Phone-based scams are on the rise. Even if you don’t have a smartphone you have probably received SMS messages that “look a bit funny”. These SMS scam messages are “smishing”.
The Australian Cyber Security Centre (ACSC) is warning that the current conflict in the Ukraine also involves cyber attacks that may affect us too, so we should be even more alert.
Smishing – the next wave of phishing
Smishing is a phishing cybersecurity attack carried out over mobile text messaging, also known as SMS phishing. It occurs on many mobile text messaging platforms, including non-SMS channels like data-based mobile messaging apps such as WhatsApp.
In any form of phishing, victims are deceived into giving sensitive information to a disguised attacker. Phishing can be assisted by malware or fraud websites to steal your personal data, which the attackers can then use to commit fraud or other cybercrimes, such as stealing your money.
Cybercriminals often use one of two methods to steal this data:
- Malware: The smishing URL link might trick you into downloading malware — malicious software — that installs itself on your phone. This SMS malware might masquerade as a legitimate app, tricking you into typing in confidential information and sending this data to the cybercriminals.
- Malicious website: The link in the smishing message might lead to a fake site that requests you to type sensitive personal information. Cybercriminals use custom-made malicious sites designed to mimic reputable ones, making it easier to steal your information.
How to protect against smishing and phishing
Unfortunately, you can’t prevent smishing texts or phishing emails. And text messaging is a legitimate means for many retailers and institutions to reach you. Not all messages should be ignored, but you should act safely regardless.
The good news is that you can easily keep yourself safe by doing nothing at all. In essence, the attacks can only do damage if you take the bait.
These steps will help you protect yourself against these attacks, whether by text message, email or phone call.
- Do not respond. Even prompts to reply like texting “STOP” to unsubscribe can be a trick to identify active phone numbers. Attackers depend on your curiosity or anxiety over the situation at hand, but you can refuse to engage.
- Slow down if a message is urgent. You should approach urgent account updates and limited time offers as caution signs of possible smishing. Remain skeptical and proceed carefully.
- Avoid using any links or contact info in the message. Avoid using links or contact info in messages that make you uncomfortable. Go directly to official contact channels when you can.
- Call your bank or merchant directly if doubtful. Legitimate institutions don’t request account updates or login info via text. Furthermore, any urgent notices can be verified directly on your online accounts or via an official phone helpline.
- Check the phone number. Odd-looking phone numbers, such as 4-digit ones, can be evidence of email-to-text services. This is one of many tactics a scammer can use to mask their true phone number.
- Use multi-factor authentication (MFA). An exposed password may still be useless to a smishing attacker if the account being breached requires a second “key” for verification. MFA’s most common variant is two-factor authentication (2FA), which often uses a text message verification code. Stronger variants include using a dedicated app for verification (like Google Authenticator) are available.
- Never provide a password or account recovery code via text. Both passwords and text message two-factor authentication (2FA) recovery codes can compromise your account in the wrong hands. Never give this information to anyone, and only use it on official sites.
- Download an anti-malware app. Several products are available for Android phones that can protect against malicious apps, including malware. There are also products available for Android and iOS devices that protect against SMS phishing links themselves. You need these on your computer as well.
What to do if you become a victim
Smishing attacks are cunning and may have already victimized you, so you’ll need to have a recovery plan in place. Take these important actions to limit the damage of a successful smishing attempt:
- Report the suspected attack to any institutions that could assist, such as Scamwatch, ReportCyber (ACSC), IDCare
- Freeze your credit to prevent any future or ongoing identity fraud.
- Change all passwords and account PINs where possible.
- Monitor finances, credit, and various online accounts for strange login locations and other activities.
Each of these steps has a substantial weight for your protection after a smishing attack. However, reporting an attack not only helps you recover, but keeps others from falling victim as well.
Be prepared – have a backup
The best protection against malware on any of your devices is to have a backup.
Here’s some information on how to do that:
Periodically, U3A Nunawading offers sessions on how to backup. Keep an eye out for the next session!
(Adapted from What is Smishing and How to Defend Against it by Kaspersky)