Smishing: How Text Message Scams Work and How to Spot Them

Smishing is phishing by text message. Why the trick fails in your inbox but works on your phone, how to read a scam text in seconds, and where to report one.

A smartphone lies face up with a blank dark screen while a single small fishing hook hangs above it on an almost invisible line, catching a warm highlight

The message arrives on a Tuesday afternoon, in the middle of everything else. Two lines, a courier, an unpaid customs fee of a couple of pounds, and a link. You did order something recently, and for that amount you are not going to start an argument. That is exactly what the message was built on. It is called smishing, a blend of SMS and phishing, and it is an attempt to extract login details, card numbers or an installed app from you through a text message.

This piece starts with why text messages work so well for this, given that email phishing is now filtered out fairly reliably. The bulk of it is practical: the signals that give a scam text away, and a calm sequence of steps for the case where you already tapped. Reporting comes at the end, and it is worth reading even if you think you know the short code.

What smishing is

Smishing is phishing delivered over messaging. The aim matches the familiar phishing email: get you onto a rebuilt copy of a real site and have you type in whatever is worth stealing. Online banking credentials, a card number with the security code, sometimes just a name and address that can be resold. A second variant asks you to install an app, usually presented as a parcel tracker.

The word has stretched a little past its own components. Messages over WhatsApp or RCS get the same label, because nothing about the technique changes with the transport. Text phishing, SMS phishing and scam text all describe the same object from different angles.

Why text messages work so well

Email phishing has become harder work. Large providers check SPF, DKIM and DMARC to establish whether a message could plausibly have come from the domain in the sender field, and what fails that check lands in spam or never arrives at all. Text messaging has no equivalent layer in general use. Carriers do run filters that catch part of the traffic, and they catch a great deal of it, but there is no cross network proof of sender identity in the way email now has one.

Then there is attention. A text arrives directly in the lock screen notification, and it sits in the same list as the dentist reminder and the one time code from your bank. You will find claims that ninety eight percent of text messages get opened, and those numbers trace back to marketing material from SMS campaign vendors rather than to independent measurement. The everyday observation holds without the false precision: texts get read faster and questioned less than email, because for years this channel carried mostly genuine senders.

Format matters too. Nobody writes elaborately in a hundred and sixty characters, so a blunt instruction reads as perfectly normal there. The tells that give away a fraudulent email are simply absent: no badly rebuilt letterhead, no signature block, no visible sender address. What remains is one sentence and a link, and links are almost always displayed truncated on a phone.

That leaves the sender label. A text can display a name instead of a number, an alphanumeric sender ID, introduced so companies could appear under their own brand. That field is a claim made by the sender and nothing more. When a forged message arrives under the same name as previous real ones, many phones file it into the same conversation thread, lending the fake the credibility of everything above it. How that forgery works in detail is covered in our piece on spoofing.

How to read a scam text

Individual signals are weak on their own, since genuine messages are also short and also contain links. Taken together they resolve into something fairly clear.

A plain dark envelope lies closed on a stone surface with a thin taut wire running out from beneath its edge and disappearing into shadow
The envelope is the visible part. The wire underneath is the point.
  • It arrives unexpectedly. No parcel pending, no refund requested, no registration started. This is the strongest single signal and the easiest to miss, because almost everyone has ordered something recently.
  • It pushes. A twelve hour deadline, a bailiff in two days, an account about to be suspended. Urgency is not a side effect here, it is the active ingredient, because it shortens the pause in which you would think.
  • The address does not match the sender. A bank message pointing at a domain where the bank name appears somewhere in the middle but is not the actual domain. Shortened URLs, endings like .info, .xyz or .cc, hyphens stitching a known brand onto an extra word.
  • The number is odd. An international prefix for a domestic bank, or an ordinary mobile number for something claiming to be a government office.
  • The greeting is empty. No name, no customer reference, but a case number or an amount you cannot account for.
  • It concerns money, access or an installation. Payment, verification, data confirmation, app download. Messages of this kind have no other purpose.

Two examples, with the links removed, in the shape they actually arrive:

Your parcel is being held at our sorting facility. An outstanding customs fee must be paid to continue delivery: [link]

Your banking app registration expires in 12 hours. Renew here: [link]

No spelling mistakes, no threats, and that is precisely why they work. The old rule about clumsy grammar stopped being useful some years ago, because translation tools got good. What remains is the comparison with your own memory. Customs fees are not collected through a link in a text message, a bank does not announce a twelve hour deadline for reactivating your app, and tax authorities do not send text messages about assessments.

The recurring scripts

The stories rotate, the frame stays put. Five variants cover most of what actually lands.

ScriptTypical contentWhere it falls apart
Parcel and customsDelivery held, small fee due, link to payCouriers do not collect fees through a link in a text, real duties go through the carrier or the customs office
Bank and accountApp registration expiring, account frozen, verification neededBanks never ask you to sign in through a link inside a message
VoicemailA new voice message, retrievable via link or appYour voicemail is reached through your own carrier short code, never a download
Authority and debt collectionSeizure of goods, fine, tax refund, two day deadlinePublic authorities send letters, and tax offices do not text about assessments
Prize and refundYou have won, a balance is waiting, a refund is pendingA prize that requires your data or a fee up front is not a prize
A small plain parcel stands alone on the floor of a large dim room casting a shadow far too long for its size in warm raking light
The parcel is small. The shadow does the work.

The parcel script is the classic, and it has a history worth knowing. FluBot malware spread through exactly these messages from 2020 onwards: tapping the link produced an offer to install a supposed tracking app, which read the address book after installation and used it to send the next wave. In May 2022 Dutch police took over the infrastructure in an operation coordinated by Europol across eleven countries, and FluBot itself was finished. The distribution idea, slipping an app in behind a delivery notice, outlived it.

A special case is the message from a supposed child: “Hi Mum, this is my new number, message me on WhatsApp.” It often starts as a text and moves into a messenger, where instead of a link comes a request for a quick transfer. Calling back on the old, saved number resolves it in under a minute. The same pattern delivered by voice rather than text is covered in our article on spam calls.

What to do if you already tapped

The reassuring part first, because it applies in nearly every case: an opened link is not yet damage. A web page cannot take over your phone in passing, and a text message carries text rather than executable code. What the fraud needs is your participation, and you can withhold that at any stage.

A single hand hovers with an extended fingertip a few centimetres above a dark blank glass surface which reflects the finger back as a soft mirrored shape
Between tapping and typing lies the whole difference.

If you only opened the page. Close it. Enter nothing, not even the apparently harmless postcode. Download nothing. Delete the message afterwards and keep an eye on your account for a few days. Nothing further is required here, and a virus scan achieves nothing either, because nothing was installed.

If you entered data. Act at once, but in order. Change the password for the affected service through the official app or an address you typed yourself, never through a link. If you reuse that password anywhere, change it there too. Where banking details were involved, call your bank on the number printed on the back of your card, and ask them to freeze the card. Then check your recent transactions and dispute anything you did not authorise.

If you installed an app. This is the serious case, and in practice it concerns Android devices, because installing from a source outside the Play Store is technically possible there. On iOS the route runs through the App Store, so this variant barely occurs. Take the device off the network, uninstall the app, then check in settings whether it was granted device administrator or accessibility permissions and revoke those first. Change your passwords from a different device. If doubt remains, a factory reset is the clean answer.

If money moved. Call the bank and report it to the police or the relevant fraud reporting service. Keep everything: the message, the sender number, the statements, screenshots. Transfers can occasionally still be stopped within the first hours.

What you do not do under any circumstances: reply to the message, call the number it gives you, or try to take the matter on yourself. A reply confirms to the sender that a reachable human sits behind that number, and your number becomes worth more the moment it does. If you suspect more has happened than a single message, the checks are laid out in has my phone been hacked.

Reporting and staying out of the way

In the United States and the United Kingdom the route is well established: forward the message to 7726, which spells SPAM on a keypad. The major carriers on both sides of the Atlantic accept it, forwarding is free of charge, and the report feeds the network level filters that stop the next wave earlier. Beyond that, the FTC takes fraud reports at reportfraud.ftc.gov, the FCC handles unwanted messaging complaints, and in the UK Action Fraud is the national reporting point.

A short length of fine chain lies on a dark desk with the nearest links lit by a warm lamp while the far end runs off the edge and disappears into black
One report rarely travels far. Many reports become a pattern.

Worth knowing if you travel or read advice across borders: 7726 is not universal. In Germany it depends on the individual carrier, and complaints about scam texts go to the telecoms regulator instead, an entirely different process. Advice written for one country transfers badly here, which is one reason the German version of this article names a different route.

On the phone itself there is the smaller remedy. Android lets you block the sender and report the conversation as spam in a single step from the conversation menu. iOS offers the equivalent through the context menu on the message, and on some carriers a dedicated reporting entry that passes the message on with its timestamp and sender number intact. Convenient and correct, but it does not solve anything: the other side rotates sender numbers by the hour. Blocking is housekeeping, not protection.

The habits that actually hold

Four rules cover ordinary life, and they work regardless of how convincing a message looks.

SituationWhat you do instead
Text from an unknown number containing a linkIgnore the link, open the provider through your own app or an address you typed yourself
Supposed parcel trackingTake the tracking number from your order confirmation and enter it on the courier site
A prompt to install an appSearch the official store only, never follow a link from a message
A message from a relative’s new numberCall back on the old, saved number

On top of that sits the rule that makes the others unnecessary when it is kept: a one time code, a password and card details never belong in a form you reached through a link in a message. No legitimate provider needs that, and no genuine process collapses because you signed in yourself instead.

Guarding your number helps less than people hope. Number ranges get counted through mechanically, which is why lines that appear in no directory still receive these messages. A scam text is therefore no indication that anything is wrong with your device.

What it comes down to

Smishing is technically unambitious. It survives because a text gets read on a phone in a moment when something else is going on, and because a small customs fee looks too trivial to question. Filters catch a fair amount now, though not all of it, and no general proof of sender identity exists for text messages.

That leaves one rule worth carrying. A message that presses you while offering a convenient way out is not information, it is an instruction. Do not take the route it offers. Take the one you already know: your own app, an address you typed, the number on the back of your card. It costs a minute, and it is the only protection that keeps working against every new version of this trick.

Frequently asked questions

What is smishing?
Smishing is phishing carried out over text messages. Criminals send an SMS that appears to come from a bank, a courier, a tax office or a family member, and the goal is to push you onto a fake website. There you are asked to type in login details, card numbers or personal information, and sometimes to install an app. The message itself does no damage. It is only the bait.
What does the word smishing mean?
It is a blend of SMS and phishing, naming the delivery channel and the fraud in one word. In practice the term now covers any phishing attempt sent through messaging, including WhatsApp and RCS, because the technique does not change with the transport. You will also see the same thing called text phishing, SMS phishing or simply a scam text.
How do I recognise a scam text?
Look for three things together: the message arrives unexpectedly, it applies time pressure, and it wants you to tap something. Add shortened or oddly assembled web addresses, a sender number from abroad or a company name in place of a number, a greeting with no name in it, and an amount or reference number you cannot place. The most reliable test is your own memory. Did you actually order, apply for or expect anything?
What happens if I clicked the link in a scam text?
Usually nothing beyond a page opening. The damage comes from the second step: typing data in, or installing an app the page offers you. If you only looked and closed it, close the tab, delete the message and watch your account for a few days. If you entered login or payment details, change that password immediately from the official app and call your bank.
Where do I report a scam text?
In the United States and the United Kingdom you can forward the message to the short code 7726, which spells SPAM on a keypad and is carried by the major networks free of charge. Beyond that, report to the FTC at reportfraud.ftc.gov in the US, and in the UK to Action Fraud, with bank impersonation also going to your bank fraud line. Elsewhere the route differs: Germany, for example, routes such complaints through the telecoms regulator rather than a short code.
Is it dangerous to just open a spam text?
No. Reading a text message does not infect anything by itself, because an SMS carries text rather than executable code. The risk lies in what follows: tapping the link, entering data, installing a file you are offered, or calling the number in the message. Replying is still a bad idea, since even a short refusal confirms that a real person reads that number.
How do I block scam texts?
On Android, open the conversation menu in your messaging app and choose to block and report spam. On iOS, use the context menu on the message to report junk and block the sender. Both work against that one sender. Because criminals rotate numbers constantly, blocking is housekeeping rather than protection. Carrier level filtering catches more, and it happens before the message reaches you.
How did they get my number?
Rarely from a single source. Numbers surface in breaches of online services, in competition entries and signup forms, through data brokers, and very often through nothing more than counting up through a block of numbers. That is why lines that appear nowhere public still receive these messages, and why a scam text tells you nothing about whether your phone or your accounts have been compromised.