Smishing: How to Recognize a Fake SMS
Smishing: How to Recognize a Fake SMS
Phishing by text message has a name: smishing (SMS + phishing). It works even better than email, because a text feels personal and urgent, and phone screens hide the tell-tale signs a computer would show. If you've ever gotten a "your package is on hold" or "unusual login on your account" text, you've already been targeted. Here's how to read one correctly.
The messages you'll actually get
Almost every smishing text is a variation on a handful of scripts:
- Delivery on hold. "Your parcel couldn't be delivered. Pay a small fee / update your address here."
- Bank alert. "Suspicious transaction detected. Verify now or your account will be locked."
- You won something. "Congratulations! Claim your prize / reward points before they expire."
- Wrong number that turns friendly. A stranger texts "Hi, is this Anna?" and, once you reply, slowly builds rapport — the opening move of a longer investment or romance scam.
- The boss / authority. "This is your manager, I need a quick favor," or a text posing as the tax office or police.
- Verification-code request. "Reply with the code we just sent to confirm it's you." (It's your code — they're trying to take over your account.)
Red flags in a text message
- Urgency and threats: a deadline, a lock, a fine, a "final notice."
- A link you weren't expecting — especially a shortened one, or a look-alike domain (read it right to left to find the real owner).
- A request for a code, PIN, password, or card details. No legitimate company asks for these by text.
- An unknown sender claiming to be a big brand, or a number that doesn't match the company's official one.
- Odd language — awkward grammar, generic "Dear Customer," or a name that isn't yours.
- An offer too good to be true. It is.
What to do with a suspicious text
- Don't tap the link. If you want to check the claim, go to the company's official app or type its address yourself.
- Never reply — not even "STOP." A reply tells them the number is live.
- Never share a code. A code sent to you is meant only for you to type into the real app, never to send to anyone.
- Verify by a separate channel. Call your bank on the number on your card; confirm a "boss" request by a call or in person.
- Report and delete. Report as junk/spam in your messaging app, then delete it.
Once you've clicked a link from a text, the rules are the same as any fake site — here's the exact check: Is This Link Safe? A Step-by-Step Check. And the bank/delivery texts almost always lead to the scams broken down here: Fake Bank & Shipping Websites: How the Scam Works.
The one habit that beats smishing
You don't have to judge every message perfectly. Just adopt a single rule: a text can tell you something happened, but never act inside the text. Go to the real app or site on your own to check. Do that, and it doesn't matter how convincing the message is.
Want to work on the other side of these attacks?
Social engineering and phishing are entire domains in the security exams. If defending people and systems appeals to you, CompTIA Security+ is the common starting point. See the exam-prep paths on CertInstructor →
Written by the team at Security365 / CertInstructor — 20+ years training cybersecurity professionals, holders of the full CompTIA security certification stack, and recipients of the EC-Council Instructor Circle of Excellence Award (two years running).
Comments
Post a Comment