SMS Phishing (Smishing): Cybercrime in the Era of Mobile Communication

SMS phishing, or smishing, is a rising form of cybercrime exploiting text messages to steal personal data. Learn how it works, legal sanctions in Indonesia, and prevention strategies to protect yourself from digital fraud.

Technological advancements in communication—particularly mobile phones and Short Message Services (SMS)—have brought tremendous convenience to modern society. However, these same technologies also open new doors for cybercriminal activities. One increasingly common scheme is SMS phishing, better known as smishing. This method exploits users’ trust in mobile communication to steal personal data or manipulate victims into harmful actions.

Definition of SMS Phishing (Smishing)

SMS phishing, or smishing (a portmanteau of SMS and phishing), is a form of phishing conducted through text messages. The objective is identical to traditional phishing—deceiving victims into clicking malicious links or providing sensitive information—but the medium is SMS (PusatSSL, n.d.).

In smishing, perpetrators impersonate trusted organizations such as banks, service providers, or government institutions. They send messages containing links or attachments that, once clicked or downloaded, direct victims to fake websites or install malware designed to harvest personal data (PusatSSL, n.d.).

Smishing is part of a broader phishing ecosystem that includes email phishing, voice phishing (vishing), and social media phishing (Vida, n.d.).

Common Methods and Techniques of Smishing

General Process

  1. Target Selection and Data Gathering
    Attackers may choose victims randomly or based on specific criteria such as banking customers. They often possess partial data—phone numbers, names, or associated institutions.

  2. Impersonation of Trusted Entities
    The attacker sends SMS messages claiming to represent legitimate organizations. This impersonation builds trust and increases the likelihood of compliance.

  3. Malicious Links or Attachments
    Messages often contain links resembling legitimate URLs. When victims click, they are redirected to phishing sites that mimic authentic websites and prompt entry of credentials (usernames, passwords, PINs, OTPs, or card numbers). In some cases, attachments contain malware that infects the victim’s device (PusatSSL, n.d.).

  4. Data Exploitation
    Stolen data is used for unauthorized financial transfers, account takeovers, or further fraud schemes.

Common Techniques and Variants

  • Hidden or Shortened Links
    Attackers use shortened URLs to obscure malicious destinations (PusatSSL, n.d.).

  • Urgency or Threat Tactics
    Messages induce panic through statements like “Your account will be blocked in 24 hours” or “Suspicious transaction detected—verify immediately” (PusatSSL, n.d.).

  • Fake Rewards or Promotions
    Victims are lured with claims of lottery winnings or exclusive offers, requiring them to share data or pay a “processing fee” (UIN Khas Jember Digital Library, n.d.).

  • Sender Number Spoofing
    Attackers forge sender IDs to appear as official organizational numbers (Hukumonline, n.d.).

  • Targeted Attacks (Spear Smishing)
    For high-value individuals such as executives or officials, attackers use personal data to craft convincing, customized messages (UIN Datokarama Repository, n.d.).

  • Malware Installation
    Clicking links may download malicious applications that install keyloggers, spyware, or enable remote access (UIN Datokarama Repository, n.d.).

  • Domain Spoofing (Lookalike Domains)
    Phishing sites mimic legitimate domains by altering small details—e.g., “bank-xx.co” vs. “bankx.co” (Universitas Airlangga E-Journal, n.d.).

Studies show that despite filtering systems and SMS firewalls, attackers continuously find loopholes to deliver malicious messages to users (arXiv, n.d.).

In summary, smishing combines technology and social engineering, manipulating victims into voluntarily surrendering sensitive data.

Legal Aspects and Sanctions in Indonesia

Smishing constitutes a form of cybercrime and digital fraud under Indonesian law. Although no specific statute explicitly defines “SMS phishing,” it falls under several legal provisions, including the Electronic Information and Transactions Law (UU ITE), the Personal Data Protection Law (UU PDP), and, in certain cases, the Indonesian Criminal Code (KUHP).

Electronic Information and Transactions Law (UU ITE)

UU ITE (Law No. 11 of 2008, amended by Law No. 19 of 2016) serves as Indonesia’s main cybercrime regulation.

  • Articles 27–37 prohibit manipulation of electronic information, dissemination of false information, unauthorized access, and interception (UIN Datokarama Repository, n.d.).

  • Articles 35–36 specifically ban the creation, transmission, or distribution of misleading or fraudulent electronic information that harms others (Ejournal APIHI, n.d.).

  • Article 51 outlines penalties for violations, including imprisonment up to 12 years and/or fines up to Rp 12 billion, depending on the severity of harm (Ejournal APIHI, n.d.).

Because smishing involves false links, identity deception, and data theft, its elements fit the UU ITE’s cybercrime provisions.

Personal Data Protection Law (Law No. 27 of 2022)

The Personal Data Protection Law (UU PDP) governs the processing and safeguarding of personal data.

  • Article 67 stipulates criminal and administrative sanctions for anyone who illegally collects or distributes personal data (UIN Datokarama Repository, n.d.).

  • The law upholds the right of every individual to the protection of personal information, making smishing a clear violation of data security principles (UIN Datokarama Repository, n.d.).

Thus, offenders may face prosecution under both UU ITE and UU PDP when proven to have unlawfully obtained personal data.

Indonesian Criminal Code (KUHP)

While the KUHP does not specifically mention cybercrimes, Article 378 on fraud can be applied if smishing results in financial loss or deceit. Stolen digital data may also be interpreted as intangible property theft (Ejournal APIHI, n.d.).
For example, if victims transfer funds based on deception, perpetrators can be charged with fraud under KUHP.

Enforcement Challenges

  • No explicit mention of “SMS phishing.”
    Interpretation of UU ITE and UU PDP articles is essential, as “smishing” is not explicitly named (Ejournal APIHI, n.d.).

  • Transnational nature.
    Perpetrators often operate from abroad using foreign servers, raising jurisdictional challenges (Ejournal APIHI, n.d.).

  • Anonymity and traceability.
    Attackers may use temporary or international SIM cards that are difficult to track (UIN Khas Jember Digital Library, n.d.).

  • Digital evidence complexity.
    Forensic expertise is required to analyze logs, metadata, and IP traces that can be accepted in court (Universitas Airlangga E-Journal, n.d.).

  • Need for specific regulations.
    Scholars recommend the government issue explicit legal provisions targeting phishing and smishing for clearer enforcement (Ejournal APIHI, n.d.).

Summary of Violations and Sanctions

Type of Violation Legal Basis / Article Potential Penalty
Manipulation or falsification of electronic information / transmission of fraudulent links UU ITE Arts. 27–37, 35–36 Up to 12 years imprisonment and/or Rp 12 billion fine (Ejournal APIHI, n.d.)
Illegal collection of personal data UU PDP Art. 67 Criminal sanctions and/or administrative fines (UIN Datokarama Repository, n.d.)
Fraud (if elements are met) KUHP Art. 378 Imprisonment or fines under the Criminal Code (Ejournal APIHI, n.d.)

Recommendations for Prevention and Enforcement

  1. Increase Digital Literacy
    Educate the public to recognize suspicious SMS messages, avoid clicking unknown links, and verify information directly with legitimate institutions.

  2. Strengthen Legal Frameworks
    The government should consider amendments or specific laws explicitly addressing phishing and smishing to enhance legal certainty.

  3. Cross-Sector and International Cooperation
    Telecommunications providers, financial institutions, and law enforcement must collaborate to detect and block malicious messages. International cooperation is crucial for transnational cases.

  4. Enhance Digital Forensics Capacity
    Law enforcement officers require forensic tools and training to collect and validate digital evidence effectively.

  5. Empower Data Protection Authorities
    The Personal Data Protection Authority established under UU PDP must play an active role in oversight, administrative sanctions, and legal coordination.

SMS phishing (smishing) exemplifies how traditional communication technologies can be exploited for modern cybercrime. Despite its seemingly simple medium, smishing can cause severe financial loss, privacy breaches, and erosion of digital trust.

While current Indonesian laws—UU ITE, UU PDP, and KUHP—can be applied to prosecute offenders, the absence of explicit terminology and jurisdictional complexities present ongoing challenges. Therefore, a comprehensive legal update, combined with education and international cooperation, is essential to effectively combat smishing and protect digital citizens.

References

arXiv. (n.d.). An overview of 7726 user reports: Uncovering SMS scams and scammer strategies. Retrieved from https://arxiv.org

Ejournal APIHI. (n.d.). Criminal sanctions against phishing crimes under Indonesian law. Retrieved from https://ejournal.apihi.or.id

E-Journal Universitas Airlangga. (n.d.). Modus operandi of phishing crimes under UU ITE. Retrieved from https://ejournal.unair.ac.id

Hukumonline. (n.d.). Legal sanctions for phishing perpetrators and their methods. Retrieved from https://www.hukumonline.com

PusatSSL. (n.d.). What is smishing? Definition, examples, and 11 protection tips. Retrieved from https://www.pusatssl.com

UIN Datokarama Repository. (n.d.). Legal review of phishing crimes and UU ITE implications. Retrieved from https://repository.iainpalu.ac.id

UIN Khas Jember Digital Library. (n.d.). Legal protection for victims of SMS fraud in Indonesia. Retrieved from https://digilib.uinkhas.ac.id

Vida. (n.d.). Understanding phishing, vishing, and smishing techniques. Retrieved from https://www.vida.id

Next Post Previous Post