Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Smishing is phishing delivered through text messaging. A scammer impersonates a bank, delivery company, government agency, employer, friend, or another trusted source to persuade you to click, call, reply, pay, reveal information, or install software. The safest response to an unexpected text is simple: do not click, reply, call, download, pay, or use contact details supplied by the message. Verify the claim through an independently known app, website, phone number, or statement.

What does smishing mean?

The word smishing combines SMS, the traditional text-message system, with phishing, the broader practice of using deception to steal information or trigger a harmful action. The FCC describes SMS phishing, or smishing, as text messages intended to trick people into revealing personal or confidential information for criminal use.

In practice, the term also covers deceptive messages delivered through iMessage, RCS, Google Messages, messaging apps, business-texting platforms, and email-to-SMS gateways. A message does not need to contain a link to be smishing. It may instead try to make you reply, call a number, send money, provide a verification code, or continue a conversation with a scammer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Term Meaning
Spam text An unwanted or unsolicited message. It may be merely promotional or malicious.
Smishing Deceptive text-based phishing intended to steal information, money, access, or induce harmful action.
Spoofing Faking the apparent sender identity, number, name, or organization. Spoofing is often used in smishing.
Malware text A message designed to make you install or run malicious software.
Vishing Phishing carried out through a voice call.
Email phishing Phishing delivered by email.

A familiar sender name, local area code, short code, logo, or polished wording is not proof that a message is genuine. Sender identities can be spoofed, and legitimate organizations may send real alerts. The decisive test is whether the request can be verified independently.

How a smishing attack works

  1. Impersonation: The attacker claims to represent a trusted company, person, service, or institution.
  2. Pressure or curiosity: The message creates urgency, fear, excitement, or a reason to respond.
  3. Interaction: You are directed to click, call, reply, scan a QR code, pay, or install an app.
  4. Capture: A fake website or human operator collects credentials, one-time codes, payment details, identity information, or money.
  5. Follow-on fraud: The attacker may take over accounts, make unauthorized transactions, impersonate you, or continue the conversation.

Texts are effective because people use them for family, work, delivery updates, authentication, and financial alerts. Notifications are often seen quickly, and a phone can be used to log in, pay, call, or install software within seconds. The FCC notes that consumers often treat texting as a trusted communication channel.

What scammers want

  • Passwords and account access: Fake login pages may target banking, email, cloud storage, payroll, social media, retail, workplace, or cryptocurrency accounts.
  • Verification codes: A scammer may already have your password or be attempting a login and needs the one-time code to get through the next security step.
  • Payment and identity information: Requests may involve card numbers, bank details, Social Security numbers, dates of birth, driver’s-license information, insurance details, tax records, or debit-card PINs.
  • Money: Common demands include gift cards, cryptocurrency, wire transfers, payment-app transfers, fake toll payments, or deposits for supposed jobs and investments.
  • Device access: The message may request an app installation, attachment download, QR-code scan, or security-setting change.
  • A conversation: A harmless-looking reply can confirm that your number is active and begin a longer romance, investment, job, or impersonation scam.

Common smishing examples

Fake package-delivery notices

The text says your address needs confirmation, a small redelivery fee is due, customs payment is required, or a delivery preference must be updated. Fake package-delivery messages were the most commonly reported text-scam type in the FTC’s 2024 analysis. Check a tracking number only through the carrier’s official app or a website you type yourself.

Bank and fraud alerts

A message may claim that a purchase was detected, your account is locked, or your money must be moved to a “safe” account. Do not call the number in the text. Open your bank’s official app or use the number on the back of your card.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Unpaid toll or parking notices

These scams commonly combine a small amount due with a short deadline and threats of late fees, penalties, or registration problems. Verify the notice through the relevant authority’s official website, not the supplied link.

Fake jobs and task scams

A text may promise easy money for rating products, optimizing apps, liking content, or completing repetitive online tasks. The scam later demands that you deposit your own money—often cryptocurrency—to continue or withdraw supposed earnings. The FTC identifies task and job scams as a major text-scam category.

Wrong-number conversations

“Are we still meeting?” or “Is this John?” may look like an innocent mistake. The scam can develop only after you respond, eventually turning into a fake friendship, romance, investment opportunity, or request for money. The FTC has documented this pattern.

Prizes, refunds, coupons, and government or employer impersonation

The message may offer a prize, refund, debt relief, student-loan help, coupon, or low-interest credit. It then asks for a fee, sensitive information, or a login. Other campaigns imitate payroll departments, tax agencies, delivery fleets, vendors, or executives.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to recognize a smishing text

No single clue proves that a message is fraudulent. Several of these signs together should make you stop and verify:

  • You were not expecting the message.
  • It demands immediate action or threatens closure, arrest, penalties, or financial loss.
  • It asks for a password, one-time code, identity number, payment details, or money.
  • The link is shortened, misspelled, strange, or unrelated to the claimed organization.
  • It tells you to call a number included in the text.
  • It requests gift cards, cryptocurrency, wire transfers, or payment-app transfers.
  • It asks you to install software, open an attachment, scan a QR code, or change a security setting.
  • It begins as a wrong-number exchange and quickly becomes personal, financial, romantic, or investment-related.

Good grammar does not make a message safe, and a grammatical mistake is not required for a scam. A text from a short code, a contact in your address book, or an iMessage or RCS conversation is not automatically trustworthy. Rich branding, typing indicators, read receipts, and a familiar name can all create an appearance of legitimacy without proving identity.

What to do when a suspicious text arrives

  1. Stop. Do not act because the message gives you a deadline.
  2. Do not reply. For an unexpected suspicious text, even “STOP,” “wrong number,” or “Who is this?” may confirm that your number is active. Replying STOP can be appropriate when you know a legitimate business sent an expected message.
  3. Do not click links, scan QR codes, call supplied numbers, download files, or install apps.
  4. Verify independently. Open the claimed company’s official app, type its website address manually, use a saved bookmark, check a statement, or call a number obtained separately.
  5. Preserve evidence if useful. Take a screenshot before deleting the message.
  6. Report it, then delete and block it. Blocking helps, but campaigns may rotate numbers, spoof identities, or use group and email-to-text services.

How to report smishing

  • Forward the message to 7726 (SPAM). This helps participating wireless providers identify and block similar messages, but it does not guarantee that a campaign will stop.
  • Use your messaging app’s spam control. In Apple Messages, use Report Junk or the equivalent available control. In Google Messages, open the conversation menu and use the spam-reporting option described in Google’s current instructions.
  • Report fraud to the FTC at ReportFraud.ftc.gov. Reports support enforcement and consumer warnings, but do not automatically recover money or generate an individual response.
  • Report unwanted or illegal texts to the FCC through its Consumer Complaint Center. The FCC says it does not resolve individual unwanted-text complaints.
  • Notify the impersonated organization using its official website or app, especially if the message uses its brand or concerns your account.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you already interacted with the message

You clicked but entered nothing

Close the page and stop interacting. Check browser downloads and installed apps, remove anything you did not intentionally install, and update the device, browser, and security software. Watch for unusual pop-ups, redirects, permissions, battery behavior, or account activity. If the page requested a login, change the password only by opening the real service independently. A click is serious, but it does not prove that malware was installed; the outcome depends on the device, software, exploit, and what happened afterward.

You entered a username or password

  1. Change the password through the legitimate app or website.
  2. Change it anywhere else you reused it.
  3. Sign out other sessions and review trusted devices.
  4. Turn on multifactor authentication, preferably phishing-resistant MFA where available.
  5. Check recovery email addresses, phone numbers, forwarding rules, recent sign-ins, and transactions.
  6. Contact the organization through an independently verified security or fraud channel.

A password change may not invalidate a stolen session, active login, recovery method, or one-time code. The NIST phishing guidance recommends changing compromised credentials, monitoring accounts, contacting relevant financial institutions, and using MFA.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You gave away a verification code

Treat this as urgent. Open the real account directly, change the password, revoke suspicious sessions and devices, check recovery details, and contact the provider’s security team. If the code involved a possible SIM swap or phone-number takeover, contact your mobile carrier. Do not assume the code was harmless: attackers often request it because they already have—or are trying to obtain—the first factor.

You supplied card or bank information

Contact the card issuer or bank immediately using the official app, card, or statement. Ask whether the account or card should be frozen or replaced. Review pending and completed transactions, follow the institution’s dispute process, change banking credentials, and watch for follow-up impersonation calls. Do not wait for an unauthorized charge to appear.

You sent money

Contact the bank, card issuer, payment app, wire service, cryptocurrency exchange, or other payment provider immediately. Ask whether the transfer can be reversed, recalled, frozen, or disputed. Preserve receipts, wallet addresses, usernames, numbers, and messages. Report the fraud to the FTC and consider filing with the FBI’s Internet Crime Complaint Center. Anyone promising guaranteed recovery for an upfront fee may be running a second scam.

You installed an app or suspect malware

  1. Disconnect the device from sensitive accounts and networks if malicious software is suspected.
  2. Do not enter more passwords or payment information on that device.
  3. Remove the suspicious app using manufacturer guidance and run current security scans where appropriate.
  4. Update the operating system and applications.
  5. Change passwords from a known-clean device.
  6. Contact your carrier, employer’s IT team, or a qualified technician if the device remains compromised.
  7. Consider a factory reset only after preserving essential data and confirming that you can recover your accounts.

Preventing future smishing attacks

  • Use multifactor authentication, with phishing-resistant methods where supported.
  • Use a password manager so fake websites cannot easily capture passwords through reuse or improvisation.
  • Keep the operating system, browser, apps, and security tools updated.
  • Enable built-in spam filtering and review your carrier’s available controls.
  • Adopt a household rule: money, passwords, codes, and account changes are verified through a separate channel.
  • Limit publicly visible personal information that can make impersonation more convincing.
  • Teach children and older relatives to pause and ask a trusted person before acting on an unexpected message.

Smishing at work

Businesses face fake payroll alerts, executive impersonation, vendor-payment requests, customer-account notices, recruiting scams, and messages designed to steal corporate credentials. Require independent verification for payment and account-change requests, particularly when a text asks someone to bypass normal approval procedures.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Organizations should provide a simple reporting route, use phishing-resistant MFA where practical, manage company-owned phones, keep software updated, train employees about texts and calls as well as email, and maintain an incident-response process for compromised credentials or devices. If criminals impersonate the company, notify customers through an official channel without repeating clickable scam links.

What smishing is not

Not every unwanted text is smishing. Some are illegal or unwanted marketing without an attempt to steal credentials or money. Conversely, a targeted smishing message may look professional and contain no link. The defining issue is deceptive intent and the harmful action the sender is trying to induce—not the message’s spelling, branding, sender type, or visual appearance.

The FTC reported that consumers reported $470 million in losses in 2024 to scams that started with text messages—five times the reported loss in 2020. That figure covers losses reported to the FTC, not all losses, and likely understates the real harm. The FTC’s leading categories came from hand-coding a random sample of 1,000 reports, so they should not be read as a complete census of every text scam. Source: FTC 2024 text-scam data.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.