Full Report
Smishing (or SMS phishing) is far more frequent during the holidays. Learn to recognize the signs of a smish and how to avoid falling victim to one.
Analysis Summary
# Best Practices: Combatting Package Tracking Smishing Scams
## Overview
These practices address **Smishing (SMS Phishing)**, specifically themed around package delivery and logistics. These attacks exploit urgency and holiday shipping volume to trick users into disclosing Personal Identifiable Information (PII) and credit card data through fraudulent websites mimicking legitimate carriers like USPS.
## Key Recommendations
### Immediate Actions
1. **Do Not Reply to Lures:** Never reply to suspicious texts. Replying confirms the number is "live" and active, increasing the volume of future attacks.
2. **Avoid Link Clicks:** Do not click links in unsolicited messages. If a package issue is suspected, navigate directly to the official carrier website (e.g., usps.com) and manually enter the tracking number.
3. **Inspect Sender IDs:** Verify the country code. Domestic services like the USPS will rarely contact U.S. residents from international codes (e.g., +63 for the Philippines).
4. **Analyze Urgency & Grammar:** Look for red flags such as "dear users," inconsistent capitalization, missing punctuation, and unusual pricing (e.g., "$0.3" instead of "$0.30").
### Short-term Improvements (1-3 months)
1. **Deploy Smishing Simulations:** Implement Security Awareness Training (SAT) that includes SMS-specific simulations to familiarize users with mobile-based threats.
2. **Report to Carriers:** Forward smishing messages to **7726 (SPAM)**. This helps mobile carriers identify and block malicious numbers across their networks.
3. **Use Official Apps:** Encourage employees to use official carrier apps for tracking, which provide secure, authenticated notifications rather than relying on SMS links.
### Long-term Strategy (3+ months)
1. **Zero-Trust Mobile Access:** Implement Mobile Device Management (MDM) policies that restrict the ability to open links from non-work-related messaging apps on corporate-managed devices.
2. **Brand Protection Monitoring:** Monitor for typosquatted domains that mimic your organization’s brand to proactively block fraudulent sites at the DNS level.
3. **Multi-Factor Authentication (MFA):** Ensure all sensitive accounts utilize hardware keys or app-based authenticators (rather than SMS-based MFA) to mitigate the impact if credentials are stolen via smishing.
## Implementation Guidance
### For Small Organizations
- **Education Focus:** Conduct informal "lunch and learn" sessions showing screenshots of real smishing attempts.
- **Policy:** Establish a "Never Click" policy for SMS-based links; require employees to use browser bookmarks for all carrier tracking.
### For Medium Organizations
- **Automated Training:** Utilize managed SAT platforms (like Huntress SAT) to automate smishing simulations and track high-risk user groups.
- **Reporting Pipeline:** Create a simple internal process (e.g., a dedicated Slack channel or email) where employees can report suspicious texts.
### For Large Enterprises
- **Technical Controls:** Implement Protective DNS (PDNS) to block access to known malicious domains and newly registered domains (NRDs) often used in smishing.
- **Threat Intelligence:** Integrate mobile threat feeds into the Security Operations Center (SOC) to track regional smishing trends during peak seasons.
## Configuration Examples
*While this article is awareness-focused, the following configurations are recommended to mitigate smishing impact:*
- **Mobile OS Filtering:** Enable "Filter Unknown Senders" in iOS (Settings > Messages) or "Spam Protection" in Android Messages.
- **DNS Filtering:** Configure corporate DNS to block top-level domains (TLDs) frequently used by scammers that differ from the official `.com` or `.gov` sites.
## Compliance Alignment
- **NIST SP 800-53:** AT-2 (Security Awareness Training) and SI-8 (Spam Protection).
- **ISO/IEC 27001:** Annex A.7.2.2 (Information security awareness, education, and training).
- **CIS Controls:** Control 14 (Security Awareness and Skills Training).
## Common Pitfalls to Avoid
- **Trusting Functional Menus:** Do not assume a site is real just because the "Help" or "Terms of Service" buttons link to the real company. Scammers often link to legitimate pages to build credibility.
- **Falling for Small Sums:** Being lured by low-cost "redelivery fees" (e.g., $0.30). Attackers aren't after the 30 cents; they are after the credit card details entered on the payment page.
- **Mistaking Convenience for Security:** Clicking a link because it is faster than typing a URL.
## Resources
- **Official Tracking:** [usps[.]com]
- **Reporting Spam:** [ftc[.]gov/complaint]
- **Managed SAT:** [mycurricula[.]com/limited-preview/prxR8MOW6OQA] (Defanged)
- **Carrier Reporting:** Text the message to **7726** (Standard across most US carriers).