Smishing is SMS phishing — fraudulent text messages designed to steal your personal information or trick you into installing malware, exploiting the fact that people trust text messages far more instinctively than they trust email. The name is a blend of "SMS" and "phishing," and the mechanics are the same con artists have used for decades: create urgency, impersonate someone trustworthy, and get you to act — click a link, hand over a code, or reply with information — before you stop to think it through.
What makes smishing different from the email phishing most people have already learned to be somewhat suspicious of is the channel itself. Email inboxes are full of spam filters, "external sender" warnings, and years of collective training that taught people to hover over links before clicking. Text messages carry none of that friction. There's no spam folder most people check regularly, no visible sender domain to inspect, and no cultural habit of treating a text with the same suspicion as an email — which is exactly why scammers have shifted so much effort toward SMS in the last few years.
This guide covers what smishing actually is, why it works so consistently well even on people who'd never fall for an obvious email scam, nine real examples of the scam texts circulating right now, exactly what to do the moment you get one, and what to do if you've already clicked. If you're looking for the email-based version of this problem instead, our what is phishing guide covers that channel in full — this article focuses specifically on the text-message side of the same threat.
Who wrote this guide
This article was written and reviewed by IT Cares certified technicians based on the recurring calls we field from clients who tapped a text link on their phone and immediately regretted it. Smishing has become one of the fastest-growing scam categories precisely because so few people apply the same caution to a text that they've learned to apply to email — this guide exists to close that gap.
Why Smishing Works So Well
Smishing succeeds at a rate that consistently surprises even security-conscious people, and it isn't because text-message scams are more technically sophisticated than email ones — usually the opposite is true. It works because of four specific factors baked into how people use their phones.
Texts feel more personal and more urgent than email
A text message lands on the same screen as messages from your spouse, your kids, your doctor's office confirming an appointment. That context alone lends it a baseline of trust email never gets, because email inboxes are already understood to be a mix of real correspondence and marketing noise. A text arriving with the same urgency as "your package couldn't be delivered" or "unusual sign-in detected" borrows credibility from every legitimate personal text that came before it in the same thread of notifications.
Sender ID is easy to spoof
Just like caller ID can be faked on a phone call, the sender name or number displayed for a text can be manipulated so a scam message appears to come from a short code, a familiar-looking number, or even a business name that matches an existing thread from your real bank or delivery company on your phone. Seeing a message land in the same conversation thread as previous legitimate texts from that sender is not proof of who actually sent it.
Mobile links get tapped without the checks people apply on a desktop
On a computer, many people have learned to hover over a link before clicking to preview the actual destination URL. On a phone, that habit essentially doesn't exist — there's no hover state, the screen is small, and tapping is the default reflex. Combine that with a shortened or slightly-off domain that's hard to scrutinize on a small screen, and the natural caution people apply to suspicious links largely evaporates on mobile.
People genuinely expect these exact kinds of texts
Delivery updates, bank fraud alerts, and two-factor authentication codes are all things people receive by text legitimately, routinely, and often unpredictably — you don't know in advance which day a real package notification or bank alert will arrive. That unpredictability is exactly what a fake version exploits: a smishing text doesn't need to convince you that receiving this kind of message is unusual, because receiving it isn't unusual at all. It just needs to convince you this particular one is real.
📊 IT Cares field note: Almost every smishing case we've helped clean up afterward started the same way: "it looked exactly like the texts I normally get from [delivery company/bank]." That's not a coincidence — scammers actively copy the formatting, tone, and even the exact wording real companies use, specifically because a message that looks routine gets far less scrutiny than one that looks obviously off.
Worried you've already been targeted by a scam text?
Our certified technicians can check your phone or computer remotely and tell you honestly whether anything was compromised — no upsell, from $119.99.
9 Real Smishing Scenarios You'll Probably Recognize
These are the specific scam text formats that show up over and over again. Each one uses generic descriptions rather than naming a specific company, because scammers impersonate whichever brand happens to be believable in a given region at a given time — the tactic stays identical no matter which real company's name gets borrowed.
1. The fake "your parcel couldn't be delivered" text
You get a text claiming a delivery attempt failed and you need to "reschedule" or "pay a small redelivery fee" by tapping a link. This is arguably the single most common smishing format worldwide, because almost everyone is expecting a delivery at any given moment.
Red flags: A request for payment to redeliver a package (legitimate carriers essentially never charge a fee by text link); a generic greeting with no order number or tracking number that matches an order you actually placed; a link using a shortened URL or a domain that resembles but doesn't exactly match the real carrier's website.
2. The fake bank fraud alert asking you to "verify" via a link
A text claims suspicious activity was detected on your account and asks you to tap a link to "verify your identity" or "confirm this was you," leading to a fake login page built to capture your banking credentials.
Red flags: Real banks generally don't ask you to "verify your account" by tapping a link in a text — they may alert you to a transaction, but the safe response is to open your banking app or type in the bank's known web address yourself, never the link provided. Urgency ("your account will be locked in 24 hours") is a manufactured pressure tactic, not a real banking practice.
3. The fake toll or parking violation payment demand
A text claims you owe an unpaid toll, parking ticket, or vehicle violation, with a small dollar amount and a link to "pay now to avoid additional penalties." This format has spread rapidly because tolling and parking systems that bill after the fact are genuinely common, making the premise plausible.
Red flags: A generic reference number instead of your actual license plate or account details; a payment link rather than a direction to the toll authority's own known website; an unusually small, easy-to-just-pay-and-move-on dollar amount designed to make the path of least resistance feel cheaper than double-checking.
4. The fake 2FA code request from someone who already has your password
You receive a real two-factor authentication code from a legitimate service you actually use, immediately followed by a text or call pretending to be that service, asking you to "confirm" or "read back" the code you just received. This scenario means an attacker has already obtained your password from a breach or previous phishing attempt and is now trying to get past your second security layer in real time.
Red flags: Receiving a 2FA code you did not request is itself the first warning sign — it means someone just entered your correct password somewhere. No legitimate company will ever contact you asking you to read back or forward a 2FA code; the code exists specifically so that only you, using your own device, can complete the login.
5. The fake prize or gift card win
A text congratulates you on winning a gift card, a free product, or a contest prize you don't remember entering, with a link to "claim" it — usually requiring personal information or a small "shipping fee" payment upfront.
Red flags: Winning a contest you never entered; any request for payment or card details to receive a "free" prize; excessive excitement and urgency ("claim within 2 hours or forfeit") designed to short-circuit normal skepticism.
6. The fake employer or "CEO" text asking for gift cards
A text appears to come from a boss, company owner, or HR contact, often claiming to be "in a meeting and can't call," asking the recipient to urgently purchase gift cards and send the codes, or to handle an unusual, time-sensitive request. This targets employees specifically and relies on workplace hierarchy and the fear of ignoring a request from someone senior.
Red flags: A request for gift cards as payment for anything work-related (no legitimate business expense works this way); a sender claiming to be unreachable by phone or in-person specifically to prevent you from verifying through a normal channel; a number that doesn't match the actual contact you have saved for that person.
7. The fake COVID or public health alert
A text claims you've been in contact with someone who tested positive for a contagious illness, or references a government health program, directing you to a link to "register" or "verify eligibility" for a benefit, capturing personal and sometimes financial information along the way. These spike whenever a real public health event is in the news, because the underlying anxiety is genuine even when the text is not.
Red flags: Legitimate health contact tracing programs generally don't operate by unsolicited text link; a request for personal or financial information framed as urgent and health-related is a strong indicator of a scam regardless of how current the health topic feels.
8. The fake subscription renewal notice
A text claims a subscription (streaming, antivirus, a shopping membership) is about to renew at a surprising price, with a link to "cancel" or "manage" your subscription — leading to a fake page that harvests payment details under the pretext of processing a "refund" or "cancellation."
Red flags: Subscription services you use typically bill and notify through the app or account you already have, not by unsolicited text with a payment-page link; an unusually high renewal amount designed to provoke an immediate, panicked click rather than a considered response.
9. The fake government benefit or tax agency text
A text claims you're owed a refund, benefit payment, or tax credit and asks you to click a link to "provide banking details" to receive it, or alternatively claims you owe a debt and threatens legal action if you don't pay immediately by text-linked payment. Government agencies in Canada and the US generally do not request banking details or demand immediate payment by unsolicited text.
Red flags: Any unsolicited text claiming to be a tax or benefits agency that asks for banking information to "deposit" money you weren't expecting; threats of arrest, legal action, or account suspension for non-payment within an unusually short window; a link rather than a direction to the agency's own known website or phone line.
Smishing Is Getting Harder to Spot
A few years ago, a large share of scam texts were easy to dismiss on sight — broken grammar, obviously mistranslated phrasing, and generic greetings that didn't match how a real company actually writes to customers. That's changing quickly. Widely available AI writing tools now let scammers generate polished, natural-sounding text messages in seconds, matching the tone and formatting of real delivery notifications, bank alerts, and employer messages far more convincingly than the clumsy scam texts of even two or three years ago.
This shift matters because it removes one of the easiest tells people have relied on for years — "it's obviously a scam, look how badly it's written" no longer holds up as a reliable filter. The practical response isn't to get better at spotting bad writing; it's to stop using writing quality as your test at all, and instead rely on the structural red flags covered in each scenario above: unsolicited links, requests for payment or credentials, and urgency that discourages verification. A well-written scam text is still a scam text, and the same six-step response applies regardless of how convincing the wording is.
📊 IT Cares field note: We've started seeing smishing texts that read genuinely well — correct grammar, natural phrasing, even a plausible-sounding local touch. The clients who avoided getting caught weren't the ones who spotted a typo; they were the ones who simply never click a link in an unexpected text at all, regardless of how convincing it looks. That single habit outperforms trying to "detect" a well-written scam every time.
Smishing vs Email Phishing: What's Actually Different
The underlying goal is identical — trick you into handing over information or installing something malicious — but the delivery channel changes the mechanics enough to be worth understanding separately, which is why we cover email phishing in depth in a separate guide rather than folding it into this one.
| Factor | Smishing (SMS) | Email phishing |
|---|---|---|
| Trust level | Higher — shares a screen with personal texts from real contacts | Lower — inboxes are already understood to mix spam and real mail |
| Link inspection habits | Minimal — no hover-to-preview on a phone, small screen hides the real URL | Better trained — many people at least glance at the sender domain |
| Filtering | Little to no equivalent of a spam folder most people check | Spam filters catch a large share automatically |
| Common bait | Delivery notices, bank alerts, 2FA codes, tolls | Invoices, password reset requests, shared documents, urgent account notices |
The practical takeaway is that the same person who correctly ignores a suspicious email may still tap a suspicious text without a second thought, simply because the two channels carry different levels of built-in suspicion. Treating a text with the same caution you'd apply to an unexpected email is the single biggest mindset shift that closes this gap.
What to Do If You Get a Suspicious Text
These six steps apply whether the text claims to be a delivery company, your bank, or anything else — the response is identical regardless of who it pretends to be.
Don't click the link
Even a single tap can load a fake page built to steal your login or, in rarer cases, trigger a download. Treat any link in an unexpected text as unsafe until you've verified it another way.
Don't reply
Replying — even just "STOP" or "who is this" — confirms to the scammer that your number is active and read by a real person, which tends to invite more attempts, not fewer.
Verify directly through the official app or website
If the text claims to be your bank, a delivery company, or your employer, open their official app or type in the known web address yourself — never the link or number given in the text.
Report and block the number
Most phones let you report a text as junk and block the sender directly from the messages app in two taps. Do both, even if you're already confident it was a scam.
Report it to your carrier and the Canadian Anti-Fraud Centre
Forward the message to 7726 (SPAM) to flag it with your mobile carrier at no cost. In Canada, also report it to the Canadian Anti-Fraud Centre; in the US, report it to the FTC. This helps flag patterns for everyone else, too.
Delete the message
Once reported and blocked, delete it. There's no reason to keep a scam text sitting in your inbox where you might second-guess yourself and tap it later out of habit.
The one habit that stops nearly every smishing attempt
Never click a link or enter information from a text you weren't specifically expecting. If a delivery, bank, or account issue is real, you can always find it by opening the official app or typing the company's known website directly — you lose nothing by verifying that way instead of tapping the link in the text itself.
What to Do If You Already Clicked
If you've already tapped a smishing link, the priority shifts from prevention to damage control — and how much damage control depends heavily on what happened after you clicked.
If a page prompted you to install something
Disconnect the device from Wi-Fi and mobile data immediately if you're not sure whether an install completed or is still running in the background. This limits any app or malicious profile's ability to communicate out while you assess the situation. Then, without connecting back to the internet, check your list of installed apps and, on Android, your device admin/accessibility permissions for anything you don't recognize.
If a page loaded but you didn't enter anything
Close the page and don't enter any information into it, even out of curiosity to "see what it says." Some fake pages are built purely to harvest whatever gets typed, and simply viewing a well-built phishing page without submitting anything generally causes no damage on its own.
If you did enter information
Change the relevant passwords immediately — but do it from a different, clean device rather than the one that may have been exposed, in case anything was installed that could capture new keystrokes. Prioritize your email and banking passwords first, since those are typically the accounts that unlock everything else. Enable two-factor authentication anywhere you haven't already, using our two-factor authentication setup guide if you need a walkthrough.
Monitor your accounts closely afterward
Check bank and credit card statements for unrecognized charges over the following weeks, and consider a credit monitoring or fraud alert if you entered sensitive personal information like a social insurance number or full card details. Our identity theft recovery guide walks through the fuller recovery process if information beyond a single password was exposed.
The broader recovery mindset here mirrors what we cover for other scam formats — for the parallel case of a live tech-support scam call rather than a text, our tech support scam warning signs guide covers the recovery steps for that specific scenario in more depth, including what to do if remote access was granted to your computer.
Not sure what actually happened after you clicked?
If you tapped a smishing link and you're not confident about what — if anything — was installed or accessed, IT Cares can check your device remotely and give you a straight answer rather than leaving you to guess.
Frequently Asked Questions
Not Sure If That Text (or Your Device) Is Actually Safe?
IT Cares can check your phone or computer remotely and tell you honestly whether a suspicious text link did anything, and help you lock down your accounts if it did.
Comments (3)
Got the "parcel couldn't be delivered" text literally the day I read this. Almost tapped it out of habit — glad I checked the tracking number first and it didn't match anything I ordered.
The 2FA code section was an eye-opener. Never realized getting a code you didn't ask for means someone already has your password.
Didn't know replying STOP to a scam text does nothing but confirm your number is active. Always thought it was harmless.
Leave a Comment