ScamLens
High RiskAverage Loss: $800Typical Duration: 1-3 days

Smishing (SMS Phishing): Text Message Scams Explained

Smishing, a portmanteau of SMS and phishing, represents one of the fastest-growing cybercrime threats, with the Federal Trade Commission reporting a 146% increase in SMS-based fraud reports between 2020 and 2023. These attacks exploit the immediacy and trust associated with text messaging, with victims losing an average of $800 per incident. Unlike email phishing which often gets filtered, text messages enjoy a 98% open rate and are read within three minutes of receipt, making them exceptionally effective attack vectors. Scammers send fraudulent text messages impersonating banks, delivery services, government agencies, or employers to create urgency and panic. These messages typically contain malicious links leading to fake websites designed to harvest login credentials, credit card numbers, Social Security numbers, or other sensitive information. The Federal Bureau of Investigation's Internet Crime Complaint Center received over 52,000 smishing complaints in 2023 alone, with total losses exceeding $42 million. What makes smishing particularly dangerous is its ability to bypass traditional security measures. Mobile devices often lack the robust spam filtering and security software present on computers, and users tend to trust text messages more than emails. Attackers leverage spoofing technology to make messages appear from legitimate phone numbers or company shortcodes, and they exploit psychological triggers like fear of account closure, package delivery failures, or tax problems to prompt immediate action without critical thinking.

Common Tactics

  • Package delivery scams where fraudsters send texts claiming a package is delayed, undelivered, or requires immediate action, with links to fake FedEx, UPS, USPS, or Amazon sites designed to steal payment information or login credentials.
  • Bank account security alerts that falsely claim suspicious activity, locked accounts, or required verification, using spoofed numbers matching the victim's actual bank to appear legitimate and direct users to credential-harvesting sites.
  • Tax or government impersonation messages claiming unpaid taxes, Social Security suspension, stimulus payment eligibility, or warrant threats that demand immediate payment through gift cards, wire transfers, or cryptocurrency to resolve fabricated issues.
  • Two-factor authentication bypass attacks where scammers send codes appearing to be from legitimate services, tricking victims into forwarding authentication codes that grant access to real accounts within minutes of interception.
  • Prize and sweepstakes notifications falsely claiming lottery wins, gift card rewards, or contest prizes that require victims to pay processing fees, provide banking details, or click malicious links to claim nonexistent winnings.
  • Employment and payroll scams targeting employees with fake messages from HR departments or executives requesting W-2 information, direct deposit changes, or urgent wire transfers, often timed during busy periods when verification is less likely.

How to Identify

  • Unexpected text messages from unknown numbers or shortcodes claiming to represent familiar companies, especially if you have no pending transactions, deliveries, or account issues with that organization.
  • Urgent language creating artificial time pressure such as 'respond within 24 hours,' 'immediate action required,' or 'account will be closed' designed to bypass your natural skepticism and force hasty decisions.
  • Shortened URLs or suspicious links that don't match the official domain of the purported sender, often using bit.ly, tinyurl.com, or misspelled variations of legitimate company websites.
  • Requests for sensitive information via text including passwords, Social Security numbers, credit card details, or account PINs, which legitimate organizations never request through SMS communications.
  • Generic greetings like 'Dear Customer' or 'Account Holder' instead of your actual name, indicating mass-distributed scam messages rather than personalized communication from companies that know your identity.
  • Grammar and spelling errors, unusual formatting, or awkward phrasing that differs from the professional communication style of legitimate organizations, often indicating translation from foreign scam operations.

How to Protect Yourself

  • Never click links in unsolicited text messages, even if they appear legitimate; instead, manually type the company's official website into your browser or use their official app to check your account status directly.
  • Enable multi-factor authentication using authenticator apps rather than SMS codes whenever possible, as SMS-based two-factor authentication remains vulnerable to SIM swapping and interception attacks by sophisticated criminals.
  • Verify suspicious messages by contacting the organization directly using phone numbers from their official website or the back of your credit card, never using contact information provided in the suspicious text itself.
  • Report smishing attempts to your mobile carrier by forwarding suspicious texts to 7726 (SPAM), which helps providers identify and block scam messages while contributing to broader fraud prevention databases.
  • Install mobile security software that includes anti-phishing protection and regularly update your phone's operating system to patch vulnerabilities that smishing attacks exploit to install malware or spyware.
  • Register your phone number with the National Do Not Call Registry and be especially cautious with any text claiming to need verification codes, as legitimate companies will never ask you to share authentication codes via any communication method.

Real-World Examples

A Chicago resident received a text appearing to be from USPS stating her package was undeliverable due to an incorrect address and providing a link to update delivery information. The link led to a convincing fake USPS website that requested her credit card information for a $3.49 redelivery fee. After entering her details, the scammers immediately made $2,400 in fraudulent charges and sold her card information on the dark web, resulting in months of identity theft complications.

A small business owner in Texas received a text appearing to come from his bank's official shortcode warning of suspicious account activity and instructing him to verify his identity immediately by clicking a link. The fake banking website captured his username, password, and answers to security questions. Within 45 minutes, scammers initiated wire transfers totaling $18,000 to overseas accounts before the business owner discovered the fraud when checking his legitimate bank app.

An elderly couple in Florida received texts claiming they owed $847 in unpaid taxes and faced arrest within 72 hours unless they paid immediately through gift cards. The message included a callback number to a fake IRS agent who pressured them during a three-hour phone call to purchase $5,000 in iTunes and Google Play cards, dictating the card numbers over the phone before the couple realized no legitimate government agency accepts gift card payments.

Frequently Asked Questions

How can I tell if a text message claiming to be from my bank or delivery company is actually a scam?
Legitimate companies rarely ask you to verify sensitive information like passwords or credit card numbers via text, and they won't include suspicious links or demand immediate action due to account problems. Check by calling the official number on your bank statement or company website directly—never use a number from the text message itself. Scammers use spoofing technology to make texts appear from real companies, so when in doubt, contact the organization through a verified channel.
What should I do if I accidentally clicked a link in a smishing text and entered my login credentials or personal information?
Contact your bank and the organization being impersonated immediately to report the incident and freeze your accounts if necessary. Change your passwords right away from a secure device, enable two-factor authentication on all accounts, and monitor your credit reports for fraudulent activity by placing a fraud alert with the credit bureaus. If financial information was compromised, consider placing a credit freeze and reviewing your accounts for unauthorized transactions.
Why are text messages more dangerous than email phishing, and how do scammers make their messages look legitimate?
Text messages have a 98% open rate and are typically read within three minutes, giving victims little time to verify authenticity, while most people trust texts more than emails and mobile devices lack robust spam filtering. Scammers use SMS spoofing technology to display legitimate company names or phone numbers from your bank, government agencies, or retailers, and they create urgency through fear-based language about account closures, package delays, or tax problems that pressure you to act without thinking.
How do I protect myself from smishing attacks without missing legitimate messages from companies I actually do business with?
Register for legitimate alerts directly through your bank and company apps rather than relying on text verification, and enable two-factor authentication methods that don't use SMS when possible, such as authenticator apps or security keys. Never click links in unsolicited texts—instead, open your banking or shopping app directly or call the official customer service number from your statement to verify any alerts about account issues or deliveries.
If a scammer got access to my account using a stolen two-factor authentication code, can I recover my account and prevent them from using it again?
Contact the service provider's account recovery team immediately and change your password using a secure device you know hasn't been compromised, then remove any unrecognized devices from your account settings. Update your recovery email and phone number to ones only you control, enable additional security measures like security questions or backup authentication methods, and review recent account activity for unauthorized changes such as forwarding rules or recovery email modifications that could lock you out further.

Where to Report — United States

Official channels in your region for reporting this scam.

FTC ReportFraud

Reporting

Federal Trade Commission consumer fraud reporting portal.

FBI IC3

Cybercrime Unit

Internet Crime Complaint Center for online and crypto fraud.

CFPB Consumer Complaint

Financial Regulator

For bank, credit card, loan, and payment-related fraud.

AARP Fraud Watch Helpline

Hotline

Free helpline for victims of any age (English/Spanish).

Authoritative Resources

Recognized government and official anti-fraud bodies with guidance on this scam type.

Think you encountered this scam?

How to cite this guide

Use this when referencing ScamLens content in articles, research, AI responses, or social media.

According to ScamLens (scamlens.org), smishing (sms phishing): text message scams explained is described at https://scamlens.org/en/encyclopedia/smishing-sms-phishing.