Smishing
Smishing is phishing delivered by text message. The channel matters more than the technique: messages arrive on a personal device outside the corporate mail gateway, sender identifiers are easy to forge, and the interface gives the recipient almost nothing with which to check a link before tapping it.
Every inspection layer that protects email is absent here. There is no gateway rewriting the link, no attachment sandbox, no banner marking the sender as external, and usually no reporting button. On a phone the address bar is short and truncated, which makes a lookalike domain far more effective than it would be on a desktop.
Two pretexts do most of the damage in a corporate context. A delivery or payment notification that arrives at a plausible moment and asks for a small confirmation, and a message that claims to come from a colleague or an executive and moves the conversation to a messaging application, where the impersonation continues without any of the controls that apply to company channels.
For the organisation the awkward part is jurisdiction: the device is often personal, the number was published by the employee, and the company has no telemetry on the channel at all. That makes reporting the only signal available, which is why the metric worth tracking in an exercise is not how many people tapped the link but how many told someone, and how quickly. The same measurement applies across phishing channels including quishing, and it is what the awareness testing that covers messaging as well as email is designed to produce.