What Are Brands Telling You About Smishing? A Cross-Industry Evaluation of Customer Guidance

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Doshi, Dev Vikesh, Tasnim, Mehjabeen, Landeros, Fernando, Venkatesh, Chinthagumpala Muni, Timko, Daniel, Rahman, Muhammad Lutfor
Format: Preprint
Publié: 2026
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866914288946380800
author Doshi, Dev Vikesh
Tasnim, Mehjabeen
Landeros, Fernando
Venkatesh, Chinthagumpala Muni
Timko, Daniel
Rahman, Muhammad Lutfor
author_facet Doshi, Dev Vikesh
Tasnim, Mehjabeen
Landeros, Fernando
Venkatesh, Chinthagumpala Muni
Timko, Daniel
Rahman, Muhammad Lutfor
contents Phishing attacks through text, also known as smishing, are a prevalent type of social engineering tactic in which attackers impersonate brands to deceive victims into providing personal information and/or money. While smishing awareness and cyber education are a key method by which organizations communicate this awareness, the guidance itself varies widely. In this paper, we investigate the state of practice of how 149 well-known brands across 25 categories educate their customers about smishing and what smishing prevention and reporting advice they provide. After conducting a comprehensive content analysis of the brands, we identified significant gaps in the smishing-related information provided: only 46\% of the 149 brands mentioned the definition of smishing, less than 1\% had a video tutorial on smishing, and only 50\% of brands provided instructions on how to report. Our study highlights variation in terminology, prevention advice, and reporting mechanisms across industries, with some brands recommending potentially ineffective strategies such as "ignoring suspicious messages." These findings establish a baseline for understanding the current state of industry smishing awareness advice and provide specific areas where standardization improvements are needed. From our evaluation, we provide recommendations for brands on how to offer streamlined education to their respective customers on smishing for better awareness and protection against increasing smishing attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2601_20999
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle What Are Brands Telling You About Smishing? A Cross-Industry Evaluation of Customer Guidance
Doshi, Dev Vikesh
Tasnim, Mehjabeen
Landeros, Fernando
Venkatesh, Chinthagumpala Muni
Timko, Daniel
Rahman, Muhammad Lutfor
Cryptography and Security
Human-Computer Interaction
Phishing attacks through text, also known as smishing, are a prevalent type of social engineering tactic in which attackers impersonate brands to deceive victims into providing personal information and/or money. While smishing awareness and cyber education are a key method by which organizations communicate this awareness, the guidance itself varies widely. In this paper, we investigate the state of practice of how 149 well-known brands across 25 categories educate their customers about smishing and what smishing prevention and reporting advice they provide. After conducting a comprehensive content analysis of the brands, we identified significant gaps in the smishing-related information provided: only 46\% of the 149 brands mentioned the definition of smishing, less than 1\% had a video tutorial on smishing, and only 50\% of brands provided instructions on how to report. Our study highlights variation in terminology, prevention advice, and reporting mechanisms across industries, with some brands recommending potentially ineffective strategies such as "ignoring suspicious messages." These findings establish a baseline for understanding the current state of industry smishing awareness advice and provide specific areas where standardization improvements are needed. From our evaluation, we provide recommendations for brands on how to offer streamlined education to their respective customers on smishing for better awareness and protection against increasing smishing attacks.
title What Are Brands Telling You About Smishing? A Cross-Industry Evaluation of Customer Guidance
topic Cryptography and Security
Human-Computer Interaction
url https://arxiv.org/abs/2601.20999