Smishing (SMS phishing) exploits the proximity and instant responsiveness of our smartphones. Before opening a link or replying to an unexpected SMS, apply this quick checklist.
1. The Sender: Beware of hidden display names
- What to look for: Does the SMS come from an unknown mobile number (e.g., 06/07
), a short code, or a brand name (e.g.,DELIVERY, INFO -ALMOND )? - The classic trap: SMS spoofing. Hackers can spoof the sender so that the phishing SMS is inserted directly into the official conversation thread of your real bank or delivery service.
2. The Pretext: Identify common manipulation themes
- What to look for: Does the message concern a blocked package, an unpaid fine, a health insurance card that needs renewing, or a bank security alert?
- The classic trap: The prefabricated urgency ("Last notice before surcharge", "Package returned to sender within 24 hours").
3. The Link: Analyze the structure of the web link
- What to look for: Does the web address (URL) look like a real official address or does it use atypical extensions (
.top,.club,.info,.site) or link shorteners (bit.ly,tinyurl)? - The classic trap: A deceptive imitation such as
suivi-colis-laposte-verification.cominstead oflaposte.fr.
4. The Request: Identify the data or money extortion
- What to look for: Are you asked to pay a small fee (e.g., €0.99 or €1.95 for "reshipping fees") or to enter your login details?
- The classic trap: Charging a small sum to actually obtain your bank card numbers or network access credentials.
5. Consistency: Question the legitimacy of the channel
- What to consider: Are you really expecting this message? Does your bank usually ask you to log in via a link received by SMS?
- The classic trap: No financial institution or administration will send you an SMS containing a direct link to validate your login details or bank details.
The right thing to do if in doubt:
- Do not click on any links and do not call back the sender's number.
- Access the relevant service yourself by opening your official application or by typing the known web address into your browser.
- Report the message to the national anti-spam service (e.g., forward the SMS to
33700in France or via[email protected]in Belgium) and then block the number.- Notify your IT department immediately if your work phone is involved.