Smishing Surges 230% in Q1 2026 — Who’s Being Targeted?

The numbers are alarming. SMS-based phishing, known as smishing surged 230% in Q1 2026 compared to the same period in 2025, according to data aggregated from mobile carrier threat intelligence programmes and community reports submitted to PhishScout.
The shift is not accidental. As email security gateways have become more sophisticated at detecting and blocking phishing links, threat actors have pivoted to a channel with far weaker defences: the SMS inbox.
Email security has matured significantly over the past decade. DMARC, DKIM, SPF, anti-phishing AI engines, and sandboxed link detonation have made it substantially harder to deliver a phishing link via email without it being caught. SMS has none of these protections.
There is no equivalent of DMARC for SMS. There is no SPF record a mobile carrier checks before delivering a text. Sender ID spoofing is trivially easy. And critically — the click-through rate on SMS phishing links is dramatically higher than email. Research consistently shows mobile users click SMS links at rates 8 to 10 times higher than email links, driven by the perceived urgency and trust associated with text messages.
The economics are compelling for attackers. Bulk SMS services — many operating legally in grey markets — can deliver millions of messages for a few hundred pounds. The return on investment from even a small percentage of victims is substantial.
Parcel delivery failure is by far the most prevalent smishing lure currently active. Messages impersonating Royal Mail, DHL, UPS, FedEx, and Evri tell the recipient their parcel couldn’t be delivered and a small fee is required to reschedule. The fee is typically £1.99 to £2.99 — low enough not to trigger suspicion. Once card details are entered, they are harvested and sold or used for larger fraud.
HMRC tax refund was also particularly active in the January-April period around UK tax season. Messages claim the recipient is owed a tax refund and must click to claim it within 24 hours. The landing page harvests HMRC credentials, National Insurance numbers, and bank details.Bank fraud alert — messages purporting to be from Barclays, Lloyds, NatWest, or HSBC warning of suspicious activity on the account and requesting immediate verification. These campaigns are highly targeted, with attackers using data from previous breaches to pre-populate victims’ names and partial account numbers to add credibility.
NHS appointment confirmation — a relatively new lure observed in Q1 2026, exploiting trust in the NHS brand. Messages claim to confirm or reschedule a medical appointment and ask for personal details to verify identity.
Council tax payment — targeting UK residents specifically, impersonating local councils including Sandwell, Birmingham, and Manchester councils with messages about overdue council tax payments.
The targeting patterns in 2026 smishing campaigns reveal a calculated approach to victim selection.
Geographic targeting — UK residents are disproportionately targeted compared to their population size. The combination of high smartphone penetration, the Royal Mail brand as a universally trusted lure, and HMRC as a high-value credential target makes the UK a primary focus for smishing operations based in Eastern Europe and Southeast Asia.
Age demographic — users over 55 are significantly more likely to click smishing links, driven by lower familiarity with the lure format and higher likelihood of expecting parcel deliveries and tax correspondence.
Previous breach victims — threat actors purchase data from previous breaches to identify victims with known mobile numbers and associated email addresses. This allows targeted campaigns that include the victim’s name, making the message far more convincing.
Small business owners — a growing trend is smishing campaigns targeting sole traders and SMB owners, impersonating HMRC for VAT refunds or Companies House for filing deadline reminders.
Modern smishing operations are sophisticated enterprises. PhishScout’s analysis of active campaigns reveals a common infrastructure pattern:
SIM farms — banks of SIM cards used to send messages at scale, rotating numbers to avoid carrier blocks. Some operations use hundreds of SIM cards simultaneously.
Bulletproof hosting — landing pages are hosted on infrastructure in jurisdictions with limited law enforcement cooperation, with domains registered minutes before the campaign launches and abandoned within 24-48 hours.
Phishing kits — pre-built landing pages impersonating Royal Mail, HMRC, and major banks are sold on criminal forums for £50-£200. They include mobile-responsive design, real-time credential notification to the attacker, and automatic redirection to the legitimate site after data capture to reduce victim suspicion.
Traffic distribution systems (TDS) — increasingly, smishing links pass through a TDS that checks the victim’s device, location, and browser before deciding whether to serve the phishing page or redirect to a benign site. This makes detection by security researchers significantly harder.
How to Protect Yourself and Your Organisation
For individuals:
Never click links in unsolicited text messages, regardless of how legitimate they appear. If you receive a message about a parcel, go directly to the carrier’s website by typing the URL manually. If you receive a message from HMRC, log into your Government Gateway account directly.
Report smishing messages by forwarding them to 7726 (SPAM) on any UK mobile network — this is a free service that feeds into carrier fraud detection systems.
For organisations:
Deploy Mobile Device Management (MDM) solutions that can enforce safe browsing policies on corporate mobile devices. Train employees specifically on smishing — it’s often overlooked in phishing awareness programmes that focus exclusively on email.
Consider implementing a company-wide policy that no financial transactions, credential resets, or sensitive data submissions will ever be initiated via SMS link.
For security teams:
Monitor threat intelligence feeds for active smishing campaigns targeting your industry or brand. PhishScout’s intel feed tracks active smishing infrastructure in real time.
If your brand is being impersonated, file a takedown request with the hosting provider and report to Action Fraud (UK) at actionfraud.police.uk.
Smishing is no longer a niche attack vector — it is one of the primary delivery mechanisms for credential theft and financial fraud in 2026. The 230% surge in Q1 is not an anomaly; it reflects a fundamental shift in attacker strategy away from increasingly hardened email channels toward the relatively undefended SMS inbox.
Defenders who have focused their phishing awareness training and technical controls exclusively on email need to urgently extend their programmes to cover mobile-based social engineering.
—
Spotted a smishing campaign? Submit it at phishscout.net
—