsmishing.ioVisit source
- Reference 62GSMAgsma.comVisit source
- Reference 63DEEPINSTINCTdeepinstinct.comVisit source
- Reference 64USAusa.visa.comVisit source
- Reference 65ELLIPTICelliptic.coVisit source
- Reference 66SENSEONsenseon.comVisit source
- Reference 67BLACKPOINTCYBERblackpointcyber.comVisit source
- Reference 68IDTHEFTCENTERidtheftcenter.orgVisit source
- Reference 69HHShhs.govVisit source
- Reference 70CISAcisa.govVisit source
- Reference 71BAKERLAWbakerlaw.comVisit source
- Reference 72QUALTRICSqualtrics.comVisit source
- Reference 73DELOITTEwww2.deloitte.comVisit source
- Reference 74CNILcnil.frVisit source
- Reference 75EVENTUSeventus.comVisit source
- Reference 76COFENSEcofense.comVisit source
- Reference 77SECURITYsecurity.googleblog.comVisit source
- Reference 78TERRANOVASECURITYterranovasecurity.comVisit source
- Reference 79NEUSCHNEEneuschnee.comVisit source
- Reference 80IDCidc.comVisit source
- Reference 81FSISACfsisac.comVisit source
- Reference 82OKTAokta.comVisit source






