Smishing
Smishing: Fraud by Text Message
Smishing is phishing sent by text message or chat app, using short links and urgency to push you into acting from your phone.
Overview
What is it
Smishing is a deception delivered by SMS or a messaging app. Because people trust text messages and read them quickly, criminals use them to impersonate banks, delivery companies, tax authorities, and even family members. The message usually contains a short link or a phone number and asks you to confirm a payment, reschedule a delivery, or claim a refund. The small screen hides the real web address, making a fake page harder to spot.
Entry point
How does it usually begin
Smishing reaches you through your phone number. Messages may appear in a thread that looks like it comes from a real organisation, or arrive from a short code or an ordinary mobile number. Some are sent to many numbers at once, while others follow a data leak and mention a service you genuinely use.
Psychology
The psychological play
Text messages feel personal and immediate, and they interrupt whatever you are doing. Criminals combine that intimacy with a small, believable ask, such as a tiny redelivery fee, so complying seems easier than checking.
Warning signs
What to watch for
- A message asks you to click a link to pay a small fee or claim a refund.
- The sender is a random mobile number or an unfamiliar short code.
- The link uses a shortened or misspelled address.
- You are told to reply with personal or banking details.
- The message pressures you to act within a short time window.
- The wording is slightly off, or the message arrives outside normal hours.
Victim perspective
What the victim usually sees
Your phone buzzes with a message that looks like a delivery or bank alert. It contains a link and a request to act quickly. Tapping it opens a page that looks official and asks for card or login details.
Anatomy
The anatomy of the deception
- 01
Contact
A text message lands in a thread that looks familiar.
Defender move
Slow down and read the sender details before tapping anything.
- 02
Trust
The message copies the wording of a real service.
Defender move
Check the claim using the organisation's own app or website.
- 03
Pressure
You are told a parcel will be returned or an account suspended.
Defender move
Recognise the countdown as a manipulation tactic.
- 04
Request
The message asks you to tap a link and confirm details.
Defender move
Do not use the link; find the service yourself.
- 05
Payment or Information
You enter card or login details on the mobile page.
Defender move
Remember that a delivery fee is never paid through a random link.
- 06
Consequence
Your card is charged or your account is accessed.
Defender move
Contact your bank, change passwords, and report the message.
Verification
What to verify
- 1Open the organisation's official app and check for any real notification.
- 2Type the organisation's web address yourself rather than tapping the link.
- 3Look up the official customer service number independently.
- 4Ask a trusted person to read the message before you act.
Protection
How to protect yourself
- Report and delete suspicious texts instead of replying STOP.
- Never enter card details after following a link in a text message.
- Turn on your phone's filtering for unknown senders where available.
- Keep your number private where you can, and be wary of messages that use your name.
If it happened
If you already responded
Act quickly, and don't blame yourself.
- 1Do not tap any further links in the thread.
- 2If you entered card details, call your bank using the number on your card.
- 3If you entered login details, change that password immediately.
- 4Forward the message to your national reporting service and then delete it.
Examples
Real-world examples
Typical smishing includes fake parcel fees, fake bank fraud alerts, fake tax refunds, fake toll charges, and messages pretending to be from a family member who has changed number.
Sources
Where this comes from
Claims are labelled by verification status. Treat reported, alleged and unresolved claims as exactly that.
- Verified factGOVERNMENT
Guidance on phishing and social engineering
UK National Cyber Security Centre (NCSC) · 10 Jun 2024
View source - Verified factGOVERNMENT
Consumer advice on recognising and reporting scams
United States Federal Trade Commission (FTC) · 15 May 2024
View source
Spotted this pattern? Help others by reporting it.