Home › Knowledgebase › KB-165

How to identify and report a suspicious SMS (Smishing) attack

Summary

This guide helps you troubleshoot and resolve: How to identify and report a suspicious SMS (Smishing) attack. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Smishing, or SMS phishing, is a technique used by cybercriminals to trick you into revealing sensitive information, such as passwords or credit card details, via text message. Because these messages often appear on your personal or work mobile device, they can feel more urgent and personal than email scams. This guide will help you identify these threats and the correct way to report them to the 220 team.

How to Spot a Suspicious SMS

Fraudulent messages often use social engineering to create a sense of panic or curiosity. Look for these common red flags:

Urgency and Threats

Suspicious Links and Senders

Never click a link in a suspicious SMS. Clicking a link can lead to a credential-harvesting site or trigger a silent download of malware onto your device.

Immediate Actions to Take

  1. Do not reply: Replying to the message, even to say "stop," confirms to the attacker that your mobile number is active.
  2. Do not click links: If you believe the message might be legitimate, open your web browser and manually type the official website address or use the official app.
  3. Take a screenshot: Capture the message and the sender's number. This provides the 220 security team with the necessary data to analyse the threat.
  4. Block the sender:
    • iOS: Tap the profile icon at the top of the conversation > info > Block this Caller.
    • Android: Long-press the conversation in the main list > Block > Report spam.

Reporting the Attack to 220

If you have received a suspicious message on a company-issued device or believe your professional credentials may have been compromised, you must report it immediately.

  1. Navigate to the 220 support portal at https://app.220.com.au/.
  2. Select Open a Ticket.
  3. In the description, specify that you are reporting a Smishing Attack.
  4. Attach the screenshot of the SMS and the sender's phone number.
  5. Mention if you clicked any links or entered any information before realising it was a scam.
If you accidentally entered your company password into a fraudulent site, please Password reset (Windows login) immediately after reporting the incident to 220.

Preventative Measures

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket