How phishing and SMS scams lead to greater attacks
It is time that we see phishing for what it is.
In the recent weeks, the citizens of Bosnia and Herzegovina have started receiving messages about unpaid traffic tickets, warning them that they can pay a 50% reduced ticket within 48 hours, or they will have to pay the full amount and additional penalties for the delay. This is not the first time such scams have caught the eye of the public. In recent years, BiH citizens have received scam SMS messages about package deliveries, bank verification, or parking tickets.
Most people simply dismiss them as annoying scams, while, mostly seniors, less digitally proficient members of the population get scammed. These campaigns often last a few months but rarely get more attention beyond a media warning. Individual cases are processed, but greater operations against the scammers are rarely launched.
That is a dangerous misunderstanding of phishing operations. Phishing is not petty cybercrime, phishing is often initial access.
The same mechanism used to steal money from an individual bank account is also used against energy systems, telecom operators, hospitals, airports, and critical infrastructure worldwide.
In cybersecurity, “initial access” refers to the first successful entry point into a system. In many major attacks, that entry point is not a sophisticated exploit or advanced malware. It is a human being who clicked a link, entered credentials, approved a login request, or trusted the wrong message.
Every major cyberattack starts somewhere. Increasingly, it starts with social engineering. The human factor is often perceived as the weakest link in cyber resilience. Education, training, airtight security protocols and digital literacy are crucial for organizational cybersecurity.
The 2021 attack against the Colonial Pipeline demonstrated how devastating that first step can become. Attackers gained access through compromised credentials tied to a VPN account, eventually forcing the shutdown of the largest fuel pipeline system in the United States. The consequences were not limited to cyberspace. Real-life consequences such as fuel shortages, panic buying, and supply chain disruption followed across the East Coast.
More recently, attacks against MGM Resorts International and Caesars Entertainment highlighted how modern threat actors increasingly rely on phishing, SMS-based deception, and social engineering instead of purely technical intrusion methods. Groups such as Scattered Spider successfully manipulated employees and help desks to gain internal access to highly sensitive systems.
In other words, the same tactic used to target an ordinary citizen in Sarajevo is also being used against multinational corporations and strategic infrastructure.
Accessing personal data, stealing credentials and infecting devices of individuals working in sectors harboring critical infrastructure is a key attack vector in modern cyber warfare.
This is why SMS phishing matters far beyond individual financial fraud. These campaigns continuously test human vulnerability at scale. Attackers are not only searching for software weaknesses; they are searching for distraction, fatigue, trust, and routine.
Critical infrastructure protection is therefore no longer limited to firewalls, servers, and physical security. The human layer has become part of the threat surface itself. A compromised employee account can become an entry point into energy grids, manufacturing systems, logistics networks, telecommunications infrastructure, or defense supply chains.
For countries increasingly dependent on digital infrastructure, this changes the nature of national security entirely. The smartphone in someone’s pocket can become the first domino in a much larger operational chain, and that chain often begins with a single SMS message.
Cyber resilience is not optional. Not in digital, not in the human layer.
[ Direct Line ]
Talk to Our Security Operations Team
If this briefing is relevant to your environment, our team can assess your exposure and show you how Outis defends critical infrastructure.




