Smishing: Why Your Texts Are the New Phishing Inbox
Fake delivery notifications, bank alerts, and 'wrong number' chats — the new front line of scams.
SMS phishing — *smishing* — has overtaken email as the #1 scam delivery channel for consumers. The US FTC reported $470 million lost to text-message scams in 2024, more than email phishing for the second year in a row. Texts work because they feel personal, arrive on a device you trust, and bypass most spam filters.
The four families of smish you'll see this year
- Delivery notifications. "DHL: your package is held at customs. Pay €1.99 here." The link goes to a card-skimming clone. The real carriers will never charge a customs fee by SMS — verify the tracking number on the carrier's official app. USPS's smishing alert shows real examples.
- Bank / card fraud alerts. "Did you authorize a $437 purchase? Reply STOP or visit bnk-alert.co". The link leads to a fake login page that also asks for your 2FA code. Real banks never ask you to confirm transactions via a link in an unsolicited text.
- "Wrong number" pig-butchering. A friendly "Hi Sarah, are we still on for Thursday?" Reply once and a long, warm conversation pivots over weeks into "I'll show you my crypto trading strategy." The FBI IC3 report on confidence/investment fraud tracks this as the single most-costly consumer scam category — billions of dollars per year.
- Government & tax scams. "IRS: your refund is on hold." Real tax authorities almost never initiate contact via SMS — see the IRS guidance on text scams.
The 5-second smish test
- Did I expect this message? If not, treat the link as hostile by default.
- Does it create urgency or fear? "Final notice", "account locked", "package held" — all classic levers.
- Is the sender a long number, a 5–6 digit shortcode I don't recognize, or an email address? Most legitimate brands you'd hear from text from a consistent shortcode you can verify on their website.
- Does the link domain match the brand exactly?
ups-tracking.netis notups.com. Shortened links (bit.ly,tinyurl,t.co) deserve extra suspicion.
What to do
- Never tap. Open the official app for that service — your bank, the delivery carrier, your tax agency — and check there.
- If you must check the link, paste it into ScreenConnect Shield's scanner first. We expand shortened URLs and reveal the final destination so you never load it in your browser.
- Report smishing in the US by forwarding the text to 7726 (SPAM). This goes to your carrier's anti-fraud team. UK users can forward to 7726 as well — see Ofcom's report-scam-texts page.
- Block the number and delete the message. Don't reply, not even "STOP" — replying confirms the number is active to a scammer.
One mindset shift
Treat unsolicited text links the way you'd treat a stranger handing you an envelope in the street. Curiosity is the attacker's most reliable tool. Slow down for five seconds, and almost every smish falls apart.
Learn more & verify
Authoritative sources used in this article — open in a new tab.
Have a suspicious link? Don't click it.
Paste it into the ScreenConnect Shield Link Scanner for an instant safety verdict.
Scan a link