Phishing by text: how SMS scams work and how to spot them
The text says your package couldn't be delivered. Or there's unusual activity on your bank account. Or you're owed a tax refund. There's a link to tap. The message feels urgent, and it's designed to.
SMS scams — sometimes called smishing — follow exactly the same playbook as email phishing. The goal is identical: get you to click a link that leads to a fake site, enter credentials, or hand over personal information. What makes the text version effective is that it arrives through a channel with no spam filter, no preview of the sender's actual domain, and a strong cultural expectation of quick responses.
How it works
The attacker sends a text impersonating a recognizable organization — a delivery carrier, your bank, a government agency. The message is short, which makes it easier to look plausible. It includes a link, usually shortened (bit.ly or similar), so you can't see where it actually goes before you tap.
If you tap and land on the fake site, it looks like the real one. If you enter your credentials, the attacker captures them. If it's a bank-themed scam, there may be a fake "verify your identity" form designed to capture enough information to take over your account.
The sender number is not a reliable indicator of legitimacy. Phone numbers can be spoofed, and some attacks even appear in existing message threads with your real bank — because both messages came to the same number, they thread together in your SMS app.
The most common formats
Knowing what these look like helps you recognize them:
Delivery notifications. "Your package couldn't be delivered. Click to reschedule or it will be returned." These are particularly effective because people are often expecting deliveries. The link goes to a fake carrier page, sometimes with a small "customs fee" to pay — which captures your card number.
Bank alerts. "Unusual activity detected on your account. Verify your identity here." Real banks do send fraud alerts by text, which makes this one harder to dismiss. The tell: the link doesn't go to the bank's actual domain, and real alerts ask you to call the number on your card, not log in through a link.
Government texts. Tax refund notices, benefit payment alerts, or "you owe a fine" messages. Government agencies in most countries will not contact you for the first time about money owed or owed to you via text with a link.
What actually helps
The one habit that handles most of this: don't tap links in unsolicited texts. If a message says there's an issue with your delivery, your bank account, or your taxes, go directly to the relevant site or app. Open your browser, type the address you know, sign in, and check. A real problem will be visible there.
This sounds obvious but is genuinely the right instinct. Both a real bank alert and a fake one can look identical in a text message. The only thing that reliably separates them is whether the destination is the bank's actual site — which you can only know by going there yourself.
A few more specific things to watch for:
If the link is shortened, the destination is hidden before you tap. That's a reason for extra skepticism, not necessarily proof of a scam — but combined with urgency and an unsolicited message, it's a meaningful signal.
If the text asks you to call a number rather than tap a link, verify the number independently. The number in the text can be fake. Look up the company's contact number on their official website.
If you're not expecting a package, be especially cautious about delivery texts. Check your email for a tracking number from an actual order, then go to the carrier's site directly with that number.
Reporting
Most carriers offer a way to report suspicious texts. In the US, you can forward smishing texts to 7726 (SPAM), which reports them to your carrier for analysis. This doesn't require any special setup and takes about ten seconds.
The short version
SMS scams rely on urgency, impersonation, and the assumption you'll tap without thinking. The defense is the same as with any phishing: pause, skip the link, and verify through a channel you already trust. Text messages can't prove who sent them — which is exactly why you shouldn't act on them before checking elsewhere.