{
  "id": "MSG-PHISHING",
  "slug": "msg-phishing",
  "title": "Content must not solicit credentials or sensitive data",
  "statement": "Messages must not ask recipients for passwords, full card numbers, SSNs, or account credentials.",
  "rationale": "Credential solicitation over SMS is indistinguishable from smishing from the carrier’s side, and it is filtered and fined accordingly. Legitimate businesses do not need it — verification belongs behind an authenticated session, not in a text reply.",
  "layer": "MESSAGE_CONTENT",
  "layerSlug": "message-content",
  "object": "campaign.sample[]",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "HARD_STOP",
  "authorities": [
    "CTIA",
    "T-Mobile",
    "Twilio",
    "TCR"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Remove any request for credentials or full financial identifiers. Link to an authenticated page on your own domain instead of collecting data by reply.",
  "catalogIds": [
    "MSG-248"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/message-content/msg-phishing/",
  "markdown": "https://ekas.io/rules/10dlc/message-content/msg-phishing.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
