How criminals test each SMS message on their own phone first to confirm it will reach yours
There are two kinds of criminals: lazy ones, and smart ones who test, refine, and guarantee delivery.
In this short article, I’ve written from the perspective of a smart criminal to help security professionals, telecoms, banks, and regulators understand exactly how phishing campaigns are prepared for SMS. The goal is to make the unseen visible.
Everything you’re about to read is real. It happens every day.
And in the video demo below, I show exactly how it’s done — live.
Not all criminals are sloppy. Some of us test, refine, and verify before launching an attack. That’s how you stay one step ahead.
Before I run a phishing campaign, I make sure every single message gets delivered. Not just most. Every one. I don’t take risks by guessing or hoping my link will make it through. I validate it in real time using the same infrastructure that banks and tech companies use to communicate with their customers.
Here’s how I do it.
Step 1: Build a simple web app using a cloud messaging provider
Nothing fancy. Just a clean form that lets me enter a mobile number and a message. I hook it up to an SMS API and I’m ready to test in minutes. With a bit of scripting, I can send hundreds of variations on demand.
You can watch exactly how this works in the video demo — from message creation to delivery confirmation.
Step 2: Send the test message to myself
I enter my own phone number, the same one I use on the mobile network I plan to target. When the message lands, I know two things instantly:
- It wasn’t blocked by the network’s defences
- It’ll land for every other subscriber on that same network
That’s not speculation. It’s how mobile delivery works. If my message gets through to me, it’ll get through to everyone else using the same network. That’s why this step is so valuable. It validates both deliverability and defence evasion in one shot.
The video walks through this exact test — proving the message lands and why that matters.
Step 3: Test multiple links
I don’t stop at one URL. I rotate through different links — some cloaked, some redirected, some with slight variations. I track which ones land and which ones don’t. Most of the time, they all go through. But when one gets blocked, I swap it out. Fast.
There’s no guesswork here. I test in the same environment I’ll attack. No threat intelligence feed can keep up with this. And AI can’t detect my messages because they look identical to legitimate messages that are supposed to reach my victims.
Step 4: Launch with confidence
Once I’ve verified which message formats and links land consistently, I’m ready. Whether I’m pretending to be a bank, a parcel delivery, or a crypto platform, I can now send the real campaign knowing it’ll be delivered without delay.
No blocks. No flags. Just reach.
Why this works
These messaging platforms are built for businesses, but smart criminals like me use them too. They’re easy to access, cheap to operate, and produce messages that look exactly like the ones people already trust. I don’t need burner phones. I don’t need SIM cards. I don’t need a fraud ring running scripts.
But if I want to test a different channel, I might use a regular SIM. I use whatever gets results — and right now, this method works better than anything else.
All I need is one clean test that lands on my phone.
Video Demo
Watch the full video demo below to see how this is done step by step. From building the test message using a cloud SMS platform, to confirming it lands, to rotating links — this is the exact process used to prepare phishing attacks that impersonate banks, payment apps, and crypto platforms across Europe and North America.
Important Reminder:
This isn’t a how-to guide. It’s a warning.
Everything described here is already happening. The video and article are designed to show how smart attackers bypass traditional defences with minimal effort.
The question isn’t whether this technique works. The question is why no one is stopping it.
