Smishing is phishing delivered by SMS or another text-messaging service. The sender impersonates a bank, delivery company, government agency, employer, retailer, or known person and asks the recipient to click, call, reply, pay, or disclose information. For message examples, warning signs, and incident response, see What is smishing?.
Common smishing messages
Fake bank alerts, package problems, unpaid tolls, expiring reward points, job offers, and security warnings are common stories. The message may link to a copied page or provide a phone number for a false representative.
The scam is defined by the text-message channel, not by one script. A campaign can begin by text and continue through a call or website.
Signs of smishing
Look for an unexpected request, urgency, a domain that does not belong to the named organization, or a demand for credentials, a one-time code, an unusual payment, or app installation. Correct names and order details can come from leaked data.
What to do
Do not click or reply. Open the official account independently and check whether the event exists. Report junk through the phone and forward scam texts to 7726 (SPAM) when supported by the carrier.
If you shared information, secure the affected account or financial product. Follow the incident steps in what is smishing.
Smishing and spam are different
Spam is unsolicited messaging. Smishing is designed to deceive the recipient into giving up information, access, or money. A text can be both.