Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Add-on

Smishing Simulations

Test how your employees respond to SMS phishing, the channel with no email gateway in front of it. Send realistic but harmless text lures, measure who taps and who reports, and route the rest into targeted training.

Smishing simulation workflow: SMS lure templates on the left, a phone receiving the simulated text in the center, and a funnel on the right showing sent, delivered, clicked, submitted, and reported rates

What is a smishing simulation?

A smishing simulation is a controlled test in which an organization sends realistic but harmless SMS phishing messages to its own employees, then measures who taps the link and who reports it. It is the SMS counterpart to a phishing simulation, run on the channel that has no gateway in front of it.

The reason to test SMS separately is that the defenses are not the same. A suspicious email passes a secure email gateway, a link scanner, and a banner warning before anyone sees it. A text arrives on a personal phone with none of that, on a screen where the address bar truncates and the reply-in-two-seconds instinct is strongest.

So people who reliably spot the same trick in their inbox still tap it in Messages. A phishing simulation will not surface that gap, because it never tests the channel where the gap lives.

Why SMS is the blind spot in most programs

Three things make text a softer target than email, and none of them are fixed by training people on email.

No gateway, no scanning

There is no SMS equivalent of a secure email gateway. Nothing rewrites the link, checks the domain age, or stamps an external-sender banner on the message before it reaches the phone.

A screen built to hide the URL

Mobile browsers truncate the address bar, so a lookalike domain reads as legitimate. Attackers pair that with URL shorteners and freshly registered domains that no blocklist has seen yet.

Pressure plus a personal device

Texts get read within minutes and often on a phone the company does not manage. A delivery exception or a toll notice converts urgency into a tap before anyone thinks to verify.

The scale is not theoretical. The US FTC recorded $470 million in text-scam losses in 2024, with package-delivery and fake-toll lures among the most reported patterns.

How smishing simulations work

Four steps from setup to measured behavior, on the same platform as your email program.

01

Configure

Pick the SMS channel, choose an approved smishing template, set a send time, and select recipients. Only employees with a phone number on file can be targeted.

02

Deliver

Messages send from a platform origination number, gated to each recipient business hours in their own timezone, and spread across a window to avoid burst patterns and carrier rate limits.

03

Track

Every link tap and REPORT reply is recorded against a signed, time-limited token, so each interaction is tied back to the specific recipient and dispatch.

04

Remediate

Recipients who tap the lure are auto-enrolled in a learning path that drills the exact pattern they fell for, with deadlines and manager visibility.

SMS templates with built-in red flags

A library of approved smishing templates modeled on the lures attackers actually send, each annotated with the cues employees should learn to spot.

Smishing campaign editor with the SMS channel selected, a package-delivery template chosen from the curated catalog, and the rendered text body with red-flag tags for sender, content, and link

Real-world lure patterns

Package-delivery, account-suspended, password-expiry, and unsolicited-MFA-code templates mirror the highest-volume smishing campaigns, including the toll and delivery lures behind 2024 FBI complaints.

Liquid personalization

Templates merge recipient and company details so the text reads like a targeted message rather than a generic blast, matching how modern smishing kits operate.

Tagged red flags

Each template marks the teaching cues (suspicious sender, pressure in the content, masked link) so the post-tap lesson points to exactly what gave the attack away.

Every text is yours to customize

Send an approved template as it is, clone one to rewrite the message, sender ID, and lookalike link, or author a new lure from scratch with Liquid variables. The reveal page updates to match, and STOP and REPORT opt-out handling stays built in.

  • Use as-is
  • Clone and edit
  • Build from scratch

Opt-out and compliance built in

SMS carries rules that email does not. The platform handles them so your program stays defensible.

STOP and REPORT handling

Recipients who reply STOP are added to a per-tenant and a platform-wide opt-out registry and never texted again. A REPORT reply is recorded as the correct, secure response.

Business-hours delivery

Texts are held until working hours in each recipient timezone, so a simulation never lands at 3 a.m. or reads as harassment.

Phone-number gating

Only employees with a phone number on file are eligible, and the audience picker shows exactly who is in and who is excluded before launch.

GDPR and works councils

Jurisdiction settings and aggregate-only reporting support GDPR Article 88 and works-council requirements for monitoring employee behavior.

Phone-gated recipient picker for an SMS campaign: employees without a phone number on file are shown disabled, with a banner reading "125 users without a phone number can’t be selected."

SMS funnel analytics

See the whole journey of a text campaign and turn it into a baseline you can track campaign over campaign.

One funnel for every campaign

Track dispatched, clicked, and reported alongside email metrics in a single behavior funnel, broken down by team so you can see which groups need attention.

Report rate as the headline

Report rate sits alongside click rate and fail rate, because the share of recipients who flag a text is the metric that tracks with real resilience.

Export for evidence

Pull CSV and PDF reports for audit evidence and board reporting, with the same shape as your email simulation results.

Phishing analytics dashboard with cross-campaign resilience trend chart and headline KPIs for campaigns, dispatched, click rate, fail rate, and report rate

From a tapped link to a measured risk score

A simulation that ends in a report is an event. A simulation that changes what happens next is a program.

Just-in-time remediation

Anyone who taps the lure is auto-enrolled in the lesson that drills the exact pattern they fell for, with a deadline and a grace period, while the moment is still fresh.

It moves the human risk score

A failed text feeds the same susceptibility signal as a failed email, so a person’s human risk score reflects the channel they are actually weak on, not just their inbox behavior.

Rules act on the result

Risk-based automation watches the score and acts when someone crosses a band, with dry-run, an audit log, and a blast cap so nothing fires by surprise.

On the roadmap

Voice (vishing) simulations

Voice-call simulations are not a live campaign channel yet. Email and SMS ship today; the voice channel is scaffolded in the platform and deferred to a later release, and we would rather say that plainly than sell a roadmap.

You can still train the reflex now. The immersive vishing exercise puts learners on a simulated call and drills hang-up-and-call-back-on-a-known-number, and the callback phishing exercise covers the text-then-call pattern that pairs smishing with a voice follow-up.

  • Live today: email and SMS campaign delivery
  • Available today: immersive vishing and callback-phishing exercises
  • Not yet available: outbound voice campaign delivery
How voice phishing works

Frequently asked questions

How are the text messages delivered?

Messages are sent from a platform-owned origination number and delivered through a transactional SMS provider. Delivery is gated to each recipient business hours in their own timezone and spread across a send window to avoid burst patterns and carrier rate limits.

Only employees with a phone number on file can be selected as recipients, and the audience picker shows who is eligible before you launch.

How does opt-out work?

Standard SMS opt-out is built in. A recipient who replies STOP is added to a per-tenant and a platform-wide opt-out registry and is never messaged again, on any campaign. A recipient who replies REPORT is recorded as having taken the correct, secure action.

This keeps your program compliant with carrier rules and respectful of employees who do not want simulated texts.

What is the difference between a phishing and a smishing simulation?

A phishing simulation tests email; a smishing simulation tests SMS. Both run on the same platform with the same scheduling, targeting, and automated remediation.

The channels differ in ways that matter: SMS has no gateway to scan links, delivery is gated to business hours, opt-out follows carrier STOP rules, and only employees with a phone number can be targeted. To see how the underlying attack works, read the smishing threat guide.

Do you support voice (vishing) simulations?

Not as a live campaign channel. Email and SMS campaigns ship today; outbound voice delivery is scaffolded in the platform but deferred to a later release, so we do not sell it as available.

You can train the reflex now with the immersive vishing exercise and the callback-phishing exercise, which drills the text-then-call pattern that pairs with smishing. See how voice phishing works for the attack side.

Is smishing simulation legal in the EU?

Yes, when run correctly. Testing your own employees with simulated messages is lawful, but GDPR Article 88 and works-council agreements govern how you monitor staff. The platform supports this with jurisdiction settings, aggregate-only reporting, and standard opt-out handling.

As with any monitoring program, confirm your works-council and privacy obligations before launch in regulated jurisdictions.

How do you run a smishing simulation?

Pick the SMS channel, choose an approved template, set a send window, and select recipients. Only employees with a phone number on file are eligible, and the audience picker shows who is in and who is excluded before you launch.

Delivery is held until working hours in each recipient timezone and spread across the window to avoid burst patterns and carrier rate limits. Taps and REPORT replies are tied to a signed, time-limited token, so every interaction maps back to a specific recipient and dispatch.

What number do the messages come from?

Messages send from a platform-owned origination number through a transactional SMS provider, with the origination country configurable per tenant so the number looks local to the people receiving it.

Standard carrier opt-out applies to that number: a STOP reply lands in both a per-tenant and a platform-wide registry and stops all future messages.

Does failing a smishing test affect the employee risk score?

Yes. A tapped text feeds the same susceptibility signal as a clicked email, so it moves that person’s human risk score and can trigger risk-based automation.

Reporting the text counts the other way. Spotting and flagging a lure is the behavior the score rewards, and it is the metric worth managing over click rate alone.

How often should we run smishing simulations?

Often enough that the channel stays in people’s heads, rarely enough that it does not read as harassment. Most programs fold SMS into the existing campaign calendar rather than running it as a separate exercise, so a person sees a mix of channels over a quarter.

Because reporting rate is the headline metric, the useful cadence is whatever lets you see that number move campaign over campaign rather than chasing a single result.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.