SmishAlert Threat Signal · Q2 2026
Workforce smishing went link-less. Here's what the data shows.
Our inaugural quarterly briefing on how social engineering is reaching the workforce through text, voice, and chat — built from what employees actually reported to SmishAlert.
The macro picture
The industry says the phone is the target. We show what the attack looks like.
| The scale (industry) | The signal (SmishAlert, Q2 2026) |
|---|---|
| 62%of breaches involve the human element | The human phone is the front line — most reported threats never touched a corporate control. |
| 41%of social-engineering breaches use a non-email vector | Text and voice are where the action moved — and where the security stack has the least visibility. |
| ~40%higher success rate for mobile phishing vs. email | ~4 in 5 reported threats carried no link, defeating the link-based defenses email relies on. |
| ~8 daysbetween fresh SMS phishing campaigns at large orgs | We correlated multiple distinct campaigns this quarter and added 240+ new fingerprints. |
Industry figures: Verizon 2026 Data Breach Investigations Report. SmishAlert figures: SmishAlert network, April – June 2026.
The Q2 2026 signal
The shape of the quarter, in four readings.
reported threats carried no link at all — the attack is a conversation, not a click.
were voice or callback (vishing), reported alongside text as one blended channel.
of sender numbers were single-use, burned as fast as they were sent.
senders used a local (+1) North American caller ID — no ‘foreign number’ tell.
The point: social engineering is now multi-channel — text, chat, and voice — and often carries no link to scan. Malicious URLs still matter, but the link-less attempts to make someone reply, call, or pay are just as dangerous, and more prevalent.
Readings are relative shares of the threats employees reported to SmishAlert during April – June 2026. Sanctioned internal phishing-simulation drills are excluded. As an emerging network, we report shares and patterns rather than absolute volumes.
What we found
Five findings that define the quarter.
The link is dead; the conversation is the payload
Roughly four of five reported threats carried no URL. The playbook is now engage first, weaponize later — an innocuous opener that exists only to provoke a reply. Link-scanning and URL-rewriting never get a URL to inspect.
Voice and text are one channel now
About one in six reports were voice or callback (vishing), flagged through the same workflow as text — often the second step of a message-first lure. Splitting SMS and voice into two programs splits a single attack in half.
Attackers show up wearing local clothes
Nearly nine in ten senders used a local (+1) caller ID, and openers routinely referenced the recipient's real name, city, and even street address. Legitimacy cues can no longer be trusted as a filter.
Sender churn defeats the blocklist
Roughly 85% of sender numbers were single-use — a snowshoe pattern that stays under carrier thresholds. What travels across the churn is the template and the behavior, which is what SmishAlert fingerprints.
The money is moving upmarket
Alongside consumer bait, the quarter brought pre-IPO / accredited-investor fraud and payroll/HR credential phishing aimed at the workplace. The small subset of link-bearing messages skewed hardest toward these workplace-credential and data-harvest themes.
What employees reported
We take the noise off your team's plate — and surface the attacks underneath.
The single largest category isn't an attack at all — it's unwanted marketing and spam, and handling it well is part of the value. SmishAlert identifies it, classifies it as a non-threat, and folders it away from the user, so it never becomes a false positive in the SOC or a distraction on a busy executive's phone. Here's the full mix, with how each category is handled.
| Category | Relative share | Link? | How SmishAlert handles it |
|---|---|---|---|
| Unwanted marketing & spam (local-services solicitations, promos) | Leading share (~1 in 4) | No | Classified non-threat, filtered & foldered — not escalated |
| Voice / callback (vishing) | ~1 in 6 | Voice, no link | Attack — captured & escalated |
| Conversational openers (‘wrong number,’ casual intro) | ~1 in 10 | No | Attack setup — captured & watched |
| Investment / financial-return fraud (pre-IPO, accredited investor) | Notable | No | Attack — captured & escalated |
| Survey / political data harvest | Notable | Yes | Attack — captured & escalated |
| Payroll / HR / workplace (direct deposit, W-2, shift/portal) | Notable | Sometimes | Attack — captured & escalated |
| All other pretexts (packages, prizes, jobs, health, brand/credential) | ~1 in 3 combined | Mixed | Triaged by type |
The spam is handled for you — off the SOC queue and off the user's phone. And once it's set aside, the real attacks almost never carry a link. The industry built its defenses for the link-bearing minority.
Get the report
The full Q2 2026 briefing, in one clean PDF.
A board-ready read on how workforce social engineering is changing — sourced from the SmishAlert network, not a third-party feed.
- All five findings with the full analysis
- The quarter's tracked campaigns (de-identified teardowns)
- What it means for security leaders — five recommendations
- Methodology, definitions, and how to cite
A note on privacy.SmishAlert never reads or correlates an individual's personal messages. Every figure is aggregate and de-identified.
Inside the report
What we tracked this quarter.
SmishAlert correlates individual reports into named campaigns — genuine attacks — and flags notable non-attack patterns worth a security team's attention. A selection from Q2 2026; full de-identified teardowns are in the report.
Payroll-verification campaign
HR/direct-deposit and shift-confirmation lures using link-shortener redirection; correlated across multiple reports to a shared sender and template family.
Payment-authorization voice scam
A high-value electronics ‘order authorization’ pretext designed to drive the target to call a fraudulent support line.
Pre-IPO investment campaign
Accredited-investor solicitations name-dropping well-known AI and aerospace firms. This one tracked the headlines — reports spiked alongside the SpaceX IPO buzz, with marquee names swapped in as the news cycle moved.
Government-citation lure
Motor-vehicle/citation ‘urgent payment’ phishing with a look-alike domain, first seen late Q1 and active into Q2.
Local-services spam — a data-exposure signal
Not an attack — ordinary local-services marketing we classify as spam. We flag it because the messages arrive pre-loaded with real names, home addresses, phone numbers, and sometimes emails: a signal that personal data is readily available and ready to fuel a future attack.
How to cite this report
SmishAlert Threat Research. "SmishAlert Threat Signal — Q2 2026: The State of Workforce Smishing, Vishing, and Mobile Social Engineering." SmishAlert LLC, July 2026.
Media and analysts may quote these findings with attribution to SmishAlert Threat Research. For data requests, interviews, or methodology, contact press@smishalert.ai.
FAQ
SmishAlert Threat Signal — FAQ
What is the SmishAlert Threat Signal report?
SmishAlert Threat Signal is a quarterly research briefing from the SmishAlert team on how social engineering reaches the workforce through text, voice, and chat — the channels the security stack can't see. It is built from the SmishAlert network, where employees report the smishing and vishing that reaches their phones.
What was the biggest smishing shift in Q2 2026?
The link disappeared. Roughly four of five threats employees reported to SmishAlert in Q2 2026 carried no link at all — the attack now opens with a conversation, not a click, which defeats the link-scanning defenses built for email.
Is vishing (voice phishing) rising alongside smishing?
Yes. About one in six reports in Q2 2026 were voice or callback events, frequently as the second step of a text-first lure. SmishAlert treats text and voice as one blended channel because attackers do.
How does SmishAlert protect employee privacy in this research?
SmishAlert never reads or correlates an individual's personal messages. Classification happens on-device, only coded fingerprints of reported threats are retained, and every figure in this report is aggregate and de-identified.
Can I cite the SmishAlert Threat Signal report?
Yes. Media and analysts may quote these findings with attribution to SmishAlert Threat Research. For data requests, interviews, or methodology, contact press@smishalert.ai.
Measure it on your own workforce
See what this report describes, in your own numbers.
A 30-day exposure pilot turns the quarter's trend into a defensible, board-ready measurement of your workforce — with the known-bad blocked on iOS before the tap.
Or take the 2-minute self-evaluation — no email required.