Skip to content

Scam Types

What is smishing? How to spot scam texts and stop them

Smishing is phishing by text message — scammers send SMS or messaging-app texts pretending to be from a trusted source like your bank, a delivery company, or a government agency. The text uses urgency or fear to push you to click a link, reply, or share personal information. If a text you didn’t expect is asking you to act fast, treat it as smishing until proven otherwise.

Last reviewed: May 10, 2026  ·  Drafted with AI assistance. Reviewed and edited by a human editor before publication.

01

What is smishing? (Definition)

Smishing is a form of social engineering that uses SMS or mobile messaging apps to deceive victims. The term is a combination of “SMS” and “phishing,” reflecting how traditional email scams have migrated to mobile devices.

In 2025 and 2026, text messages became the most common initial contact method for consumer fraud. Scammers favor this channel because it feels more personal and immediate than email. While email filters have become highly effective at blocking traditional phishing, SMS remains a less-regulated space where users are statistically more likely to engage with incoming messages.

02

How do you spot a smishing text? (Warning signs)

As of 2026, scammers update their tactics frequently to bypass mobile security filters, but most scam texts rely on a few consistent indicators. Recognition is critical because SMS open rates in 2025–2026 remain as high as 98%, with 90% of messages being read within three minutes.

  1. Shortened or suspicious URLs — Links that use services like bit.ly or tinyurl.com to hide the final destination, or domains that look like a brand name but have slight misspellings.
  2. Sender numbers that don’t match — A text from “your bank” or “USPS” that comes from a standard 10-digit mobile number or an international area code.
  3. Extreme urgency or fear — Claims that your account is locked, a package is about to be returned, or that legal action is imminent.
  4. Unexpected “Track Package” links — Texts regarding delivery issues for items you did not order or from companies you haven’t used recently.
  5. Requests to “Reply” to stop messages — Instructions to text a word like “STOP” or “NO,” which scammers use to confirm your number is active.
  6. Unusual greetings — Texts that address you as “Customer” or “User” instead of your name, though personalization is becoming more common due to AI.
  7. Claims of government refunds or debts — Unsolicited alerts about tax rebates or unpaid fines from agencies like the IRS, HMRC, or ATO. The FTC notes that government agencies do not initiate contact via text to request sensitive information.

Key Takeaway

The most reliable smishing signal is simple: did you expect this text? If a text from any sender — even one that looks like your bank — surprises you, treat it as smishing until you’ve verified through an official channel.

03

What does smishing actually look like? (Real examples)

Example

These examples are paraphrased from real smishing messages reported in 2025 and 2026. The exact wording changes constantly — the pattern matters more than the specific script.

Scenario 1: The fake delivery alert

The message: “USPS: Your package has been put on hold due to a missing house number. Please update your address here: [Malicious Link]”

What makes it smishing: This uses a “low-friction” request to trick you into entering address and credit card details. In the UK, fake parcel delivery texts accounted for 53–67% of smishing attempts in mid-2025.

Scenario 2: The bank security alert

The message: “[Bank Name] Security: A new device logged into your account from [City]. If this was not you, please secure your account immediately: [Malicious Link]”

What makes it smishing: This creates a high-stress “fight or flight” response. The link leads to a fake login portal designed to steal your username, password, and one-time security codes.

Scenario 3: The fake tax refund

The message: “HMRC: You are eligible for a tax rebate of £240.15. To claim your refund, please fill out the form at [Malicious Link]”

What makes it smishing: It uses the promise of “free money” to lower your guard. Official tax agencies like HMRC, the IRS, and the ATO do not send text messages to process refunds.

04

Why are smishing scams so common in 2026?

As of 2026, scammers have shifted toward SMS because it exploits mobile-first behavior and the high trust users place in their text inboxes. While email open rates hover around 20%, SMS open rates reach 98%, making it a far more “efficient” channel for criminals.

Furthermore, mobile screens often obscure the full URL of a link and the verified sender details, making it easier for attackers to hide malicious domains. As of late 2025, the Anti-Phishing Working Group observed that smishing volumes continued to rise even as overall URL-based email phishing saw slight quarterly declines. Scammers are following user attention; as people move more of their lives to mobile devices, the fraud follows.

Definition

“Smishing” combines SMS + phishing. The term has been used since the early 2000s but smishing volume has surged in the 2020s as email filters improved and mobile usage grew.

05

What should you do if you receive a smishing text?

Warning

Do not reply, even with “STOP” or “NO.” Replying tells scammers your number is active and increases future targeting. Forward the message, then delete it.

  1. Do not reply. Replying confirms your number is active and leads to more scams.
  2. Do not click. Links in smishing texts are designed to steal data or install malware.
  3. Forward and report. Reporting helps carriers block the scammer’s number.
  4. Delete the text. Once reported, remove it from your phone so you don’t click it by accident later.

Where to report smishing

  • United States: Copy and forward the text to 7726 (which spells SPAM). This helps your wireless provider spot and block similar messages.
  • United Kingdom: Forward the text to 7726. This service is free on all major UK networks and is used by the NCSC to take down malicious websites.
  • Australia: Report scam texts to ACCC Scamwatch. You can also report cybercrime incidents through ReportCyber.
06

What if you already clicked or replied?

If you tapped a link in a suspicious text or replied to a message you now think was smishing, act quickly. Please follow our step-by-step recovery guides for instructions on securing your accounts and checking for malware.

07

How can you protect yourself from smishing in the future?

  • Never click links from unknown senders. If you receive an unexpected text from a business, visit their official website directly through your browser instead of using the link provided.
  • Use carrier spam filters. Most major mobile carriers in 2025–2026 offer built-in tools to identify and filter suspected spam texts.
  • Set up Two-Factor Authentication (2FA). Use an authenticator app or hardware key so that even if a scammer steals your password via a fake text, they cannot access your account.
08

Sources

  • FTC 2025 Fraud Loss Report — freep.com. Accessed May 2026. Cited for 2025 record fraud losses and contact methods.
  • APWG Phishing Activity Trends Report Q4 2025 — apwg.org. Accessed May 2026. Cited for rising smishing volume trends in 2025.
  • UK Finance Smishing Statistics 2025–26 — ukfinance.org.uk. Accessed May 2026. Cited for UK parcel and delivery scam data.
  • NCSC Reporting Guidance — ncsc.gov.uk. Accessed May 2026. Cited for UK 7726 reporting and takedown outcomes.
  • FTC Smishing and Spam Text Guidance — consumer.ftc.gov. Accessed May 2026. Cited for US warning signs and 7726 reporting.