ScreenConnect Shield
All articles
Mobile 6 min read

Smishing: Why Your Texts Are the New Phishing Inbox

Fake delivery notifications, bank alerts, and 'wrong number' chats — the new front line of scams.

SMS phishing — *smishing* — has overtaken email as the #1 scam delivery channel for consumers. The US FTC reported $470 million lost to text-message scams in 2024, more than email phishing for the second year in a row. Texts work because they feel personal, arrive on a device you trust, and bypass most spam filters.

The four families of smish you'll see this year

  1. Delivery notifications. "DHL: your package is held at customs. Pay €1.99 here." The link goes to a card-skimming clone. The real carriers will never charge a customs fee by SMS — verify the tracking number on the carrier's official app. USPS's smishing alert shows real examples.
  2. Bank / card fraud alerts. "Did you authorize a $437 purchase? Reply STOP or visit bnk-alert.co". The link leads to a fake login page that also asks for your 2FA code. Real banks never ask you to confirm transactions via a link in an unsolicited text.
  3. "Wrong number" pig-butchering. A friendly "Hi Sarah, are we still on for Thursday?" Reply once and a long, warm conversation pivots over weeks into "I'll show you my crypto trading strategy." The FBI IC3 report on confidence/investment fraud tracks this as the single most-costly consumer scam category — billions of dollars per year.
  4. Government & tax scams. "IRS: your refund is on hold." Real tax authorities almost never initiate contact via SMS — see the IRS guidance on text scams.

The 5-second smish test

  • Did I expect this message? If not, treat the link as hostile by default.
  • Does it create urgency or fear? "Final notice", "account locked", "package held" — all classic levers.
  • Is the sender a long number, a 5–6 digit shortcode I don't recognize, or an email address? Most legitimate brands you'd hear from text from a consistent shortcode you can verify on their website.
  • Does the link domain match the brand exactly? ups-tracking.net is not ups.com. Shortened links (bit.ly, tinyurl, t.co) deserve extra suspicion.

What to do

  • Never tap. Open the official app for that service — your bank, the delivery carrier, your tax agency — and check there.
  • If you must check the link, paste it into ScreenConnect Shield's scanner first. We expand shortened URLs and reveal the final destination so you never load it in your browser.
  • Report smishing in the US by forwarding the text to 7726 (SPAM). This goes to your carrier's anti-fraud team. UK users can forward to 7726 as well — see Ofcom's report-scam-texts page.
  • Block the number and delete the message. Don't reply, not even "STOP" — replying confirms the number is active to a scammer.

One mindset shift

Treat unsolicited text links the way you'd treat a stranger handing you an envelope in the street. Curiosity is the attacker's most reliable tool. Slow down for five seconds, and almost every smish falls apart.

Learn more & verify

Authoritative sources used in this article — open in a new tab.

Have a suspicious link? Don't click it.

Paste it into the ScreenConnect Shield Link Scanner for an instant safety verdict.

Scan a link