Threats Tagged 'smishing'
View all threats tagged with 'smishing'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'smishing'
Click on any threat for detailed analysis and mitigation recommendations
New customs charges for online orders outside the EU 0 With the introduction of charges/taxes on certain items posted from outside the EU, threat actors appear to be leveraging the situation to send fraudulent SMS and email messages impersonating postal services in an attempt to harvest payment details and personal information. The campaign is already being observed targeting Irish users, and I'd like to highlight this activity publicly as part of a LinkedIn post around our Brand Protection, Threat Intelligence, and Domain Takedown capabilities. Join the discussion | AlienVault OTX General | 06/29/2026, 15:40:51 UTC Added: 06/29/2026, 15:51:30 UTC |
Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages 0 A sophisticated smishing and phishing operation active since the second half of 2025 has impersonated over 267 brands across 72 countries, with particular concentration in Latin America. The campaign generated 4,389 phishing domain instances, with Mexico accounting for 1,851 cases. Telecommunications is the most targeted sector with 1,754 instances, followed by financial services and consumer rewards programs. The operation employs fake Cloudflare error pages as decoys, revealing malicious content only to victims matching specific geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. Approximately 30% of infrastructure is hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain progresses from SMS lures through progressive credential harvesting, ultimately capturing complete credit card details including CVV codes. Join the discussion | AlienVault OTX General | 06/03/2026, 13:18:23 UTC Added: 06/04/2026, 09:03:35 UTC |
Showing 1 to 2 of 2 results