Smishing is phishing delivered by SMS or another text-messaging service. A criminal pretends to be a bank, delivery company, government agency, retailer, or person you know and tries to make you click, call, reply, pay, or disclose information. The scam usually causes harm after the recipient follows the message’s instructions.

How does smishing work?

A smishing message supplies a believable reason to act before checking the story. It may claim that a package needs a small delivery fee, a bank stopped a purchase, a toll remains unpaid, reward points will expire, or an account will be closed. The sender then directs the recipient to a website, phone number, or conversation controlled by the scammer.

The next step may ask for a password, card number, Social Security number, one-time code, payment, or software installation. A page can also collect information in stages so that each request appears routine.

The FTC advises people not to click or respond to unexpected texts and to contact the named company using a website or number they already know is real. Accurate details in a text do not establish its origin. Names, addresses, order information, and partial account data may come from public records or a previous data breach.

Common smishing messages in the United States

  • A bank fraud alert asks you to reply or call about an unfamiliar purchase.
  • A USPS or delivery notice claims that an address problem requires a small fee.
  • An unpaid toll or traffic notice threatens a penalty.
  • A retailer offers a gift or says reward points are about to expire.
  • A government impersonator warns about taxes, benefits, or a Social Security number.
  • A recruiter offers remote work and asks for information or an advance payment.
  • A known contact appears to send an urgent request from a new number.

Scammers adapt their stories to current events and consumer habits. Focus on what the message asks you to do and where it sends you.

Signs that a text may be a scam

Treat an unexpected text as unverified when it combines urgency with a request for money, credentials, or a click. Other warning signs include:

  • a shortened link or domain that does not belong to the named organization;
  • a demand to pay by gift card, cryptocurrency, wire transfer, or payment app;
  • a request for a password, PIN, or multifactor authentication code;
  • a threat of arrest, account closure, loss of benefits, or a large late fee;
  • a request to move the conversation to a different app;
  • a sender who discourages you from contacting the organization directly;
  • a page that asks to install an app, configuration profile, or remote-access tool.

Spelling and design are weak tests. Scammers can copy logos and write polished messages. The reliable check is whether the claim also appears in the official account you reach independently.

Smishing, phishing, and vishing

Phishing is the broader use of impersonation to steal information, access, or money. Smishing names the text-message channel. Vishing uses a call or voice message.

One attack can use all three. A text may provide a phone number, a caller may send a link, and the linked page may imitate a legitimate sign-in screen. The response should address every action taken, not only the first message.

What to do with a suspicious text

Do not click, reply, or call the number in the message. Open the company’s official app, type a known web address, or use a phone number printed on a statement or payment card. If the alert is real, the official account should provide a way to review it.

Use your phone’s report-junk feature and forward scam texts to 7726 (SPAM) when supported by your carrier. Report fraud at ReportFraud.ftc.gov. Preserve screenshots first if the message relates to a loss or account takeover.

A URL Checker can analyze a copied address for known technical risk. It cannot confirm that a debt, delivery, sender, or offer is real.

What to do if you clicked or replied

Match the response to what happened:

  • If you opened a page, close it and do not accept downloads, notifications, or permissions. Update the device and security software.
  • If you entered a password, change it through the real service, change every account that reused it, end unfamiliar sessions, and turn on two-factor authentication.
  • If you shared a code, contact the account provider and review recovery information and connected devices.
  • If you entered card or bank data, contact the financial institution using an official number and monitor transactions.
  • If you provided a Social Security number, follow the steps for an exposed Social Security number.
  • If you installed an app, remove unrecognized software and permissions, run a trusted security scan, and review sensitive accounts from another device you trust.
  • If you sent money, contact the payment company and financial institution immediately. Recovery is not guaranteed, but prompt reporting can preserve options.

For a complete decision path, see what to do if you clicked a fake link.

PSafe’s analysis of smishing

Text messages provide little context, which makes independent verification more important. A useful review separates three questions:

  1. Does the claimed event appear in the official app or account?
  2. Does the domain or phone number belong to the organization?
  3. Is the requested action appropriate for the event?

A clean link result answers none of those questions by itself. Treat the text as a notification that still needs confirmation through a channel you choose.

Frequently asked questions about smishing

Can a legitimate company send links by text?

Yes. The presence of a link does not prove either legitimacy or fraud. For an unexpected or sensitive request, bypass the link and use the official app or a known address.

Should I reply STOP to a suspicious message?

Use STOP for marketing texts from a sender you recognize. Do not reply to an apparent scam, because the response can confirm that your number is active. Block and report it instead.

Can reading a text infect my phone?

Merely viewing a normal text is generally lower risk than opening its link, downloading a file, installing an app, or granting permission. Keep the phone and messaging app updated because software vulnerabilities can change that risk.

Can caller ID or a short code be spoofed?

Sender information can be manipulated, and messages can appear in an existing conversation thread. Verify the request independently even when the sender name looks familiar.

Does dfndr security prove that a text is genuine?

No. Security tools can identify some malicious destinations or software. They cannot validate the sender’s identity or the story used to request an action.