What Is Smishing? How to Spot and Avoid SMS Phishing Scams (2026)

Reviewed by IT Cares certified technicians · Updated July 2026

Smartphone screen showing a suspicious fake delivery text message — an example of an SMS phishing (smishing) scam
A fake "your parcel couldn't be delivered" text is one of the most common smishing openers — it feels routine enough that most people don't stop to question it.
📱
Already clicked a suspicious text link and not sure what to check? Our certified technicians can look at your device remotely and tell you plainly whether anything was actually installed.
Get Help Now →

Smishing is SMS phishing — fraudulent text messages designed to steal your personal information or trick you into installing malware, exploiting the fact that people trust text messages far more instinctively than they trust email. The name is a blend of "SMS" and "phishing," and the mechanics are the same con artists have used for decades: create urgency, impersonate someone trustworthy, and get you to act — click a link, hand over a code, or reply with information — before you stop to think it through.

What makes smishing different from the email phishing most people have already learned to be somewhat suspicious of is the channel itself. Email inboxes are full of spam filters, "external sender" warnings, and years of collective training that taught people to hover over links before clicking. Text messages carry none of that friction. There's no spam folder most people check regularly, no visible sender domain to inspect, and no cultural habit of treating a text with the same suspicion as an email — which is exactly why scammers have shifted so much effort toward SMS in the last few years.

This guide covers what smishing actually is, why it works so consistently well even on people who'd never fall for an obvious email scam, nine real examples of the scam texts circulating right now, exactly what to do the moment you get one, and what to do if you've already clicked. If you're looking for the email-based version of this problem instead, our what is phishing guide covers that channel in full — this article focuses specifically on the text-message side of the same threat.

Who wrote this guide

This article was written and reviewed by IT Cares certified technicians based on the recurring calls we field from clients who tapped a text link on their phone and immediately regretted it. Smishing has become one of the fastest-growing scam categories precisely because so few people apply the same caution to a text that they've learned to apply to email — this guide exists to close that gap.

Why Smishing Works So Well

Smishing succeeds at a rate that consistently surprises even security-conscious people, and it isn't because text-message scams are more technically sophisticated than email ones — usually the opposite is true. It works because of four specific factors baked into how people use their phones.

Texts feel more personal and more urgent than email

A text message lands on the same screen as messages from your spouse, your kids, your doctor's office confirming an appointment. That context alone lends it a baseline of trust email never gets, because email inboxes are already understood to be a mix of real correspondence and marketing noise. A text arriving with the same urgency as "your package couldn't be delivered" or "unusual sign-in detected" borrows credibility from every legitimate personal text that came before it in the same thread of notifications.

Sender ID is easy to spoof

Just like caller ID can be faked on a phone call, the sender name or number displayed for a text can be manipulated so a scam message appears to come from a short code, a familiar-looking number, or even a business name that matches an existing thread from your real bank or delivery company on your phone. Seeing a message land in the same conversation thread as previous legitimate texts from that sender is not proof of who actually sent it.

Mobile links get tapped without the checks people apply on a desktop

On a computer, many people have learned to hover over a link before clicking to preview the actual destination URL. On a phone, that habit essentially doesn't exist — there's no hover state, the screen is small, and tapping is the default reflex. Combine that with a shortened or slightly-off domain that's hard to scrutinize on a small screen, and the natural caution people apply to suspicious links largely evaporates on mobile.

People genuinely expect these exact kinds of texts

Delivery updates, bank fraud alerts, and two-factor authentication codes are all things people receive by text legitimately, routinely, and often unpredictably — you don't know in advance which day a real package notification or bank alert will arrive. That unpredictability is exactly what a fake version exploits: a smishing text doesn't need to convince you that receiving this kind of message is unusual, because receiving it isn't unusual at all. It just needs to convince you this particular one is real.

📊 IT Cares field note: Almost every smishing case we've helped clean up afterward started the same way: "it looked exactly like the texts I normally get from [delivery company/bank]." That's not a coincidence — scammers actively copy the formatting, tone, and even the exact wording real companies use, specifically because a message that looks routine gets far less scrutiny than one that looks obviously off.

Worried you've already been targeted by a scam text?

Our certified technicians can check your phone or computer remotely and tell you honestly whether anything was compromised — no upsell, from $119.99.

9 Real Smishing Scenarios You'll Probably Recognize

These are the specific scam text formats that show up over and over again. Each one uses generic descriptions rather than naming a specific company, because scammers impersonate whichever brand happens to be believable in a given region at a given time — the tactic stays identical no matter which real company's name gets borrowed.

1. The fake "your parcel couldn't be delivered" text

You get a text claiming a delivery attempt failed and you need to "reschedule" or "pay a small redelivery fee" by tapping a link. This is arguably the single most common smishing format worldwide, because almost everyone is expecting a delivery at any given moment.

Red flags: A request for payment to redeliver a package (legitimate carriers essentially never charge a fee by text link); a generic greeting with no order number or tracking number that matches an order you actually placed; a link using a shortened URL or a domain that resembles but doesn't exactly match the real carrier's website.

2. The fake bank fraud alert asking you to "verify" via a link

A text claims suspicious activity was detected on your account and asks you to tap a link to "verify your identity" or "confirm this was you," leading to a fake login page built to capture your banking credentials.

Red flags: Real banks generally don't ask you to "verify your account" by tapping a link in a text — they may alert you to a transaction, but the safe response is to open your banking app or type in the bank's known web address yourself, never the link provided. Urgency ("your account will be locked in 24 hours") is a manufactured pressure tactic, not a real banking practice.

3. The fake toll or parking violation payment demand

A text claims you owe an unpaid toll, parking ticket, or vehicle violation, with a small dollar amount and a link to "pay now to avoid additional penalties." This format has spread rapidly because tolling and parking systems that bill after the fact are genuinely common, making the premise plausible.

Red flags: A generic reference number instead of your actual license plate or account details; a payment link rather than a direction to the toll authority's own known website; an unusually small, easy-to-just-pay-and-move-on dollar amount designed to make the path of least resistance feel cheaper than double-checking.

4. The fake 2FA code request from someone who already has your password

You receive a real two-factor authentication code from a legitimate service you actually use, immediately followed by a text or call pretending to be that service, asking you to "confirm" or "read back" the code you just received. This scenario means an attacker has already obtained your password from a breach or previous phishing attempt and is now trying to get past your second security layer in real time.

Red flags: Receiving a 2FA code you did not request is itself the first warning sign — it means someone just entered your correct password somewhere. No legitimate company will ever contact you asking you to read back or forward a 2FA code; the code exists specifically so that only you, using your own device, can complete the login.

5. The fake prize or gift card win

A text congratulates you on winning a gift card, a free product, or a contest prize you don't remember entering, with a link to "claim" it — usually requiring personal information or a small "shipping fee" payment upfront.

Red flags: Winning a contest you never entered; any request for payment or card details to receive a "free" prize; excessive excitement and urgency ("claim within 2 hours or forfeit") designed to short-circuit normal skepticism.

6. The fake employer or "CEO" text asking for gift cards

A text appears to come from a boss, company owner, or HR contact, often claiming to be "in a meeting and can't call," asking the recipient to urgently purchase gift cards and send the codes, or to handle an unusual, time-sensitive request. This targets employees specifically and relies on workplace hierarchy and the fear of ignoring a request from someone senior.

Red flags: A request for gift cards as payment for anything work-related (no legitimate business expense works this way); a sender claiming to be unreachable by phone or in-person specifically to prevent you from verifying through a normal channel; a number that doesn't match the actual contact you have saved for that person.

7. The fake COVID or public health alert

A text claims you've been in contact with someone who tested positive for a contagious illness, or references a government health program, directing you to a link to "register" or "verify eligibility" for a benefit, capturing personal and sometimes financial information along the way. These spike whenever a real public health event is in the news, because the underlying anxiety is genuine even when the text is not.

Red flags: Legitimate health contact tracing programs generally don't operate by unsolicited text link; a request for personal or financial information framed as urgent and health-related is a strong indicator of a scam regardless of how current the health topic feels.

8. The fake subscription renewal notice

A text claims a subscription (streaming, antivirus, a shopping membership) is about to renew at a surprising price, with a link to "cancel" or "manage" your subscription — leading to a fake page that harvests payment details under the pretext of processing a "refund" or "cancellation."

Red flags: Subscription services you use typically bill and notify through the app or account you already have, not by unsolicited text with a payment-page link; an unusually high renewal amount designed to provoke an immediate, panicked click rather than a considered response.

9. The fake government benefit or tax agency text

A text claims you're owed a refund, benefit payment, or tax credit and asks you to click a link to "provide banking details" to receive it, or alternatively claims you owe a debt and threatens legal action if you don't pay immediately by text-linked payment. Government agencies in Canada and the US generally do not request banking details or demand immediate payment by unsolicited text.

Red flags: Any unsolicited text claiming to be a tax or benefits agency that asks for banking information to "deposit" money you weren't expecting; threats of arrest, legal action, or account suspension for non-payment within an unusually short window; a link rather than a direction to the agency's own known website or phone line.

Smishing Is Getting Harder to Spot

A few years ago, a large share of scam texts were easy to dismiss on sight — broken grammar, obviously mistranslated phrasing, and generic greetings that didn't match how a real company actually writes to customers. That's changing quickly. Widely available AI writing tools now let scammers generate polished, natural-sounding text messages in seconds, matching the tone and formatting of real delivery notifications, bank alerts, and employer messages far more convincingly than the clumsy scam texts of even two or three years ago.

This shift matters because it removes one of the easiest tells people have relied on for years — "it's obviously a scam, look how badly it's written" no longer holds up as a reliable filter. The practical response isn't to get better at spotting bad writing; it's to stop using writing quality as your test at all, and instead rely on the structural red flags covered in each scenario above: unsolicited links, requests for payment or credentials, and urgency that discourages verification. A well-written scam text is still a scam text, and the same six-step response applies regardless of how convincing the wording is.

📊 IT Cares field note: We've started seeing smishing texts that read genuinely well — correct grammar, natural phrasing, even a plausible-sounding local touch. The clients who avoided getting caught weren't the ones who spotted a typo; they were the ones who simply never click a link in an unexpected text at all, regardless of how convincing it looks. That single habit outperforms trying to "detect" a well-written scam every time.

Smishing vs Email Phishing: What's Actually Different

The underlying goal is identical — trick you into handing over information or installing something malicious — but the delivery channel changes the mechanics enough to be worth understanding separately, which is why we cover email phishing in depth in a separate guide rather than folding it into this one.

FactorSmishing (SMS)Email phishing
Trust level Higher — shares a screen with personal texts from real contacts Lower — inboxes are already understood to mix spam and real mail
Link inspection habits Minimal — no hover-to-preview on a phone, small screen hides the real URL Better trained — many people at least glance at the sender domain
Filtering Little to no equivalent of a spam folder most people check Spam filters catch a large share automatically
Common bait Delivery notices, bank alerts, 2FA codes, tolls Invoices, password reset requests, shared documents, urgent account notices

The practical takeaway is that the same person who correctly ignores a suspicious email may still tap a suspicious text without a second thought, simply because the two channels carry different levels of built-in suspicion. Treating a text with the same caution you'd apply to an unexpected email is the single biggest mindset shift that closes this gap.

What to Do If You Get a Suspicious Text

These six steps apply whether the text claims to be a delivery company, your bank, or anything else — the response is identical regardless of who it pretends to be.

1

Don't click the link

Even a single tap can load a fake page built to steal your login or, in rarer cases, trigger a download. Treat any link in an unexpected text as unsafe until you've verified it another way.

2

Don't reply

Replying — even just "STOP" or "who is this" — confirms to the scammer that your number is active and read by a real person, which tends to invite more attempts, not fewer.

3

Verify directly through the official app or website

If the text claims to be your bank, a delivery company, or your employer, open their official app or type in the known web address yourself — never the link or number given in the text.

4

Report and block the number

Most phones let you report a text as junk and block the sender directly from the messages app in two taps. Do both, even if you're already confident it was a scam.

5

Report it to your carrier and the Canadian Anti-Fraud Centre

Forward the message to 7726 (SPAM) to flag it with your mobile carrier at no cost. In Canada, also report it to the Canadian Anti-Fraud Centre; in the US, report it to the FTC. This helps flag patterns for everyone else, too.

6

Delete the message

Once reported and blocked, delete it. There's no reason to keep a scam text sitting in your inbox where you might second-guess yourself and tap it later out of habit.

The one habit that stops nearly every smishing attempt

Never click a link or enter information from a text you weren't specifically expecting. If a delivery, bank, or account issue is real, you can always find it by opening the official app or typing the company's known website directly — you lose nothing by verifying that way instead of tapping the link in the text itself.

What to Do If You Already Clicked

If you've already tapped a smishing link, the priority shifts from prevention to damage control — and how much damage control depends heavily on what happened after you clicked.

If a page prompted you to install something

Disconnect the device from Wi-Fi and mobile data immediately if you're not sure whether an install completed or is still running in the background. This limits any app or malicious profile's ability to communicate out while you assess the situation. Then, without connecting back to the internet, check your list of installed apps and, on Android, your device admin/accessibility permissions for anything you don't recognize.

If a page loaded but you didn't enter anything

Close the page and don't enter any information into it, even out of curiosity to "see what it says." Some fake pages are built purely to harvest whatever gets typed, and simply viewing a well-built phishing page without submitting anything generally causes no damage on its own.

If you did enter information

Change the relevant passwords immediately — but do it from a different, clean device rather than the one that may have been exposed, in case anything was installed that could capture new keystrokes. Prioritize your email and banking passwords first, since those are typically the accounts that unlock everything else. Enable two-factor authentication anywhere you haven't already, using our two-factor authentication setup guide if you need a walkthrough.

Monitor your accounts closely afterward

Check bank and credit card statements for unrecognized charges over the following weeks, and consider a credit monitoring or fraud alert if you entered sensitive personal information like a social insurance number or full card details. Our identity theft recovery guide walks through the fuller recovery process if information beyond a single password was exposed.

The broader recovery mindset here mirrors what we cover for other scam formats — for the parallel case of a live tech-support scam call rather than a text, our tech support scam warning signs guide covers the recovery steps for that specific scenario in more depth, including what to do if remote access was granted to your computer.

Not sure what actually happened after you clicked?

If you tapped a smishing link and you're not confident about what — if anything — was installed or accessed, IT Cares can check your device remotely and give you a straight answer rather than leaving you to guess.

Frequently Asked Questions

Can a smishing text install malware just by opening it?
Simply opening a text message and reading it is very unlikely to install anything on its own, on a modern, updated phone — the real danger is almost always the link inside it, or an attachment you're prompted to open. That said, keeping your phone's operating system updated matters, because rare vulnerabilities that allow message-based exploitation without any tap at all have existed in the past and get patched through software updates. The safest working assumption is: opening the text is fine, tapping the link is where the risk begins.
How do scammers get my phone number in the first place?
Usually from data breaches, where phone numbers tied to accounts get leaked or sold in bulk, from public sources like old classified ads or business listings, or simply from random number generation aimed at every possible combination in a given area code. Scammers don't need to specifically target you — mass smishing campaigns send the same fake delivery or bank text to thousands of numbers at once, and it costs them almost nothing to do so, even if only a small fraction of people fall for it.
Is it safe to reply STOP to a scam text?
For a legitimate company's marketing texts, yes — replying STOP is a real opt-out mechanism required by law. For a smishing scam, no: scammers don't run real opt-out systems, so replying STOP does nothing to unsubscribe you. What it does do is confirm your number is active and read by a real person, which can result in your number being sold or targeted more, not less. The safer move for a suspected scam text is to block and report it without replying at all.
Can I get charged money just by clicking a smishing link?
Clicking a link by itself typically doesn't charge you anything directly, but it can lead somewhere that does — a fake payment page designed to capture your card details, a page that tricks you into a premium subscription, or a prompt to install an app that later charges you or steals stored payment info. The financial damage from smishing almost always comes from what happens after the click: entering information or installing something, not the click itself.
Do scam texts always come from a random or foreign-looking number?
No, and this is part of why smishing is so effective. Scammers can spoof the sender ID so a text appears to come from a short code, a familiar area code, or even display a recognizable business name instead of a number, using the same techniques as caller ID spoofing on phone calls. A message that visually blends into a real thread from your bank or a delivery company tells you nothing reliable about who actually sent it — the sender name and number can both be faked.
Should I block every unknown number that texts me?
Blocking is a reasonable default for anything suspicious, but it isn't strictly necessary for every unknown number — legitimate one-time codes, appointment reminders, and delivery updates often come from numbers you haven't saved. The safer habit isn't blocking everything blindly; it's never clicking a link or entering information from an unexpected text until you've verified it through an official app or website first, then blocking and reporting anything that turns out to be a scam.
Can smishing happen through iMessage or WhatsApp, not just regular SMS?
Yes. While "smishing" technically refers to SMS, the same fake-message-with-a-malicious-link approach happens constantly over iMessage, WhatsApp, and other messaging apps — the delivery channel changes, but the tactic and the red flags to watch for are identical. Treat a suspicious link the same way regardless of which messaging app it arrived through.
What's the difference between smishing and vishing?
Smishing is phishing delivered by text message; vishing ("voice phishing") is the same kind of scam delivered through a phone call, often with a caller impersonating a bank, government agency, or tech support representative. The two frequently work together — a smishing text creates urgency and directs you to call a number, and that call is answered by a scammer running a live vishing script. Both rely on the same psychological pressure: urgency, authority, and a reason not to stop and verify.

Not Sure If That Text (or Your Device) Is Actually Safe?

IT Cares can check your phone or computer remotely and tell you honestly whether a suspicious text link did anything, and help you lock down your accounts if it did.

Comments (3)

MT
Maxime T., Laval
July 19, 2026

Got the "parcel couldn't be delivered" text literally the day I read this. Almost tapped it out of habit — glad I checked the tracking number first and it didn't match anything I ordered.

CB
Chantal B., Brossard
July 18, 2026

The 2FA code section was an eye-opener. Never realized getting a code you didn't ask for means someone already has your password.

JR
Jonathan R., Longueuil
July 17, 2026

Didn't know replying STOP to a scam text does nothing but confirm your number is active. Always thought it was harmless.

Leave a Comment

Need Help?