home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Smishing and Executive Impersonation Protection

Smishing, a combination of SMS and phishing, is a kind of social engineering attack that uses text messages (SMS, MMS, RCS) to trick people into downloading malware, sharing sensitive personal or financial information or sending money to cybercriminals. For example, an attacker sends you a text message saying you have a package that cannot be delivered until you sign in and authorize the delivery. You click a link to access an authorization system which asks for personally identifiable information or sign-in credentials.

MES and Lookout for Work 9.0 and higher can detect smishing text messages and warn users to use caution (Android, iOS) or prevent users from accessing the link by moving to a junk filter (iOS only). Smishing Protection proactively alerts the device owners against any such attacks such as:
  • Malicious urls attempting to deliver malicious software or codes to devices (All Tiers)
  • Phishing urls attempting to phish for confidential information or credentials (All Tiers)

  • Executive Impersonations attempting to impersonate executives of the organization (Premium Tier or Add-on)

Lookout will notify users if Lookout detects any of these text message types and provides choices to what they can do to protect themselves. These choices are also configurable by the administrators. If users click those links, they are protected only if Phishing and Content Protection is set up as well.