For a CISO, IT team, or compliance function in LATAM, the useful way to read smishing and phishing is operational, not semantic: the mobile channel is already an expanding attack surface, and PCI DSS v4.0 requires an annual awareness program that includes phishing, related attacks, and social engineering. If human failure rates are also considered, the decision stops being theoretical and becomes SMS simulations, exposure metrics, and compliance evidence.
Putting the sources side by side shows a tension none of them covers alone: some explain what the attack is, others show that the channel is growing, and PCI defines what has to be trained and how often. That leaves a clear gap between definition, risk, and control, exactly where a security team has to decide what to measure tomorrow.
Source comparison
When they are cross-referenced, a difference emerges between attack description, growth evidence, and control requirements. That combination is what makes it possible to move from a dictionary explanation to a program decision.
| Source | Concept | Channel or vector | Growth | Compliance | Review | Examples |
|---|---|---|---|---|---|---|
| Social engineering attack using fake mobile text messages | SMS, mobile text messages | Not specified | Not specified | Not specified | Download malware, share sensitive information, send money | |
| SMS cyberattack that appears to come from a trusted source | SMS, text messages | Not specified | Not specified | Not specified | Share personal or financial information, click malicious links, download harmful software | |
| Phishing through mobile messaging, based on human trust | Mobile messaging, SMS | Not specified | Not specified | Not specified | Not specified | |
| Social engineering through text messages | Text messages | Not specified | Not specified | Not specified | Banks, package deliveries, HR | |
| Smishing is phishing via SMS, while mobile phishing is broader | SMS, chat, mobile browsers, QR, PDF, redirects | Not specified | Not specified | Not specified | Text scams and fraud not necessarily tied to phishing | |
| Complaints up 50% between 2022 and 2023, 76% of organizations affected in 2023 | Smishing measured through complaints and organizational attacks | SMS | Complaints up 50% between 2022 and 2023, 76% of organizations affected in 2023 | Not specified | Not specified | Fake deliveries, fake banking alerts, tolls |
| Smishing as part of phone and mobile fraud | SMS, text messages | +40% between Q1 and Q2 of 2026 | Not specified | Not specified | Expanding mobile attack surface | |
| PCI Security Standards Council | Awareness program for staff focused on threats to the CDE | Phishing, related attacks, social engineering | Not specified | Program reviewed and updated at least every 12 months | At least every 12 months | Phishing and related attacks, social engineering |
What does IBM say about smishing?
IBM defines it as a social engineering attack that uses fake mobile text messages to trick people into downloading malware, sharing sensitive information, or sending money. The key is not the channel alone, but the combination of short messages, urgency, and apparent trust. That framing helps explain the mechanism, but it is not enough to prioritize control or training.
What does Proofpoint add about the vector?
Proofpoint describes it as a cyberattack aimed at individuals through SMS or text messages, with messages that appear to come from a trusted source. The practical difference is that it brings the phenomenon down to everyday deception with concrete outcomes: sharing personal or financial information, clicking malicious links, or downloading harmful software. For Whalemate, that level of specificity is useful because it turns risk into observable behavior.
Why do Kaspersky and Descope focus on human trust?
Kaspersky and the person gives up sensitive information without noticing the deception agree that smishing exploits human trust more than technical vulnerabilities. Kaspersky labels it phishing through mobile messaging, and Descope ties it to that idea. That reading matters because it shifts the response from isolated technical hygiene to continuous training and behavior measurement.



