Smishing Triad Targeted EU Nations in 2025

The criminal syndicate utilized mass text message campaigns to extract sensitive data and secure illicit profits.

Updated on Sept. 23, 2026 in Cybersecurity

Isometric editorial illustration showing a network of metallic signal hubs connected by glowing paths, representing automated cybercriminal activity.
The 'Smishing Triad' criminal group amassed $1 billion in illicit profits between 2022 and 2025 by deploying automated SMS phishing campaigns across Ireland, France, Germany, Poland, and Lithuania. AI Illustration. Upload story photo >

Live Poll

Do you trust text messages sent by banks or government agencies?

In 2025, the organization known as Smishing Triad conducted extensive fraudulent text message campaigns targeting Ireland, France, Poland, Germany, and Lithuania. The group successfully generated $1 billion in earnings over three years through these activities.

Why it matters

The surge in smishing—a form of phishing conducted via SMS—highlights how cybercriminals shift strategies toward high-volume, automated fraud for financial gain. These operations often bypass traditional defenses, creating significant economic and security risks for both individuals and national infrastructures.

The Smishing Triad sustained a volume of 100,000 text messages daily to execute its campaigns. This operational scale contributed to a total earnings figure of $1 billion across three years of activity.

The players

Smishing Triad

A criminal syndicate specializing in automated SMS-based phishing operations that generate illicit financial returns.

Enisa

The European Union Agency for Cybersecurity that monitors emerging threats and identifies ransomware activity across member states.

The details

The Smishing Triad employs social engineering—the psychological manipulation of people into performing actions or divulging confidential information—by masquerading as trusted institutions like banks, delivery companies, or government agencies. Victims receive SMS messages containing fraudulent links that, when clicked, direct them to malicious portals designed to harvest banking credentials and personal data. This method exploits the inherent trust users place in mobile messaging to circumvent traditional email-based spam filters.

Timeline

  1. 2021: The Russian Conti group executed a ransomware attack against the Irish Health Service Executive (HSE).

  2. 2025: The Smishing Triad targeted users across multiple EU nations including Ireland.

  3. 2026: Enisa released the Threat Landscape 2026 report.

The Tech Race

The 2021 HSE ransomware attack serves as a critical historical benchmark for the economic damage caused by foreign cyber interference. This report places the current rise in smishing and ransomware against that 100 million euro event, illustrating the evolving threat landscape in the EU.

Users should be aware that messages appearing to originate from banks or delivery services are primary vectors for credential harvesting. Verifying senders through official app channels rather than clicking links remains the most effective defense against this automated fraud.

The takeaway

The trajectory of cybercrime increasingly favors automated smishing due to its massive scale and low barrier to entry for criminals. Readers should monitor Enisa threat reports to stay updated on the specific ransomware groups currently targeting their national infrastructure.

Further reading

For more on the current state of digital defense, read the latest analysis in Cybersecurity.

Live Poll

Do you trust text messages sent by banks or government agencies?