Keepnet – AI-powered human risk management platform logo
Menu
HOME > blog > mobile phishing reporting gap

The Mobile Phishing Reporting Gap: Why Security Teams Never See SMS and Voice Attacks

Employees report suspicious email in one click. SMS and voice attempts usually go unreported, so security teams never see them. Here is what that costs.

Ozan Ucar, Founder and CEO of Keepnet

Iceberg diagram of the mobile phishing reporting gap: email reported above the waterline where security teams see it, SMS and voice calls unreported below it.

Most security teams can tell you how many phishing emails employees reported last month. Almost none can tell you how many suspicious text messages or voice calls those same employees received, because there is no way to report them. That missing number is the mobile phishing reporting gap, and it is widening: smishing volume grew 30 to 40 percent quarter over quarter through 2025 (Anti-Phishing Working Group, Phishing Activity Trends Report, Q4 2025, p. 4).

Above the waterline, email phishing gets reported. Below it, SMS and voice attempts reach employees but never reach the security team.

Why Do SMS and Voice Attacks Go Unreported?

Email reporting works because it was built. Someone added a report button to the mail client, someone routed those reports to an analysis queue, and someone measured the reporting rate. None of that exists for a text message. An employee who receives a fraudulent SMS on a personal phone has three options: screenshot it and email IT, mention it to someone later, or ignore it. In practice most attempts end in the third option, so they never become data.

Are Mobile Phishing Attacks More Effective Than Email?

Simulation data says yes. In the 2026 Verizon Data Breach Investigations Report, phone-centric simulations show a median click rate of around 2 percent against roughly 1.4 percent for email, and phone-based failure runs about 40 percent higher (Verizon, 2026 Data Breach Investigations Report, p. 50). The report puts it plainly: higher click rates make mobile devices the new favorite target.

The scale matches. 80 percent of organizations experienced mobile phishing attempts (Verizon Business, 2025 Mobile Security Index).

What Does the Visibility Gap Cost a Security Team?

Four things compound. Incidents go unreported, so nothing starts. Escalation slows, because the first person who notices has no channel. Patterns stay hidden, since a single unreported SMS looks like nothing while forty of them are a campaign. And security telemetry stays incomplete, which means the reporting rate a team presents to its board describes one channel while it is read as if it described all of them.

How Do You Close the Mobile Reporting Gap?

Three requirements, in order.

Reporting has to happen on the device where the attack arrives. A workflow that requires forwarding to a desktop mail client will not be used.

The report has to become an analysed signal, not a screenshot in a ticket queue. The person reporting needs a verdict quickly enough that reporting feels worth doing, and the security team needs an enriched event rather than an image to interpret.

Mobile reports have to join the same pipeline as email reports. A separate inbox for SMS reports recreates the original problem in a new place.

Can Employees Report Suspicious SMS and Calls for Free?

Yes. The Keepnet SMS and Call Reporter app turns a suspicious message or call into a one-tap report, and it is free to install and use, for employees and for individuals. Reports flow into the same analysis pipeline as reported email for Keepnet customers, which is where the visibility part happens.

What Should You Measure Once Reporting Exists?

Start with the reporting rate per channel, not overall. An organization with a 30 percent email reporting rate and no SMS reporting path does not have a 30 percent reporting rate, it has one channel covered. Then measure time from report to verdict, and the share of reported events that turn into a confirmed campaign. Those three numbers describe whether the gap is actually closing.

Read the Full Whitepaper

The full analysis, with the source list and methodology note, is in The Mobile Phishing Visibility Gap. For the underlying numbers see our smishing statistics and vishing statistics guides, and for testing the channels themselves, smishing simulation and vishing simulation.

SHARE ON

twitter
linkedin
facebook

Can your employees report a suspicious text or call?

Book a 30 minute Keepnet walkthrough and run it against your own users.
tickEmail has a report button. SMS and voice usually do not.
tickKeepnet SMS and Call Reporter turns both into a one-tap report.
tickReports land in the same pipeline as reported email.

Frequently Asked Questions

What is smishing?

arrow down

Smishing is phishing delivered by SMS. The attacker sends a text message that impersonates a trusted brand or internal function and pushes the recipient to click a link, reply, or call a number.

How do I report a phishing text message at work?

arrow down

If your organization uses a mobile reporting app, report it from the phone itself. If it does not, the usual path is to screenshot the message and send it to your security or IT team, which is slower and often skipped. The gap between those two options is what this article is about.

Why do security teams not see SMS phishing attempts?

arrow down

Because reporting workflows were built for email. Secure gateways, report buttons and analyst queues all sit on the mail path. A text message arrives outside all of it, so unless the employee takes a manual step, the attempt leaves no trace in security tooling.

Is smishing increasing?

arrow down

Smishing volume grew 30 to 40 percent quarter over quarter through 2025 (Anti-Phishing Working Group, Phishing Activity Trends Report, Q4 2025, p. 4).

Does reporting an SMS share the message content with my employer?

arrow down

With the Keepnet SMS and Call Reporter, only what the person explicitly reports is captured. There is no monitoring of the inbox, no call recording and no passive collection.

Can we run simulations on SMS and voice, not just email?

arrow down

Yes. Keepnet runs simulations across email, voice, SMS, QR code and callback, so the reporting rate can be measured on the channels attackers actually use.