Smishing: How to Spot Text Message Scams
Smishing is phishing delivered by SMS or text message. Because texts feel personal and urgent, and we tap links on our phones without thinking, smishing works well. The tricks are predictable once you know them.
Common text scams
Most smishing falls into a few buckets:
- Delivery scams: "Your package is held, pay a small fee / confirm your address."
- Bank or payment alerts: "Suspicious transaction, tap to verify" leading to a fake login.
- Toll or fine notices: a fake unpaid-toll or ticket demanding immediate payment.
- The "wrong number" or friendly chat that slowly turns into an investment or romance scam.
- Fake messages from your "boss" asking you to buy gift cards.
Red flags in a text
Watch for these signals:
- A link in an unexpected text, especially a shortened or odd-looking URL.
- Urgency, threats, or a small fee to "release" something.
- A sender you do not recognize, or a number that is not the company’s real one.
- Requests for passwords, codes, or payment.
What to do
Keep it simple:
- Do not tap links in unexpected texts, go to the app or website directly.
- Never share one-time codes, even if asked by "support".
- Do not reply "STOP" to obvious scams, it confirms your number is active; just delete and block.
- Report smishing to your carrier (forward to 7726 in many countries) and your IT team.
Real scam texts, annotated
Illustrative training examples. The tells repeat: look-alike links, urgency, and requests a real company would never send by text.
Example 1: fake delivery text
- The link is not the real domain. The real site is usps.com. Scammers register look-alikes such as usps-redelivery-support.com. Press and hold a link to preview it, and when in doubt, check tracking in the carrier’s own app or website instead.
- A random number and a countdown. Real delivery updates come from the retailer’s app or a consistent short code, and no carrier gives you a 12-hour deadline to fix an address.
- You were not expecting it. If you have not ordered anything, or your real tracking shows no problem, the "hold" is invented. Never resolve a package issue through a link in a text.
Example 2: fake bank fraud alert
- The callback number belongs to the scammer. There is no link to spot here; the trap is the phone number. Whoever answers will "verify" you by asking for your card number, PIN, or a one-time code. Call the number on the back of your card instead, never the one in the text.
- Fear does the work. A specific dollar amount and "immediately" are designed to make you skip thinking. Real fraud alerts let you confirm or deny in the bank’s own app.
- Banks never ask for PINs or codes. No legitimate bank will ever ask you to read out a one-time code or your PIN on a call. That request alone ends the conversation.
Example 3: the "wrong number" opener
- A friendly stranger is a script. You never met "Amy". If you reply, even just to say wrong number, a warm and patient conversation begins that pivots weeks later to crypto "investment opportunities" or romance. Investigators call this long game pig butchering.
- Replying marks your number as live. Any response tells the operator a real person reads this number, which moves you up the target list and invites more scams. Do not engage, just delete and block.
Test yourself
Practice spotting smishing with a free quiz.
Frequently asked questions
How did scammers get my phone number?
Often from data breaches, leaked marketing lists, or simply random number generation. Receiving smishing does not mean you were specifically targeted, but you should still never tap the links.
Is it dangerous just to open a scam text?
Reading the text is generally safe. The danger is tapping the link or replying. Do neither, and delete it.
What is the "wrong number" text scam?
A stranger texts as if they reached the wrong number, then strikes up a friendly conversation that gradually pivots to crypto "investment" tips or romance. It is a long-game scam, do not engage.