To the puzzled: 'Smishing' = 'SMS' ∩ 'phishing' > Signs that you are getting "Smished": [...] when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric se…
This is odd and completely counter to my own anecdotal experience. SMS messages from large companies I interact with (My bank, cell phone provider) always come from fairly static short codes. The elephant in the room here is that SMS is not a medium where integrity or authenticity of a message can be guaranteed—which is one of the big reasons it’s such a popular medium for phishing.
Generally speaking, there are short codes, and long codes. Sometimes alphanumerics are allowed, but the rules vary regionally.
Long codes resemble traditional phone numbers and tend to be treated as more disposable, low volume, and person-to-person. As such, they are typically easier to spoof with.
Short codes tend to be more like car license plates: short random/vanity codes that require a more in-depth process to get access to. They are easier to verify ownership, suited for higher volume messaging, and tend to be backed by automation systems that respond to a set of automated commands like "HELP". These qualities make them less likely to be used for nefarious purposes.
It's definitely a topic I'd love to understand more. Any corrections/additions are very much welcome!