The PLDT Group, through its wireless unit Smart Communications Inc. (Smart), is intensifying efforts to combat text scams. As part of this initiative, Smart has enhanced its blocking tools and expanded its #BeCyberSmart awareness campaign.
However, the PLDT Group also highlights the evolving strategies employed by cybercriminals targeting unsuspecting customers.
“Smart’s much-improved blocking capabilities have prevented a significant number of SMShing messages from reaching customers,” said Jojo Gendrano, SVP and chief information security officer at PLDT and Smart. “But scammers keep looking for new ways to run their phishing activities. They now send unclickable links, but with the same goal of luring customers into opening malicious domains.”
According to Smart’s investigation, these scammers are altering URLs by replacing dots with other characters, such as underscores or slashes. They then instruct recipients to manually copy the altered address, paste it into their browser, and replace the special characters with dots to activate the link. In some cases, scammers are using numeric links that resemble IP addresses, which can still be clicked by unsuspecting users.
In response to these new threats, the PLDT Group has not only strengthened its cybersecurity tools but is also urging customers to play an active role in identifying and reporting these scams. The #BeCyberSmart campaign provides practical tips to help users recognize phishing attempts, summarized by the acronym SCAM.
- S is for Suspicious: Avoid responding to calls or messages from unknown sources, especially those requesting one-time passwords (OTPs). Legitimate entities, including banks and Smart representatives, will never ask for your OTP.
- C is for Clickbait: Be wary of messages offering unrealistic deals or prizes, which often contain links designed to lure victims into clicking.
- A is for Alarming: Scammers frequently create a sense of urgency, claiming account suspensions or other issues to prompt victims to take immediate action.
- M is for Malicious: These messages, whether sent via SMS or email, often include links leading to phishing websites.
Smart encourages customers who encounter suspicious messages or calls to report them to the designated cybersecurity incident email addresses (cybersecurityincidents@smart.com.ph and cybersecurityincidents@pldt.com.ph) or through Smart’s official social media channels and hotline.

