TL;DR:

  • Smishing (SMS phishing) is increasing against UK small businesses — fake HMRC, delivery firm, and bank texts targeting business owners and staff
  • SMS bypasses the email filtering that blocks most phishing — and people are less suspicious of texts than emails
  • Forward suspicious texts to 7726 (NCSC’s spam reporting service), and brief your staff on the common pretexts before someone clicks something they shouldn’t

Email phishing gets most of the attention in cybersecurity guidance — spam filters, suspicious sender domains, generic greetings. But a growing share of phishing attempts are arriving by SMS, and those don’t get filtered at all. Your staff’s phones receive texts directly, without any security layer between the sender and the screen.

Smishing — SMS phishing — uses text messages to do what phishing emails have always done: trick recipients into clicking a link, entering credentials, or calling a fake number. The pretexts are familiar, but the delivery mechanism changes the success rate. People are more trusting of texts, more likely to act quickly on them, and less trained to scrutinise them.

Why Smishing Works Better Than It Should

Email phishing has been a known threat for two decades. Business email clients have spam filters, many organisations have email security gateways, and staff have had at least some training to spot suspicious messages. None of that applies to SMS.

A text arriving on your phone gets no automatic filtering. There’s no spam scoring, no sender reputation check, no header analysis. The message arrives looking identical whether it came from your actual bank or from a fraudster in Eastern Europe using a spoofed sender name.

A few things compound the problem for small businesses specifically:

Business owners use personal phones for business. A text to the owner’s mobile might be about a personal delivery or a business HMRC matter — they’re mixed in the same inbox and often dealt with quickly.

Speed is expected. Texts carry an implicit urgency. People respond to texts faster than emails. That speed reduces the time available to pause and think critically about whether something looks wrong.

Sender names can be spoofed. Texts can arrive in existing conversation threads with a real company if the attacker spoofs the same sender name. A fake HMRC text might appear in the same thread as a genuine HMRC text you received previously.

The Common Pretexts in 2026

The messages that are actually landing in UK inboxes right now fall into a few recurring categories:

HMRC tax and VAT notices — texts claiming your VAT return has an issue, a tax refund is waiting, or an immediate payment is required to avoid a penalty. These are particularly effective against small business owners who self-file and have genuine anxiety about HMRC communications. HMRC does not contact businesses by text about outstanding debt or tax issues.

Parcel delivery failures — fake Royal Mail, DHL, DPD, and Evri texts saying a delivery couldn’t be completed and a small fee (typically £1.99–£2.99) is required to rebook. Small businesses receive a lot of deliveries, so these are plausible. The fee amount is designed to feel low-stakes, but submitting payment card details is the real objective.

Business bank account security alerts — texts appearing to be from NatWest, Barclays, Lloyds, or Starling saying a suspicious transaction has been blocked and urgent action is required. These often include a phone number to call (staffed by fraudsters) or a link to a convincing fake banking site.

Business broadband or phone provider alerts — fake BT, Sky, or Virgin texts about service disruptions, payment issues, or account upgrades requiring immediate action.

How Your Number Gets on Lists

There are several ways attackers obtain mobile numbers for smishing campaigns:

Data breaches are the main one. Your mobile number is in your Companies House registration, on your website, in accounts with suppliers, in loyalty schemes. A proportion of those systems have been breached over the years, and mobile numbers from breaches circulate on criminal forums.

Registered business information is publicly searchable. If you’ve listed a mobile number as a point of contact for your business on Companies House, that’s harvestable.

Bulk text campaigns also use random number generation. An attacker can send texts to every possible number in a UK mobile range — it’s cheap enough that even a low response rate makes it worthwhile.

What to Do If You or Your Staff Receive a Suspicious Text

Don’t click links in texts claiming to be from banks, HMRC, or delivery companies. If you think there might be a real issue with your HMRC account or bank, go directly to the official website by typing the URL yourself, or call the number on your bank card or official HMRC correspondence.

Forward the text to 7726. This is the NCSC’s free spam text reporting service. Texting a suspicious message to 7726 (which spells SPAM on a keypad) sends it to the NCSC for analysis and helps identify and block the sending numbers. It takes ten seconds.

Report HMRC-related smishing to HMRC. HMRC has a dedicated reporting mechanism at phishing@hmrc.gov.uk for suspicious emails and texts claiming to be from them.

If you or a staff member clicked and entered details, treat it as a credential compromise immediately. Change passwords for any account that uses those credentials, contact your bank’s fraud team if payment card details were entered, and report it to Action Fraud (0300 123 2040).

Briefing Your Staff

The most effective thing a small business can do is a ten-minute conversation with anyone who uses a work phone or handles payments. Specific points worth covering:

  • HMRC will never contact you by text to say you owe money or to process a refund
  • Delivery firms do not ask for payment by text to rebook deliveries
  • Any text creating urgency about a financial matter is suspicious by default
  • If they’re unsure about a text, they should ask before clicking anything
  • Forward suspicious texts to 7726

You don’t need a formal policy document or a training session. A quick briefing, particularly if you can reference a real example that’s circulating, sticks better than written guidance.

Technical Controls (Where Available)

For businesses with more control over devices, some additional measures help:

Mobile Device Management (MDM) — if your staff use company-issued phones, an MDM solution can enforce URL filtering and restrict installation of unapproved apps. Small business MDM options include Jamf Now (Apple devices) and Microsoft Intune (available with Microsoft 365 Business Premium).

Carrier-level spam filtering — most UK mobile networks now have some spam text filtering enabled by default. It doesn’t catch everything, but it removes the lowest-effort campaigns.

The NCSC’s Small Business Guide (available at ncsc.gov.uk) covers smishing briefly as part of broader phishing guidance and is worth bookmarking as a reference if staff ask for more information.