Smishing Simulations
Test how your employees respond to SMS phishing, the channel with no email gateway in front of it. Send realistic but harmless text lures, measure who taps and who reports, and route the rest into targeted training.
What is a smishing simulation?
A smishing simulation is a controlled test in which an organization sends realistic but harmless SMS phishing messages to its own employees, then measures who taps the link and who reports it. It is the SMS counterpart to a phishing simulation, run on the channel that has no gateway in front of it.
The reason to test SMS separately is that the defenses are not the same. A suspicious email passes a secure email gateway, a link scanner, and a banner warning before anyone sees it. A text arrives on a personal phone with none of that, on a screen where the address bar truncates and the reply-in-two-seconds instinct is strongest.
So people who reliably spot the same trick in their inbox still tap it in Messages. A phishing simulation will not surface that gap, because it never tests the channel where the gap lives.
Why SMS is the blind spot in most programs
Three things make text a softer target than email, and none of them are fixed by training people on email.
No gateway, no scanning
There is no SMS equivalent of a secure email gateway. Nothing rewrites the link, checks the domain age, or stamps an external-sender banner on the message before it reaches the phone.
A screen built to hide the URL
Mobile browsers truncate the address bar, so a lookalike domain reads as legitimate. Attackers pair that with URL shorteners and freshly registered domains that no blocklist has seen yet.
Pressure plus a personal device
Texts get read within minutes and often on a phone the company does not manage. A delivery exception or a toll notice converts urgency into a tap before anyone thinks to verify.
The scale is not theoretical. The US FTC recorded $470 million in text-scam losses in 2024, with package-delivery and fake-toll lures among the most reported patterns.
How smishing simulations work
Four steps from setup to measured behavior, on the same platform as your email program.
Configure
Pick the SMS channel, choose an approved smishing template, set a send time, and select recipients. Only employees with a phone number on file can be targeted.
Deliver
Messages send from a platform origination number, gated to each recipient business hours in their own timezone, and spread across a window to avoid burst patterns and carrier rate limits.
Track
Every link tap and REPORT reply is recorded against a signed, time-limited token, so each interaction is tied back to the specific recipient and dispatch.
Remediate
Recipients who tap the lure are auto-enrolled in a learning path that drills the exact pattern they fell for, with deadlines and manager visibility.
SMS templates with built-in red flags
A library of approved smishing templates modeled on the lures attackers actually send, each annotated with the cues employees should learn to spot.
Real-world lure patterns
Package-delivery, account-suspended, password-expiry, and unsolicited-MFA-code templates mirror the highest-volume smishing campaigns, including the toll and delivery lures behind 2024 FBI complaints.
Liquid personalization
Templates merge recipient and company details so the text reads like a targeted message rather than a generic blast, matching how modern smishing kits operate.
Tagged red flags
Each template marks the teaching cues (suspicious sender, pressure in the content, masked link) so the post-tap lesson points to exactly what gave the attack away.
Every text is yours to customize
Send an approved template as it is, clone one to rewrite the message, sender ID, and lookalike link, or author a new lure from scratch with Liquid variables. The reveal page updates to match, and STOP and REPORT opt-out handling stays built in.
- Use as-is
- Clone and edit
- Build from scratch
Example SMS lures
The four highest-volume smishing patterns, ready to send.
Opt-out and compliance built in
SMS carries rules that email does not. The platform handles them so your program stays defensible.
STOP and REPORT handling
Recipients who reply STOP are added to a per-tenant and a platform-wide opt-out registry and never texted again. A REPORT reply is recorded as the correct, secure response.
Business-hours delivery
Texts are held until working hours in each recipient timezone, so a simulation never lands at 3 a.m. or reads as harassment.
Phone-number gating
Only employees with a phone number on file are eligible, and the audience picker shows exactly who is in and who is excluded before launch.
GDPR and works councils
Jurisdiction settings and aggregate-only reporting support GDPR Article 88 and works-council requirements for monitoring employee behavior.
SMS funnel analytics
See the whole journey of a text campaign and turn it into a baseline you can track campaign over campaign.
One funnel for every campaign
Track dispatched, clicked, and reported alongside email metrics in a single behavior funnel, broken down by team so you can see which groups need attention.
Report rate as the headline
Report rate sits alongside click rate and fail rate, because the share of recipients who flag a text is the metric that tracks with real resilience.
Export for evidence
Pull CSV and PDF reports for audit evidence and board reporting, with the same shape as your email simulation results.
From a tapped link to a measured risk score
A simulation that ends in a report is an event. A simulation that changes what happens next is a program.
Just-in-time remediation
Anyone who taps the lure is auto-enrolled in the lesson that drills the exact pattern they fell for, with a deadline and a grace period, while the moment is still fresh.
It moves the human risk score
A failed text feeds the same susceptibility signal as a failed email, so a person’s human risk score reflects the channel they are actually weak on, not just their inbox behavior.
Rules act on the result
Risk-based automation watches the score and acts when someone crosses a band, with dry-run, an audit log, and a blast cap so nothing fires by surprise.
Voice (vishing) simulations
Voice-call simulations are not a live campaign channel yet. Email and SMS ship today; the voice channel is scaffolded in the platform and deferred to a later release, and we would rather say that plainly than sell a roadmap.
You can still train the reflex now. The immersive vishing exercise puts learners on a simulated call and drills hang-up-and-call-back-on-a-known-number, and the callback phishing exercise covers the text-then-call pattern that pairs smishing with a voice follow-up.
- Live today: email and SMS campaign delivery
- Available today: immersive vishing and callback-phishing exercises
- Not yet available: outbound voice campaign delivery
Frequently asked questions
How are the text messages delivered?
Messages are sent from a platform-owned origination number and delivered through a transactional SMS provider. Delivery is gated to each recipient business hours in their own timezone and spread across a send window to avoid burst patterns and carrier rate limits.
Only employees with a phone number on file can be selected as recipients, and the audience picker shows who is eligible before you launch.
How does opt-out work?
Standard SMS opt-out is built in. A recipient who replies STOP is added to a per-tenant and a platform-wide opt-out registry and is never messaged again, on any campaign. A recipient who replies REPORT is recorded as having taken the correct, secure action.
This keeps your program compliant with carrier rules and respectful of employees who do not want simulated texts.
What is the difference between a phishing and a smishing simulation?
A phishing simulation tests email; a smishing simulation tests SMS. Both run on the same platform with the same scheduling, targeting, and automated remediation.
The channels differ in ways that matter: SMS has no gateway to scan links, delivery is gated to business hours, opt-out follows carrier STOP rules, and only employees with a phone number can be targeted. To see how the underlying attack works, read the smishing threat guide.
Do you support voice (vishing) simulations?
Not as a live campaign channel. Email and SMS campaigns ship today; outbound voice delivery is scaffolded in the platform but deferred to a later release, so we do not sell it as available.
You can train the reflex now with the immersive vishing exercise and the callback-phishing exercise, which drills the text-then-call pattern that pairs with smishing. See how voice phishing works for the attack side.
Is smishing simulation legal in the EU?
Yes, when run correctly. Testing your own employees with simulated messages is lawful, but GDPR Article 88 and works-council agreements govern how you monitor staff. The platform supports this with jurisdiction settings, aggregate-only reporting, and standard opt-out handling.
As with any monitoring program, confirm your works-council and privacy obligations before launch in regulated jurisdictions.
How do you run a smishing simulation?
Pick the SMS channel, choose an approved template, set a send window, and select recipients. Only employees with a phone number on file are eligible, and the audience picker shows who is in and who is excluded before you launch.
Delivery is held until working hours in each recipient timezone and spread across the window to avoid burst patterns and carrier rate limits. Taps and REPORT replies are tied to a signed, time-limited token, so every interaction maps back to a specific recipient and dispatch.
What number do the messages come from?
Messages send from a platform-owned origination number through a transactional SMS provider, with the origination country configurable per tenant so the number looks local to the people receiving it.
Standard carrier opt-out applies to that number: a STOP reply lands in both a per-tenant and a platform-wide registry and stops all future messages.
Does failing a smishing test affect the employee risk score?
Yes. A tapped text feeds the same susceptibility signal as a clicked email, so it moves that person’s human risk score and can trigger risk-based automation.
Reporting the text counts the other way. Spotting and flagging a lure is the behavior the score rewards, and it is the metric worth managing over click rate alone.
How often should we run smishing simulations?
Often enough that the channel stays in people’s heads, rarely enough that it does not read as harassment. Most programs fold SMS into the existing campaign calendar rather than running it as a separate exercise, so a person sees a mix of channels over a quarter.
Because reporting rate is the headline metric, the useful cadence is whatever lets you see that number move campaign over campaign rather than chasing a single result.
See RansomLeak in Action
Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.