How to identify and report a suspicious SMS (Smishing) attack
Summary
This guide helps you troubleshoot and resolve: How to identify and report a suspicious SMS (Smishing) attack. Follow the steps below to fix the issue.
Common Causes
Smishing, or SMS phishing, is a technique used by cybercriminals to trick you into revealing sensitive information, such as passwords or credit card details, via text message. Because these messages often appear on your personal or work mobile device, they can feel more urgent and personal than email scams. This guide will help you identify these threats and the correct way to report them to the 220 team.
How to Spot a Suspicious SMS
Fraudulent messages often use social engineering to create a sense of panic or curiosity. Look for these common red flags:
Urgency and Threats
- Messages claiming your account will be suspended immediately.
- Alerts about "unauthorised activity" or "failed deliveries" that require immediate action.
- Threats of legal action or fines from government agencies (e.g., ATO or Centrelink).
Suspicious Links and Senders
- Shortened URLs: Use of services like
bit.lyortinyurl.comto hide the actual destination. - Misspelled Domains: A link that looks almost correct but has a slight variation (e.g.,
mygov-au.netinstead ofmy.gov.au). - Unknown Numbers: Messages from international area codes or random mobile numbers claiming to be from a large organisation.
Immediate Actions to Take
- Do not reply: Replying to the message, even to say "stop," confirms to the attacker that your mobile number is active.
- Do not click links: If you believe the message might be legitimate, open your web browser and manually type the official website address or use the official app.
- Take a screenshot: Capture the message and the sender's number. This provides the 220 security team with the necessary data to analyse the threat.
- Block the sender:
- iOS: Tap the profile icon at the top of the conversation > info > Block this Caller.
- Android: Long-press the conversation in the main list > Block > Report spam.
Reporting the Attack to 220
If you have received a suspicious message on a company-issued device or believe your professional credentials may have been compromised, you must report it immediately.
- Navigate to the 220 support portal at https://app.220.com.au/.
- Select Open a Ticket.
- In the description, specify that you are reporting a
Smishing Attack. - Attach the screenshot of the SMS and the sender's phone number.
- Mention if you clicked any links or entered any information before realising it was a scam.
Preventative Measures
- Enable Multi-Factor Authentication (MFA): Ensure MFA is active on all business accounts. Even if a scammer steals your password, MFA provides a critical second layer of defence.
- Keep Software Updated: Regularly update your mobile OS (iOS/Android) to ensure you have the latest security patches.
- Be Skeptical: Remember that banks, government agencies, and 220 Internet Services will never ask for your password or credit card details via SMS.
Still Having Issues?
💻 Open a Ticket