What Is Smishing? How SMS Phishing Works and How to Stop It

Smishing — a portmanteau of “SMS” and “phishing” — is phishing conducted via text message. It is one of the fastest-growing forms of fraud in the United States, fueled by the ubiquity of smartphones, the high open rates of text messages (people open 98% of texts they receive, versus around 20% of emails), and the fact that most people are less naturally suspicious of a text than an email.

The FBI has repeatedly warned about the explosive growth of smishing campaigns. In 2023, the FTC received more than 350,000 reports of text message scams, with total reported losses exceeding $330 million. And like all scam statistics, the real number is substantially higher because most smishing victims never report.

What Is Smishing?

Smishing is a phishing attack delivered via SMS text message (or, increasingly, via messaging apps like WhatsApp, iMessage, and Messenger). The attacker sends a fraudulent text impersonating a trusted entity — a bank, a government agency, a shipping company, a toll authority, a retailer — with a link or phone number designed to capture the victim’s personal information, payment details, or device credentials.

The mechanics are identical to email phishing: a convincing impersonation, a call to action, and a capture mechanism. What makes smishing distinctive is the delivery channel: text messages are opened quickly, often in moments of distraction, and the small screen of a mobile device makes it harder to evaluate the details that would reveal the fraud on a larger display.

The Most Common Smishing Scams in 2025

Package Delivery Smishing

The most common format. A text purportedly from USPS, UPS, FedEx, or Amazon tells you your package couldn’t be delivered or requires a small fee to release. A link leads to a fake delivery site that captures your name, address, and payment card details.

“USPS: Your package has been held at our facility. Please confirm your address to proceed with delivery: [link]”

“Your Amazon package has been returned to our facility. Confirm delivery: [link]”

Bank Fraud Alert Smishing

A text from your “bank” warning of suspicious activity on your account and asking you to click a link or call a number to verify. The link leads to a fake banking login page.

“Chase Alert: A suspicious transaction of $847 was attempted on your account. Verify: [link] or reply STOP to cancel.”

Toll Road / EZPass Smishing

A text claiming you have an unpaid toll balance and must pay immediately to avoid fines. These scams impersonate EZPass, SunPass, and state toll authorities.

“EZPass: You have an outstanding balance of $3.89. Pay now to avoid a $35 late fee: [link]”

DMV Smishing

Fake texts claiming your driver’s license or vehicle registration requires urgent action. Extremely high search volume (dmv scam text 14K/mo).

“CA DMV: Your vehicle registration has been flagged. Update your information to avoid suspension: [link]”

“You’ve Won” / Prize Smishing

Texts claiming you’ve won a prize, gift card, or lottery. A link leads to a page that “claims” the prize while capturing your personal and payment information.

Government / IRS Smishing

Texts impersonating the IRS, Social Security Administration, or state government agencies claiming you owe money or are owed a refund.

Coinbase / Crypto Exchange Smishing

Fake security alerts from cryptocurrency exchanges claiming your account has been compromised. (coinbase text scam 43K/mo searches — the single highest-volume individual text scam keyword.)

“Coinbase: Your account has been accessed from a new device. If this wasn’t you, secure your account: [link]”

Why Smishing Is So Effective

High open rate. Texts are opened and read within minutes. The reflexive habit of checking texts means there’s less mental space for skepticism.

Mobile screen limitations. On a small screen, you can’t easily hover over links to check the destination URL. The abbreviated display of URLs makes it harder to spot suspicious domains.

Context believability. People genuinely receive texts from USPS about packages, from banks about transactions, and from toll authorities about balances. Smishing exploits this real expectation.

No spam filter equivalent for SMS. Email spam filters are sophisticated and catch the majority of phishing emails. SMS filtering is far less mature, and most carriers’ protections are easily bypassed.

Short messages with no red flags. Unlike phishing emails, which may have visible inconsistencies in headers or branding, a text message is just text and a link. There are fewer visible signals to evaluate.

How to Spot a Smishing Text

The link uses a shortened URL or an unfamiliar domain. Legitimate companies rarely use link shorteners in official text communications. And your bank won’t text you a link to bank-secure-verify-alert.com.

The message creates urgency. “Within 24 hours.” “Immediately.” “Or your account will be suspended.” Urgency is the primary lever.

You weren’t expecting contact from this company about this topic. If you haven’t ordered a package, a delivery notification is suspicious. If you’re not an EZPass customer, an EZPass text is a scam.

The sender is a random phone number, not a short code. Legitimate business texts typically come from registered short codes (5-6 digit numbers) or recognizable numbers. A random 10-digit number is a warning sign — though sophisticated smishing operations do sometimes use short codes.

The text asks you to click a link and enter payment information. Legitimate toll authorities, delivery companies, and banks do not collect payment information via text link.

What to Do If You Receive a Smishing Text

Do not click any links. Even if you’re curious about where the link goes — don’t.

Do not call any numbers in the text. The number may connect to a scammer.

Do not reply. Replying confirms your number is active and may result in more scam texts.

Report it: Forward the text to 7726 (SPAM) — the FTC’s shortcode for reporting spam texts. Report to reportfraud.ftc.gov.

Block the sender.

If you’re genuinely concerned about a delivery, a toll balance, or a bank alert, go directly to the company’s official app or website — do not use the link or number in the text.

What to Do If You Clicked a Smishing Link

If you clicked but didn’t enter any information: close the page immediately and run a security scan on your phone. Consider a security app like Malwarebytes or your device’s built-in security features.

If you entered personal information: contact the relevant institution (your bank, the billing company) directly using their official contact information. Change passwords on any accounts that may have been compromised. Monitor your credit reports.

If you entered payment information: contact your bank or card issuer immediately to report unauthorized potential use and request new card numbers.

How to Protect Yourself From Smishing

Enable your carrier’s spam text filtering. Most major carriers (Verizon, AT&T, T-Mobile) offer free or low-cost spam text blocking services. T-Mobile’s “Scam Shield,” AT&T’s “Call Protect,” and Verizon’s “Call Filter” all include SMS spam filtering.

Use a mobile security app. Apps like Malwarebytes, Bitdefender, and Norton Mobile Security provide real-time link scanning and warn you before you visit a fraudulent site.

Verify directly. For any text that claims to require action from you — a delivery, a payment, an account alert — go directly to the company’s official website or app. Do not use the link or number provided in the text.

Don’t share your phone number unnecessarily. The more places your number appears, the more likely it is to end up in a smishing list. Opt out of marketing texts from retailers and limit the sharing of your number.

Frequently Asked Questions

Q: Is smishing the same as text scams?

A: Yes — smishing is the technical term for what’s commonly called text message scams or SMS scams. The terms are interchangeable.

Q: Can I get a virus just from opening a smishing text?

A: Simply opening and reading a text message is generally safe. The risk comes from clicking links within the text. However, if you click a link that leads to a malicious page, malware installation is possible on some devices — particularly older Android devices with unpatched security vulnerabilities.

Q: How do smishing attackers get my phone number?

A: Phone numbers are obtained the same ways as email addresses: data breaches, data brokers, social media profiles, and simply generating numbers systematically. If you’ve ever entered your phone number on a website that was later breached, your number is likely in criminal databases.

→ Back to Pillar: https://www.scammed.org/phishing/

→ See also: https://www.scammed.org/sms-scams/

→ Cross-silo: https://www.scammed.org/phishing/vishing/