Smishing (SMS phishing) exploits the proximity and instant responsiveness of our smartphones. Before opening a link or replying to an unexpected SMS, apply this quick checklist.

1. The Sender: Beware of hidden display names

  • What to look for: Does the SMS come from an unknown mobile number (e.g., 06/07 ) , a short code, or a brand name (e.g., DELIVERY , INFO -ALMOND )?
  • The classic trap: SMS spoofing. Hackers can spoof the sender so that the phishing SMS is inserted directly into the official conversation thread of your real bank or delivery service.

2. The Pretext: Identify common manipulation themes

  • What to look for: Does the message concern a blocked package, an unpaid fine, a health insurance card that needs renewing, or a bank security alert?
  • The classic trap: The prefabricated urgency ("Last notice before surcharge", "Package returned to sender within 24 hours").

3. The Link: Analyze the structure of the web link

  • What to look for: Does the web address (URL) look like a real official address or does it use atypical extensions (.top, .club, .info, .site) or link shorteners (bit.ly, tinyurl)?
  • The classic trap: A deceptive imitation such as suivi-colis-laposte-verification.com instead of laposte.fr.

4. The Request: Identify the data or money extortion

  • What to look for: Are you asked to pay a small fee (e.g., €0.99 or €1.95 for "reshipping fees") or to enter your login details?
  • The classic trap: Charging a small sum to actually obtain your bank card numbers or network access credentials.

5. Consistency: Question the legitimacy of the channel

  • What to consider: Are you really expecting this message? Does your bank usually ask you to log in via a link received by SMS?
  • The classic trap: No financial institution or administration will send you an SMS containing a direct link to validate your login details or bank details.

The right thing to do if in doubt:

  1. Do not click on any links and do not call back the sender's number.
  2. Access the relevant service yourself by opening your official application or by typing the known web address into your browser.
  3. Report the message to the national anti-spam service (e.g., forward the SMS to 33700 in France or via [email protected] in Belgium) and then block the number.
  4. Notify your IT department immediately if your work phone is involved.

Categories: