Security Awareness7 min read

Smishing, fake apps, and MFA fatigue: the mobile attacks aimed at Israeli SMBs

Protecting a phone is not only about settings on the device. Most mobile incidents start with a message, a fake login page, or a well-timed prompt. Here are the attacks aimed at your team's phones and the practical ways to blunt them.

#Mobile#Phishing#MFA#Security Awareness

Securing the devices themselves, with app protection and encryption, closes one door. The attacks that walk through the other one are aimed not at the phone but at the person holding it. A text message feels more personal and more urgent than an email, people read it while walking or between meetings, and the small screen hides most of the signals that would give a scam away on a laptop. That combination is exactly why so much fraud has moved to the phone. This is a companion to our guide on protecting business data on personal devices: that one is about the settings, this one is about the messages and logins that trick people into handing over access no setting can protect.

Why the Phone Lowers People's Guard

On a computer, an experienced user can hover over a link to see where it really goes, spot a misspelled sender address, and notice that a login page is not quite right. On a phone almost none of that is available. The sender shows as a name, not an address. The full web address is cut off. A person is usually doing something else at the same time. Attackers know this, so they craft messages that rely on speed and habit rather than careful reading. The defense is not a cleverer eye, it is a simple rule the whole team follows, which we come back to at the end.

Smishing: Phishing by Text Message

Smishing is phishing delivered by SMS or a messaging app. The common forms are familiar: a parcel that cannot be delivered until you pay a small fee, a bank warning about a blocked card, a message that looks like it is from the boss asking you to sort something out quickly. Each one carries a link or a phone number and a reason to act now. They work because a text arrives inside the same stream as messages from family and colleagues, so it inherits a trust that email lost years ago. The practical habit that defeats almost all of it: never act on a link in an unexpected message. If your bank or a supplier appears to be asking for something, open their app or type their known address yourself, or call a number you already have. A real organisation will not mind the extra minute.

The Fake Login Page

Many mobile attacks have one goal, which is to land the person on a page that looks like a Microsoft 365 or bank sign-in and capture what they type. On a phone the fake is harder to spot, because the address bar is short and the page can look pixel-perfect. The more advanced versions sit in the middle in real time: the moment someone enters their password and even their multi-factor code, the attacker relays it to the real service and steps into the session. This is why a stolen password plus a one-time code is no longer a guarantee of safety, and why the kind of sign-in you use matters. Phishing-resistant methods, such as passkeys or the Microsoft Authenticator app, are far harder to relay than a code read off a screen and typed into a fake page.

MFA Fatigue and Prompt Bombing

Once an attacker has a working password, often bought from an earlier breach, multi-factor authentication is the last thing standing between them and the account. A common way around it does not break the technology at all, it wears down the person. The attacker triggers approval prompt after approval prompt, sometimes late at night, until a tired or confused employee taps approve just to make it stop. The fix is partly technical and partly human. On the technical side, number matching, which Microsoft now applies by default, forces the person to read a number from the login screen and type it into the app, so a reflexive tap does nothing. On the human side, the rule is blunt: if a prompt appears when you were not trying to sign in, never approve it, and tell whoever handles your IT, because it means your password is already known.

Fake and Lookalike Apps

Not every threat arrives as a message. Some come as an app. These range from outright malicious apps that slip through review, to copycats of a legitimate business tool with a name and icon close enough to fool a quick glance, to genuine free apps that demand far more access than their job requires, a flashlight that wants your contacts and location. The guidance is unglamorous and effective. Install apps only from the official Apple or Google stores, be wary of anything that asks to be installed from a link or a file, and glance at the permissions an app requests before agreeing. If a simple utility wants access to your messages, contacts, and microphone, that is a reason to stop, not a box to tap through.

QR Code Scams

The QR code has become a quiet favourite for attackers, because a phone camera opens the link behind it without any of the scrutiny a typed address gets. A code printed on a fake parking notice, stuck over the real one on a poster, or pasted into an email leads straight to a phishing page, and the victim scanned it themselves. This one is spreading precisely because it feels harmless. Treat a QR code like any other link from an unknown source: useful from a menu you trust, worth real suspicion when it arrives unexpectedly or asks you to sign in or pay after scanning.

SIM Swapping and the Trouble With SMS Codes

There is one attack worth understanding because it targets a control many businesses still rely on. In a SIM swap, an attacker convinces a mobile carrier to move a target's phone number onto a SIM they control, often using personal details gathered beforehand. Once they have the number, any security code sent by SMS goes to them, and accounts protected only by a texted code fall open. The lesson is not that multi-factor authentication is pointless, it is that the SMS version is the weakest kind. Wherever an account matters, an app-based approver or a passkey is a stronger choice than a code by text, and moving your most important logins off SMS is one of the higher-value changes an SMB can make.

What Actually Reduces the Risk

None of these attacks needs an exotic defense, and they overlap enough that a handful of changes cover most of them. Move important accounts to phishing-resistant sign-in, passkeys or an authenticator app with number matching, rather than SMS codes. Use Conditional Access so that company data opens only on devices that meet your standard, which is where the device-protection setup and this threat side meet. Keep phones on an operating system that still gets security updates, since many mobile exploits target versions the maker has stopped patching. Each of these is a setting or a policy that, once in place, protects everyone without asking staff to become security experts.

Make It Normal to Pause and Check

The single most effective control here is not a product, it is a habit, and it is one leadership has to make safe. Most successful mobile scams rely on urgency, so the counter is permission to slow down. Staff need to know that verifying a request through a second channel, calling the person the message claims to be from on a number they already have, is expected and appreciated, never treated as being difficult. When a manager or owner models this themselves, and no one is ever punished for double-checking a payment or a login request, the whole team becomes far harder to rush. This is what security awareness training is really for: not to turn people into experts, but to build the reflex to pause on the messages that matter.

Where NetFortress fits

The mobile threats aimed at small businesses are ordinary and repetitive, which is good news, because ordinary and repetitive is exactly what a well-configured environment and a well-briefed team handle well. NetFortress helps Israeli SMBs move their Microsoft 365 sign-in to phishing-resistant methods, set Conditional Access so business data only opens on protected devices, and run practical awareness training that fits how people actually work. It pairs naturally with locking down the devices themselves. If you are not sure how your team would hold up against a convincing text or a fake login page, ask us for a review and we will give you a clear, honest picture and a short list of what to fix first.

Frequently asked questions

What is smishing?

Smishing is phishing delivered by text message or a messaging app rather than email. Typical examples are a parcel that needs a small fee to be released, a bank warning about a blocked card, or a message that looks like it is from the boss asking you to act quickly. It works because a text arrives in the same stream as messages from family and colleagues, so it inherits trust that email lost long ago. The habit that defeats almost all of it is to never act on a link in an unexpected message, and instead open the company's app or call a number you already have.

Does multi-factor authentication protect us from mobile phishing?

It helps, but not all MFA is equal. A one-time code sent by SMS, or even typed into a fake login page, can be relayed to the real service by an attacker in real time, and SMS codes can also be intercepted through a SIM swap. Phishing-resistant methods, such as passkeys or an authenticator app with number matching, are much harder to defeat. Moving your most important logins off SMS codes is one of the higher-value changes an SMB can make.

What is MFA fatigue, and how do we stop it?

MFA fatigue, or prompt bombing, is when an attacker who already has your password sends approval prompt after approval prompt until a tired or distracted person taps approve just to make it stop. Number matching, which Microsoft now applies by default, blocks the reflexive tap by making you read a number from the login screen and type it into the app. The human rule matters just as much: if a prompt appears when you were not signing in, never approve it and tell whoever handles your IT, because it means your password is already known.

Are QR codes dangerous?

They can be, because a phone camera opens the link behind a QR code without the scrutiny a typed address would get. Attackers print codes on fake notices, stick them over real ones on posters, or paste them into emails so the victim scans their way to a phishing page. A QR code from a menu you trust is fine. One that arrives unexpectedly, or asks you to sign in or pay after scanning, deserves the same suspicion as any link from an unknown source.

What is the single most effective thing we can do?

Two things, one technical and one human. Move important accounts to phishing-resistant sign-in like passkeys or an authenticator app rather than SMS codes, and use Conditional Access so business data opens only on protected devices. Then make it normal to pause and verify: staff should feel free to check an urgent request through a second channel, such as calling the person on a number they already have, and no one should ever be treated as difficult for double-checking a payment or a login.

Ready to secure your business without building an internal IT team?

Book a free consultation and get a practical first look at your IT and Microsoft 365 security posture.