Back to blog

Blog

APWG and PCI DSS: Smishing Is Rising

Smishing is growing on mobile channels while PCI DSS v4.0 requires annual awareness training and explicit phishing and social engineering content.

APWG and PCI DSS: Smishing Is Rising

For a CISO, IT team, or compliance function in LATAM, the useful way to read smishing and phishing is operational, not semantic: the mobile channel is already an expanding attack surface, and PCI DSS v4.0 requires an annual awareness program that includes phishing, related attacks, and social engineering. If human failure rates are also considered, the decision stops being theoretical and becomes SMS simulations, exposure metrics, and compliance evidence.

Putting the sources side by side shows a tension none of them covers alone: some explain what the attack is, others show that the channel is growing, and PCI defines what has to be trained and how often. That leaves a clear gap between definition, risk, and control, exactly where a security team has to decide what to measure tomorrow.

Source comparison

When they are cross-referenced, a difference emerges between attack description, growth evidence, and control requirements. That combination is what makes it possible to move from a dictionary explanation to a program decision.

Phishing, Vishing, and SMiShing |Phishing attacks |Cyber security awareness video |Security Quotient — Security Quotient. Ver el original
Source Concept Channel or vector Growth Compliance Review Examples
Social engineering attack using fake mobile text messages SMS, mobile text messages Not specified Not specified Not specified Download malware, share sensitive information, send money
SMS cyberattack that appears to come from a trusted source SMS, text messages Not specified Not specified Not specified Share personal or financial information, click malicious links, download harmful software
Phishing through mobile messaging, based on human trust Mobile messaging, SMS Not specified Not specified Not specified Not specified
Social engineering through text messages Text messages Not specified Not specified Not specified Banks, package deliveries, HR
Smishing is phishing via SMS, while mobile phishing is broader SMS, chat, mobile browsers, QR, PDF, redirects Not specified Not specified Not specified Text scams and fraud not necessarily tied to phishing
Complaints up 50% between 2022 and 2023, 76% of organizations affected in 2023 Smishing measured through complaints and organizational attacks SMS Complaints up 50% between 2022 and 2023, 76% of organizations affected in 2023 Not specified Not specified Fake deliveries, fake banking alerts, tolls
Smishing as part of phone and mobile fraud SMS, text messages +40% between Q1 and Q2 of 2026 Not specified Not specified Expanding mobile attack surface
PCI Security Standards Council Awareness program for staff focused on threats to the CDE Phishing, related attacks, social engineering Not specified Program reviewed and updated at least every 12 months At least every 12 months Phishing and related attacks, social engineering

What does IBM say about smishing?

IBM defines it as a social engineering attack that uses fake mobile text messages to trick people into downloading malware, sharing sensitive information, or sending money. The key is not the channel alone, but the combination of short messages, urgency, and apparent trust. That framing helps explain the mechanism, but it is not enough to prioritize control or training.

What does Proofpoint add about the vector?

Proofpoint describes it as a cyberattack aimed at individuals through SMS or text messages, with messages that appear to come from a trusted source. The practical difference is that it brings the phenomenon down to everyday deception with concrete outcomes: sharing personal or financial information, clicking malicious links, or downloading harmful software. For Whalemate, that level of specificity is useful because it turns risk into observable behavior.

Why do Kaspersky and Descope focus on human trust?

Kaspersky and the person gives up sensitive information without noticing the deception agree that smishing exploits human trust more than technical vulnerabilities. Kaspersky labels it phishing through mobile messaging, and Descope ties it to that idea. That reading matters because it shifts the response from isolated technical hygiene to continuous training and behavior measurement.

How New Phishing Scams Trick You — KristoferYee. Ver el original

What changes when smishing is separated from mobile phishing?

DeepStrike draws a useful line: smishing is phishing via SMS or text messages, while mobile phishing also includes chat apps, mobile browsers, QR codes, PDF lures, and app-based redirects. That distinction avoids underestimating the mobile channel, because a program that looks only at SMS can miss other lures that reach the same user on the same device.

What do the growth figures show?

Smishing complaints grew 50% between 2022 and 2023, with fake package deliveries, fake banking alerts, and toll requests among the campaigns. The same material cites Proofpoint and says 76% of organizations experienced smishing attacks in 2023, up from 61% in 2022. Smishing increased 40% between Q1 and Q2 of 2026. Read together, the figures show channel expansion rather than an isolated case.

What does PCI DSS v4.0 require in awareness training?

The PCI DSS v4.0 summary of changes says the awareness program must be reviewed and updated at least every 12 months, and that the content must cover threats and vulnerabilities that affect CDE security, including phishing and related attacks and social engineering from March 31, 2025 onward. Sources: PCI Security Standards Council, BaitandPhish, CyberAware

What does Whalemate's reading mean for LATAM?

The implication is direct: if the mobile channel is growing and PCI requires annual awareness with explicit focus on phishing and social engineering, then the program should not stop at a course. Whalemate proposes a Human Risk Management model that simulates, trains, measures, intervenes, and reports, with a risk score to prioritize interventions, not to discipline people. That enables a concrete decision for CISO, IT, and compliance: use SMS simulations, consolidate signals from courses, reports, and behavior, and document evidence of reduced exposure.

Operational consequence

Starting tomorrow, a security team can decide three things. First, treat mobile as a priority surface within the awareness program. Second, measure clicks and reports in SMS simulations as a sign of human failure, along with training completion and repeat behavior. Third, use that evidence to support PCI DSS v4.0 compliance and prioritize exposed groups, without turning the score into a disciplinary tool.

How New Phishing Scams Trick You — KristoferYee. Ver el original

What to read next?

See the full topic guide

Would you like to go deeper on this topic?

Open this article directly in Claude or ChatGPT — ask questions, get a summary, or explore related ideas.

Open with ClaudeOpen with ChatGPT