The Mobile Phishing Reporting Gap: Why Security Teams Never See SMS and Voice Attacks
Employees report suspicious email in one click. SMS and voice attempts usually go unreported, so security teams never see them. Here is what that costs.
Ozan Ucar, Founder and CEO of Keepnet
Most security teams can tell you how many phishing emails employees reported last month. Almost none can tell you how many suspicious text messages or voice calls those same employees received, because there is no way to report them. That missing number is the mobile phishing reporting gap, and it is widening: smishing volume grew 30 to 40 percent quarter over quarter through 2025 (Anti-Phishing Working Group, Phishing Activity Trends Report, Q4 2025, p. 4).
Why Do SMS and Voice Attacks Go Unreported?
Email reporting works because it was built. Someone added a report button to the mail client, someone routed those reports to an analysis queue, and someone measured the reporting rate. None of that exists for a text message. An employee who receives a fraudulent SMS on a personal phone has three options: screenshot it and email IT, mention it to someone later, or ignore it. In practice most attempts end in the third option, so they never become data.
Are Mobile Phishing Attacks More Effective Than Email?
Simulation data says yes. In the 2026 Verizon Data Breach Investigations Report, phone-centric simulations show a median click rate of around 2 percent against roughly 1.4 percent for email, and phone-based failure runs about 40 percent higher (Verizon, 2026 Data Breach Investigations Report, p. 50). The report puts it plainly: higher click rates make mobile devices the new favorite target.
The scale matches. 80 percent of organizations experienced mobile phishing attempts (Verizon Business, 2025 Mobile Security Index).
What Does the Visibility Gap Cost a Security Team?
Four things compound. Incidents go unreported, so nothing starts. Escalation slows, because the first person who notices has no channel. Patterns stay hidden, since a single unreported SMS looks like nothing while forty of them are a campaign. And security telemetry stays incomplete, which means the reporting rate a team presents to its board describes one channel while it is read as if it described all of them.
How Do You Close the Mobile Reporting Gap?
Three requirements, in order.
Reporting has to happen on the device where the attack arrives. A workflow that requires forwarding to a desktop mail client will not be used.
The report has to become an analysed signal, not a screenshot in a ticket queue. The person reporting needs a verdict quickly enough that reporting feels worth doing, and the security team needs an enriched event rather than an image to interpret.
Mobile reports have to join the same pipeline as email reports. A separate inbox for SMS reports recreates the original problem in a new place.
Can Employees Report Suspicious SMS and Calls for Free?
Yes. The Keepnet SMS and Call Reporter app turns a suspicious message or call into a one-tap report, and it is free to install and use, for employees and for individuals. Reports flow into the same analysis pipeline as reported email for Keepnet customers, which is where the visibility part happens.
What Should You Measure Once Reporting Exists?
Start with the reporting rate per channel, not overall. An organization with a 30 percent email reporting rate and no SMS reporting path does not have a 30 percent reporting rate, it has one channel covered. Then measure time from report to verdict, and the share of reported events that turn into a confirmed campaign. Those three numbers describe whether the gap is actually closing.
Read the Full Whitepaper
The full analysis, with the source list and methodology note, is in The Mobile Phishing Visibility Gap. For the underlying numbers see our smishing statistics and vishing statistics guides, and for testing the channels themselves, smishing simulation and vishing simulation.