Short Message Service (SMS) Phishing Attacks and Defenses: A Systematic Review

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Pritom, Mir Mehedi A., Sanjari, Seyed Mohammad, Mia, Maraz, Shibli, Ashfak Md, Hossain, S M Mostaq, Ismail, Muhammad, Xu, Shouhuai
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866918442991353856
author Pritom, Mir Mehedi A.
Sanjari, Seyed Mohammad
Mia, Maraz
Shibli, Ashfak Md
Hossain, S M Mostaq
Ismail, Muhammad
Xu, Shouhuai
author_facet Pritom, Mir Mehedi A.
Sanjari, Seyed Mohammad
Mia, Maraz
Shibli, Ashfak Md
Hossain, S M Mostaq
Ismail, Muhammad
Xu, Shouhuai
contents SMS Phishing (also known as 'smishing') is a growing deceptive social engineering (SE) attack that leverages mobile SMS to conduct cybercrimes such as stealing sensitive information or spreading malware by tricking users into interacting with attackers' messages (e.g., responding to or clicking URLs). This threat has increased rapidly in recent years, causing $470M in financial losses for United States users in 2024 alone. This threat is also evolving rapidly, meaning that attackers continually adapt their tactics, reshaping the landscape. There is a significant body of literature on investigating smishing attacks and defenses. However, there is no systematic review that reflects the current attack and defense landscape along with available resources (i.e., relevant datasets). This motivates us to systematize the current smishing research efforts, including the following four research pillars: (a) user perception and susceptibility, (b) attack characterization, (c) defense landscape, and (d) smishing datasets. This leads us to propose novel future research directions towards effectively mitigating smishing attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2604_11429
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Short Message Service (SMS) Phishing Attacks and Defenses: A Systematic Review
Pritom, Mir Mehedi A.
Sanjari, Seyed Mohammad
Mia, Maraz
Shibli, Ashfak Md
Hossain, S M Mostaq
Ismail, Muhammad
Xu, Shouhuai
Cryptography and Security
68M25 (Primary), 68M11 (Secondary)
K.6.5; C.2.0; H.1.2
SMS Phishing (also known as 'smishing') is a growing deceptive social engineering (SE) attack that leverages mobile SMS to conduct cybercrimes such as stealing sensitive information or spreading malware by tricking users into interacting with attackers' messages (e.g., responding to or clicking URLs). This threat has increased rapidly in recent years, causing $470M in financial losses for United States users in 2024 alone. This threat is also evolving rapidly, meaning that attackers continually adapt their tactics, reshaping the landscape. There is a significant body of literature on investigating smishing attacks and defenses. However, there is no systematic review that reflects the current attack and defense landscape along with available resources (i.e., relevant datasets). This motivates us to systematize the current smishing research efforts, including the following four research pillars: (a) user perception and susceptibility, (b) attack characterization, (c) defense landscape, and (d) smishing datasets. This leads us to propose novel future research directions towards effectively mitigating smishing attacks.
title Short Message Service (SMS) Phishing Attacks and Defenses: A Systematic Review
topic Cryptography and Security
68M25 (Primary), 68M11 (Secondary)
K.6.5; C.2.0; H.1.2
url https://arxiv.org/abs/2604.11429