
Smishing in Puerto Rico: when SMS looks like your real bank
Short links mimicking Popular, Oriental, or FirstBank. Educating customers and staff against SMS fraud.
Smishing — SMS phishing — surged in Puerto Rico between 2024 and 2025: messages warning of "suspicious activity" on your Popular or Oriental account, with a short link to a perfect clone page. Brian Krebs documents similar campaigns against continental banks; here the message arrives in Spanish with 787/939 prefixes and urgency tuned to Caribbean business hours.
The attacker does not need to hack the bank: they need the victim to enter credentials on a fake site and approve a transfer or register a new device. SIM swap raises risk when SMS is the only second factor. CISA publishes periodic smishing alerts; Puerto Rico financial institutions should assume customers receive dozens of attempts yearly.
Controls for banks and credit unions: official messages without clickable links (direct to app or memorized URL), verified short code for alerts, and education campaigns in branches and social media. Call center staff need scripts to verify identity without asking the customer for OTP — OWASP social engineering guidance applies to operations, not just dev.
For non-financial companies in PR: employees receive smishing from "couriers" and "payroll" as much as banks. Include smishing in cwAWARE simulations; reporting and blocking a number should be easier than ignoring. Bruce Schneier reminds us mobile users trust SMS more than email — attackers exploit that bias.
Coordinated response matters: FCC reporting, collaboration with local carriers, and phishing domain takedown. Clients in San Juan and Miami serving Puerto Rico accounts need consistent messaging: your bank never asks for full credentials via SMS.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


