SmishAlert Threat Signal · Q2 2026

Workforce smishing went link-less. Here's what the data shows.

Our inaugural quarterly briefing on how social engineering is reaching the workforce through text, voice, and chat — built from what employees actually reported to SmishAlert.

Get the full reportApril – June 2026 · Published July 2026

The macro picture

The industry says the phone is the target. We show what the attack looks like.

The scale (industry)The signal (SmishAlert, Q2 2026)
62%of breaches involve the human elementThe human phone is the front line — most reported threats never touched a corporate control.
41%of social-engineering breaches use a non-email vectorText and voice are where the action moved — and where the security stack has the least visibility.
~40%higher success rate for mobile phishing vs. email~4 in 5 reported threats carried no link, defeating the link-based defenses email relies on.
~8 daysbetween fresh SMS phishing campaigns at large orgsWe correlated multiple distinct campaigns this quarter and added 240+ new fingerprints.

Industry figures: Verizon 2026 Data Breach Investigations Report. SmishAlert figures: SmishAlert network, April – June 2026.

The Q2 2026 signal

The shape of the quarter, in four readings.

≈ 4 in 5

reported threats carried no link at all — the attack is a conversation, not a click.

≈ 16%

were voice or callback (vishing), reported alongside text as one blended channel.

≈ 85%

of sender numbers were single-use, burned as fast as they were sent.

≈ 9 in 10

senders used a local (+1) North American caller ID — no ‘foreign number’ tell.

The point: social engineering is now multi-channel — text, chat, and voice — and often carries no link to scan. Malicious URLs still matter, but the link-less attempts to make someone reply, call, or pay are just as dangerous, and more prevalent.

Readings are relative shares of the threats employees reported to SmishAlert during April – June 2026. Sanctioned internal phishing-simulation drills are excluded. As an emerging network, we report shares and patterns rather than absolute volumes.

What we found

Five findings that define the quarter.

01

The link is dead; the conversation is the payload

Roughly four of five reported threats carried no URL. The playbook is now engage first, weaponize later — an innocuous opener that exists only to provoke a reply. Link-scanning and URL-rewriting never get a URL to inspect.

02

Voice and text are one channel now

About one in six reports were voice or callback (vishing), flagged through the same workflow as text — often the second step of a message-first lure. Splitting SMS and voice into two programs splits a single attack in half.

03

Attackers show up wearing local clothes

Nearly nine in ten senders used a local (+1) caller ID, and openers routinely referenced the recipient's real name, city, and even street address. Legitimacy cues can no longer be trusted as a filter.

04

Sender churn defeats the blocklist

Roughly 85% of sender numbers were single-use — a snowshoe pattern that stays under carrier thresholds. What travels across the churn is the template and the behavior, which is what SmishAlert fingerprints.

05

The money is moving upmarket

Alongside consumer bait, the quarter brought pre-IPO / accredited-investor fraud and payroll/HR credential phishing aimed at the workplace. The small subset of link-bearing messages skewed hardest toward these workplace-credential and data-harvest themes.

What employees reported

We take the noise off your team's plate — and surface the attacks underneath.

The single largest category isn't an attack at all — it's unwanted marketing and spam, and handling it well is part of the value. SmishAlert identifies it, classifies it as a non-threat, and folders it away from the user, so it never becomes a false positive in the SOC or a distraction on a busy executive's phone. Here's the full mix, with how each category is handled.

CategoryRelative shareLink?How SmishAlert handles it
Unwanted marketing & spam (local-services solicitations, promos)Leading share (~1 in 4)NoClassified non-threat, filtered & foldered — not escalated
Voice / callback (vishing)~1 in 6Voice, no linkAttack — captured & escalated
Conversational openers (‘wrong number,’ casual intro)~1 in 10NoAttack setup — captured & watched
Investment / financial-return fraud (pre-IPO, accredited investor)NotableNoAttack — captured & escalated
Survey / political data harvestNotableYesAttack — captured & escalated
Payroll / HR / workplace (direct deposit, W-2, shift/portal)NotableSometimesAttack — captured & escalated
All other pretexts (packages, prizes, jobs, health, brand/credential)~1 in 3 combinedMixedTriaged by type

The spam is handled for you — off the SOC queue and off the user's phone. And once it's set aside, the real attacks almost never carry a link. The industry built its defenses for the link-bearing minority.

Get the report

The full Q2 2026 briefing, in one clean PDF.

A board-ready read on how workforce social engineering is changing — sourced from the SmishAlert network, not a third-party feed.

  • All five findings with the full analysis
  • The quarter's tracked campaigns (de-identified teardowns)
  • What it means for security leaders — five recommendations
  • Methodology, definitions, and how to cite

A note on privacy.SmishAlert never reads or correlates an individual's personal messages. Every figure is aggregate and de-identified.

Inside the report

What we tracked this quarter.

SmishAlert correlates individual reports into named campaigns — genuine attacks — and flags notable non-attack patterns worth a security team's attention. A selection from Q2 2026; full de-identified teardowns are in the report.

Attack

Payroll-verification campaign

HR/direct-deposit and shift-confirmation lures using link-shortener redirection; correlated across multiple reports to a shared sender and template family.

Attack

Payment-authorization voice scam

A high-value electronics ‘order authorization’ pretext designed to drive the target to call a fraudulent support line.

Attack

Pre-IPO investment campaign

Accredited-investor solicitations name-dropping well-known AI and aerospace firms. This one tracked the headlines — reports spiked alongside the SpaceX IPO buzz, with marquee names swapped in as the news cycle moved.

Attack

Government-citation lure

Motor-vehicle/citation ‘urgent payment’ phishing with a look-alike domain, first seen late Q1 and active into Q2.

Flagged · not an attack

Local-services spam — a data-exposure signal

Not an attack — ordinary local-services marketing we classify as spam. We flag it because the messages arrive pre-loaded with real names, home addresses, phone numbers, and sometimes emails: a signal that personal data is readily available and ready to fuel a future attack.

How to cite this report

SmishAlert Threat Research. "SmishAlert Threat Signal — Q2 2026: The State of Workforce Smishing, Vishing, and Mobile Social Engineering." SmishAlert LLC, July 2026.

Media and analysts may quote these findings with attribution to SmishAlert Threat Research. For data requests, interviews, or methodology, contact press@smishalert.ai.

FAQ

SmishAlert Threat Signal — FAQ

What is the SmishAlert Threat Signal report?

SmishAlert Threat Signal is a quarterly research briefing from the SmishAlert team on how social engineering reaches the workforce through text, voice, and chat — the channels the security stack can't see. It is built from the SmishAlert network, where employees report the smishing and vishing that reaches their phones.

What was the biggest smishing shift in Q2 2026?

The link disappeared. Roughly four of five threats employees reported to SmishAlert in Q2 2026 carried no link at all — the attack now opens with a conversation, not a click, which defeats the link-scanning defenses built for email.

Is vishing (voice phishing) rising alongside smishing?

Yes. About one in six reports in Q2 2026 were voice or callback events, frequently as the second step of a text-first lure. SmishAlert treats text and voice as one blended channel because attackers do.

How does SmishAlert protect employee privacy in this research?

SmishAlert never reads or correlates an individual's personal messages. Classification happens on-device, only coded fingerprints of reported threats are retained, and every figure in this report is aggregate and de-identified.

Can I cite the SmishAlert Threat Signal report?

Yes. Media and analysts may quote these findings with attribution to SmishAlert Threat Research. For data requests, interviews, or methodology, contact press@smishalert.ai.

Measure it on your own workforce

See what this report describes, in your own numbers.

A 30-day exposure pilot turns the quarter's trend into a defensible, board-ready measurement of your workforce — with the known-bad blocked on iOS before the tap.

Or take the 2-minute self-evaluation — no email required.