Smishing is a phishing attack that targets users through mobile text messaging, also known as SMS phishing. As a variant of phishing, victims are deceived into giving sensitive information to a disguised attacker. It occurs on many mobile text messaging platforms, including non-SMS channels like data-based mobile messaging apps.
Understanding smishing
Smishing is a form of phishing delivered through text messages rather than email, and it works on the same underlying principle. The attacker does not need to break into a system, they just need the recipient to trust a message enough to click a link, call a number, or hand over information voluntarily. A 2024 academic study on smishing mitigation noted that nearly all US consumers now carry a mobile phone, and scammers have followed them there deliberately, because text messages carry a level of implicit trust that email lost years ago.
That trust is exactly what makes smishing effective in a healthcare context. A message that looks like it comes from a pharmacy, an insurer, or a provider's office does not need to be sophisticated to work, it only needs to feel routine.
Read more: What is a phishing attack?
How the scale of smishing has changed
The FBI's 2025 Internet Crime Report recorded more than one million total complaints and $20.9 billion in losses across all reported internet crime categories, a 26% increase from the year before. Text-based scams have been a consistent driver of that growth, as in April 2024, the FBI's Internet Crime Complaint Center issued a public advisory after receiving more than 2,000 complaints about smishing texts impersonating road toll collection services, with the campaign spreading from state to state and using nearly identical language in every message.
That specific campaign never really stopped, the FTC's 2026 consumer alert on imposter scams found that reports of government imposter scams rose 40% in 2025, with toll-related messages cited as a major driver, and total imposter scam losses reaching $3.5 billion for the year. The pattern that made the toll scam so effective, a routine-sounding message tied to something the recipient might plausibly owe, has become the template for smishing campaigns well beyond tolls.
Why healthcare has become a specific target
In June 2025, the FBI and the Centers for Medicare and Medicaid Services jointly warned healthcare providers and their patients about a phishing and smishing scheme in which criminals impersonated legitimate health insurers, sending messages by both email and text designed to extract protected health information, medical records, and financial details. In some cases, the messages requested reimbursement for services the recipient had never used, banking on the confusion that follows an unfamiliar billing claim.
The advisory shows something healthcare organizations cannot really opt out of, which is that smishing does not require breaching a hospital's systems at all. A text sent directly to a patient, referencing an appointment or a claim that sounds plausible, can extract exactly the kind of information an attacker needs without ever touching a covered entity's network. That makes patient-facing communication itself part of the threat surface, as well as internal email.
Why SMS-based verification is becoming part of the problem
There is a further complication specific to healthcare's reliance on text messages, which is that SMS has also been the default second factor for account verification for years. That reliance is viewed as a liability rather than a safeguard. A 2026 industry analysis of authentication trends found that SMS-based one-time codes remain vulnerable to SIM-swapping, interception through telecom network weaknesses, and adversary-in-the-middle phishing kits that proxy a legitimate login page well enough to capture the code as the user types it in.
The 2025 Verizon Data Breach Investigations Report found that MFA fatigue and social engineering against traditional authentication methods remain a big factor in confirmed breaches, and organizations that have moved to phishing-resistant methods, such as hardware security keys built on the FIDO2 standard, report measurably fewer successful account takeovers than those still relying on SMS codes. For healthcare organizations issuing text-based codes to staff or patients, this means the same channel used to deliver smishing attacks is also, in many cases, the channel relied upon to keep accounts secure.
Read also: What is social engineering?
What actually reduces the risk
Because smishing depends on a message reaching someone who trusts it, the most reliable defenses focus on reducing that trust rather than trying to filter every text message, which is not something most healthcare organizations can technically do at scale. Slowing down before responding to any unsolicited request for information, verifying through a phone number or website already known to be legitimate rather than one provided in the message itself, and never storing sensitive account or payment information directly on a mobile device all reduce the chance that a single message causes real damage.
For the entry points a healthcare organization can actually control, the picture is different. Most smishing campaigns directed at healthcare either originate from or connect back to email-based infrastructure, whether through linked phishing pages or coordinated multi-channel campaigns that use both text and email to reach the same target. Paubox's 2025 Healthcare Email Security Report found that only 5% of known phishing attempts in healthcare are reported by employees to security teams, a gap that applies just as much to the email side of these blended campaigns as it does to smishing itself. Paubox Inbound Email Security uses AI to analyze sender behavior, message intent, and contextual signals, catching phishing attempts before they reach an inbox and before any linked smishing follow-up has a chance to work.
Learn more: Paubox Inbound Email Security
In the news
In June 2026, Google filed a lawsuit in Manhattan federal court against a Chinese cybercrime network accused of using its Gemini AI model to build phishing pages for a large-scale smishing operation. The network ran a service called Outsider, generating more than 1.59 million fraudulent URLs and sending 2.5 million smishing texts to Android users in a single two-week period, with the FBI estimating the platform responsible for roughly $1.9 billion in losses since 2023. Operators avoided triggering AI safety filters by framing their requests to Gemini as harmless web design tasks, asking for HTML code for a generic rewards page rather than describing its actual fraudulent purpose, then deploying that code as a credential-harvesting site. Google is now partnering with AT&T, T-Mobile, and Verizon to block messages tied to the platform. For healthcare specifically, the case illustrates a shift worth taking seriously. AI is being used to write more convincing smishing text. It is now generating the phishing infrastructure itself, which means the pages a smishing link leads to can be freshly built for every campaign rather than reused, making them far harder to block through traditional detection methods.
FAQs
What is the difference between phishing and smishing?
Phishing typically refers to email-based attacks, while smishing uses text messages as the delivery method. Both rely on the same social engineering principle of impersonating a trusted source to extract information or prompt a harmful click, but smishing takes advantage of the higher trust people tend to place in text messages compared to email.
Why has SMS-based MFA become less recommended?
SMS codes can be intercepted through SIM-swapping, telecom network vulnerabilities, or phishing kits that capture the code in real time as a user enters it on a fake login page. Authentication methods built on the FIDO2 standard, such as hardware security keys, are not vulnerable to these interception techniques in the same way.
How does smishing target healthcare specifically?
Attackers impersonate insurers, providers, or billing departments to request payment for services never rendered, or to harvest personal and financial information under the guise of an appointment or claim update. Because the message goes directly to a patient's phone, it does not require breaching any healthcare organization's systems to be effective.
What should someone do if they receive a suspicious text message?
Avoid clicking any link or responding to the message directly, and instead verify the claim by contacting the organization through a phone number or website already known to be legitimate. Reporting the message to the FTC or the FBI's Internet Crime Complaint Center helps track and disrupt ongoing campaigns.
Can email security tools help against smishing?
Directly, no, since smishing arrives by text rather than email. Many smishing campaigns are part of broader multi-channel attacks that also use email, so strong inbound email filtering can catch the related phishing attempt even when the smishing message itself arrives through a separate channel.
