Smishing: How Text Message Scams Work and How to Spot Them
Smishing is phishing by text message. Why the trick fails in your inbox but works on your phone, how to read a scam text in seconds, and where to report one.
The message arrives on a Tuesday afternoon, in the middle of everything else. Two lines, a courier, an unpaid customs fee of a couple of pounds, and a link. You did order something recently, and for that amount you are not going to start an argument. That is exactly what the message was built on. It is called smishing, a blend of SMS and phishing, and it is an attempt to extract login details, card numbers or an installed app from you through a text message.
This piece starts with why text messages work so well for this, given that email phishing is now filtered out fairly reliably. The bulk of it is practical: the signals that give a scam text away, and a calm sequence of steps for the case where you already tapped. Reporting comes at the end, and it is worth reading even if you think you know the short code.
What smishing is
Smishing is phishing delivered over messaging. The aim matches the familiar phishing email: get you onto a rebuilt copy of a real site and have you type in whatever is worth stealing. Online banking credentials, a card number with the security code, sometimes just a name and address that can be resold. A second variant asks you to install an app, usually presented as a parcel tracker.
The word has stretched a little past its own components. Messages over WhatsApp or RCS get the same label, because nothing about the technique changes with the transport. Text phishing, SMS phishing and scam text all describe the same object from different angles.
Why text messages work so well
Email phishing has become harder work. Large providers check SPF, DKIM and DMARC to establish whether a message could plausibly have come from the domain in the sender field, and what fails that check lands in spam or never arrives at all. Text messaging has no equivalent layer in general use. Carriers do run filters that catch part of the traffic, and they catch a great deal of it, but there is no cross network proof of sender identity in the way email now has one.
Then there is attention. A text arrives directly in the lock screen notification, and it sits in the same list as the dentist reminder and the one time code from your bank. You will find claims that ninety eight percent of text messages get opened, and those numbers trace back to marketing material from SMS campaign vendors rather than to independent measurement. The everyday observation holds without the false precision: texts get read faster and questioned less than email, because for years this channel carried mostly genuine senders.
Format matters too. Nobody writes elaborately in a hundred and sixty characters, so a blunt instruction reads as perfectly normal there. The tells that give away a fraudulent email are simply absent: no badly rebuilt letterhead, no signature block, no visible sender address. What remains is one sentence and a link, and links are almost always displayed truncated on a phone.
That leaves the sender label. A text can display a name instead of a number, an alphanumeric sender ID, introduced so companies could appear under their own brand. That field is a claim made by the sender and nothing more. When a forged message arrives under the same name as previous real ones, many phones file it into the same conversation thread, lending the fake the credibility of everything above it. How that forgery works in detail is covered in our piece on spoofing.
How to read a scam text
Individual signals are weak on their own, since genuine messages are also short and also contain links. Taken together they resolve into something fairly clear.
- It arrives unexpectedly. No parcel pending, no refund requested, no registration started. This is the strongest single signal and the easiest to miss, because almost everyone has ordered something recently.
- It pushes. A twelve hour deadline, a bailiff in two days, an account about to be suspended. Urgency is not a side effect here, it is the active ingredient, because it shortens the pause in which you would think.
- The address does not match the sender. A bank message pointing at a domain where the bank name appears somewhere in the middle but is not the actual domain. Shortened URLs, endings like .info, .xyz or .cc, hyphens stitching a known brand onto an extra word.
- The number is odd. An international prefix for a domestic bank, or an ordinary mobile number for something claiming to be a government office.
- The greeting is empty. No name, no customer reference, but a case number or an amount you cannot account for.
- It concerns money, access or an installation. Payment, verification, data confirmation, app download. Messages of this kind have no other purpose.
Two examples, with the links removed, in the shape they actually arrive:
Your parcel is being held at our sorting facility. An outstanding customs fee must be paid to continue delivery: [link]
Your banking app registration expires in 12 hours. Renew here: [link]
No spelling mistakes, no threats, and that is precisely why they work. The old rule about clumsy grammar stopped being useful some years ago, because translation tools got good. What remains is the comparison with your own memory. Customs fees are not collected through a link in a text message, a bank does not announce a twelve hour deadline for reactivating your app, and tax authorities do not send text messages about assessments.
The recurring scripts
The stories rotate, the frame stays put. Five variants cover most of what actually lands.
| Script | Typical content | Where it falls apart |
|---|---|---|
| Parcel and customs | Delivery held, small fee due, link to pay | Couriers do not collect fees through a link in a text, real duties go through the carrier or the customs office |
| Bank and account | App registration expiring, account frozen, verification needed | Banks never ask you to sign in through a link inside a message |
| Voicemail | A new voice message, retrievable via link or app | Your voicemail is reached through your own carrier short code, never a download |
| Authority and debt collection | Seizure of goods, fine, tax refund, two day deadline | Public authorities send letters, and tax offices do not text about assessments |
| Prize and refund | You have won, a balance is waiting, a refund is pending | A prize that requires your data or a fee up front is not a prize |
The parcel script is the classic, and it has a history worth knowing. FluBot malware spread through exactly these messages from 2020 onwards: tapping the link produced an offer to install a supposed tracking app, which read the address book after installation and used it to send the next wave. In May 2022 Dutch police took over the infrastructure in an operation coordinated by Europol across eleven countries, and FluBot itself was finished. The distribution idea, slipping an app in behind a delivery notice, outlived it.
A special case is the message from a supposed child: “Hi Mum, this is my new number, message me on WhatsApp.” It often starts as a text and moves into a messenger, where instead of a link comes a request for a quick transfer. Calling back on the old, saved number resolves it in under a minute. The same pattern delivered by voice rather than text is covered in our article on spam calls.
What to do if you already tapped
The reassuring part first, because it applies in nearly every case: an opened link is not yet damage. A web page cannot take over your phone in passing, and a text message carries text rather than executable code. What the fraud needs is your participation, and you can withhold that at any stage.
If you only opened the page. Close it. Enter nothing, not even the apparently harmless postcode. Download nothing. Delete the message afterwards and keep an eye on your account for a few days. Nothing further is required here, and a virus scan achieves nothing either, because nothing was installed.
If you entered data. Act at once, but in order. Change the password for the affected service through the official app or an address you typed yourself, never through a link. If you reuse that password anywhere, change it there too. Where banking details were involved, call your bank on the number printed on the back of your card, and ask them to freeze the card. Then check your recent transactions and dispute anything you did not authorise.
If you installed an app. This is the serious case, and in practice it concerns Android devices, because installing from a source outside the Play Store is technically possible there. On iOS the route runs through the App Store, so this variant barely occurs. Take the device off the network, uninstall the app, then check in settings whether it was granted device administrator or accessibility permissions and revoke those first. Change your passwords from a different device. If doubt remains, a factory reset is the clean answer.
If money moved. Call the bank and report it to the police or the relevant fraud reporting service. Keep everything: the message, the sender number, the statements, screenshots. Transfers can occasionally still be stopped within the first hours.
What you do not do under any circumstances: reply to the message, call the number it gives you, or try to take the matter on yourself. A reply confirms to the sender that a reachable human sits behind that number, and your number becomes worth more the moment it does. If you suspect more has happened than a single message, the checks are laid out in has my phone been hacked.
Reporting and staying out of the way
In the United States and the United Kingdom the route is well established: forward the message to 7726, which spells SPAM on a keypad. The major carriers on both sides of the Atlantic accept it, forwarding is free of charge, and the report feeds the network level filters that stop the next wave earlier. Beyond that, the FTC takes fraud reports at reportfraud.ftc.gov, the FCC handles unwanted messaging complaints, and in the UK Action Fraud is the national reporting point.
Worth knowing if you travel or read advice across borders: 7726 is not universal. In Germany it depends on the individual carrier, and complaints about scam texts go to the telecoms regulator instead, an entirely different process. Advice written for one country transfers badly here, which is one reason the German version of this article names a different route.
On the phone itself there is the smaller remedy. Android lets you block the sender and report the conversation as spam in a single step from the conversation menu. iOS offers the equivalent through the context menu on the message, and on some carriers a dedicated reporting entry that passes the message on with its timestamp and sender number intact. Convenient and correct, but it does not solve anything: the other side rotates sender numbers by the hour. Blocking is housekeeping, not protection.
The habits that actually hold
Four rules cover ordinary life, and they work regardless of how convincing a message looks.
| Situation | What you do instead |
|---|---|
| Text from an unknown number containing a link | Ignore the link, open the provider through your own app or an address you typed yourself |
| Supposed parcel tracking | Take the tracking number from your order confirmation and enter it on the courier site |
| A prompt to install an app | Search the official store only, never follow a link from a message |
| A message from a relative’s new number | Call back on the old, saved number |
On top of that sits the rule that makes the others unnecessary when it is kept: a one time code, a password and card details never belong in a form you reached through a link in a message. No legitimate provider needs that, and no genuine process collapses because you signed in yourself instead.
Guarding your number helps less than people hope. Number ranges get counted through mechanically, which is why lines that appear in no directory still receive these messages. A scam text is therefore no indication that anything is wrong with your device.
What it comes down to
Smishing is technically unambitious. It survives because a text gets read on a phone in a moment when something else is going on, and because a small customs fee looks too trivial to question. Filters catch a fair amount now, though not all of it, and no general proof of sender identity exists for text messages.
That leaves one rule worth carrying. A message that presses you while offering a convenient way out is not information, it is an instruction. Do not take the route it offers. Take the one you already know: your own app, an address you typed, the number on the back of your card. It costs a minute, and it is the only protection that keeps working against every new version of this trick.
Frequently asked questions
- What is smishing?
- Smishing is phishing carried out over text messages. Criminals send an SMS that appears to come from a bank, a courier, a tax office or a family member, and the goal is to push you onto a fake website. There you are asked to type in login details, card numbers or personal information, and sometimes to install an app. The message itself does no damage. It is only the bait.
- What does the word smishing mean?
- It is a blend of SMS and phishing, naming the delivery channel and the fraud in one word. In practice the term now covers any phishing attempt sent through messaging, including WhatsApp and RCS, because the technique does not change with the transport. You will also see the same thing called text phishing, SMS phishing or simply a scam text.
- How do I recognise a scam text?
- Look for three things together: the message arrives unexpectedly, it applies time pressure, and it wants you to tap something. Add shortened or oddly assembled web addresses, a sender number from abroad or a company name in place of a number, a greeting with no name in it, and an amount or reference number you cannot place. The most reliable test is your own memory. Did you actually order, apply for or expect anything?
- What happens if I clicked the link in a scam text?
- Usually nothing beyond a page opening. The damage comes from the second step: typing data in, or installing an app the page offers you. If you only looked and closed it, close the tab, delete the message and watch your account for a few days. If you entered login or payment details, change that password immediately from the official app and call your bank.
- Where do I report a scam text?
- In the United States and the United Kingdom you can forward the message to the short code 7726, which spells SPAM on a keypad and is carried by the major networks free of charge. Beyond that, report to the FTC at reportfraud.ftc.gov in the US, and in the UK to Action Fraud, with bank impersonation also going to your bank fraud line. Elsewhere the route differs: Germany, for example, routes such complaints through the telecoms regulator rather than a short code.
- Is it dangerous to just open a spam text?
- No. Reading a text message does not infect anything by itself, because an SMS carries text rather than executable code. The risk lies in what follows: tapping the link, entering data, installing a file you are offered, or calling the number in the message. Replying is still a bad idea, since even a short refusal confirms that a real person reads that number.
- How do I block scam texts?
- On Android, open the conversation menu in your messaging app and choose to block and report spam. On iOS, use the context menu on the message to report junk and block the sender. Both work against that one sender. Because criminals rotate numbers constantly, blocking is housekeeping rather than protection. Carrier level filtering catches more, and it happens before the message reaches you.
- How did they get my number?
- Rarely from a single source. Numbers surface in breaches of online services, in competition entries and signup forms, through data brokers, and very often through nothing more than counting up through a block of numbers. That is why lines that appear nowhere public still receive these messages, and why a scam text tells you nothing about whether your phone or your accounts have been compromised.