Smishing: how to recognize a fraudulent SMS and protect yourself
Fake delivery, bank and government texts have become one of the most widespread frauds worldwide. It's called smishing: phishing delivered by SMS or messaging apps, designed to make you click before you think. The scenarios on this page — parcel held in customs, account locked, unpaid fine, child with a new number — cover the vast majority of reported cases. But the list keeps growing: streaming subscriptions, transit passes, tax refunds.
In other words, memorizing a list of brands isn't enough. What protects you long-term is knowing how to spot the mechanisms — identical from one scam to the next.
The 3 mechanisms behind every scam SMS
Urgency
"Final notice", "before a late fee applies", "your account has been locked", "before 10/13". The countdown is artificial: it exists only to stop you from verifying. A message that rushes you deserves more suspicion, not less.
Authority
The name of a bank, a carrier or a government agency is enough to switch off your vigilance. Yet that name costs nothing to copy: a text's sender name can be spoofed, and a fraudulent message can even slip into a thread containing genuine messages from your bank.
Emotion
This is the engine of the fake family member scam. A parent who believes their child is in trouble doesn't verify: they reply. Scammers know this and deliberately write messages with no first name, so they work on any recipient.
5 habits to avoid the trap
1. Never send sensitive data by SMS
Bank details, passwords, one-time verification codes, social security numbers, ID copies: no serious organization asks for these by message. Not your bank, not the tax office, not any government agency. If a message asks, the question is settled: it's a scam.
2. Verify through your own channels
Don't reply to the message, don't call the number it gives. Open your bank's official app, type the website address yourself, or call the number on the back of your bank card or on a letter you received. A real parcel can be tracked on the carrier's own website. Thirty seconds of independent checking cancels the entire scam.
3. Read the link address before clicking
This is the most effective check, and the least known. A web address's real domain is read just before the extension and the first / — not at the start.
How to read an address: the example to remember
In irs-gov.secure-refund.top/.IRS, the real domain is secure-refund.top, an anonymous hosting service — not the IRS. What matters is the word just before the extension (.top,.com…) and the first /.
Three clues that should stop you in your tracks:
- An unusual extension for the organization named:
.biz,.info,.link,.xyz,.top. Afedex-delivery.bizhas nothing to do withfedex.com. - A government agency outside its official domain. US federal agencies use
.gov, UK services.gov.uk.irs-refund-center.comis fraudulent by construction, however credible it looks. - A shortened link (
bit.ly,tinyurl,cutt.us,is.gd): it hides the real destination. An official organization has no reason to hide where it's sending you.
Also remember: major banks state their official texts never contain login links. A link in a "bank" message is, on its own, a red flag.
4. Never install an app from a received link
A legitimate app is downloaded from the App Store, Google Play Store or Galaxy Store, and nowhere else. A link offering to install a file, a "security update" or a "certificate" is trying to plant spyware on your phone — capable of intercepting your bank verification codes afterwards.
5. Beware the channel switch
"Text me on WhatsApp", "call me on this number": being asked to leave SMS is never harmless. It lets the scammer show a credible profile photo, juggle multiple victims at once and escape carrier filtering. When a relative announces a new number, call them on their old one, or check with another family member. Always before, never after.
What to do if you already clicked, replied or paid
Act fast — the order matters.
- 1Contact your bank immediately if you entered banking details, and freeze your card. Fraud reported quickly is far easier to reverse.
- 2Change your passwords from another device, starting with your email and banking accounts. Turn on two-factor authentication wherever it's available.
- 3Forward the text to 7726 (SPAM) — the free spam-reporting shortcode used by carriers in the US and UK.
- 4Report the fraud to the authorities: FTC ReportFraud or IC3 in the US, Action Fraud in the UK, ReportCyber in Australia. If money was taken, file a police report.
- 5Get support if you need it: national helplines and victim-support services exist in most countries and can walk you through the recovery steps.
One last point that matters: falling for it is not carelessness. These messages are crafted by teams that test their wording across millions of sends. The one real habit to keep is reporting it rather than hiding it.
Unsure about a message? Get it analyzed
Paste the suspicious message into our tool: Detect-arnaques examines the text, the links and the scenario, then tells you within seconds whether it matches known scam patterns. Free, no sign-up.
Analyze my messageFrequently asked questions
What is smishing?
Smishing is a form of phishing delivered by SMS or instant messaging. The word combines "SMS" and "phishing". The scammer impersonates a trusted organization to get a click, personal data or a payment.
How can I tell if a text message is a scam?
Check three things: does the message create a sense of urgency? Does it ask for sensitive information? Does the link address exactly match the official domain of the organization it names? A single suspicious answer is enough to justify an independent check.
What happens if I click a scam link without entering anything?
The main risk remains limited, but not zero. Enter nothing on the page, close it, and watch your bank accounts over the following days. If a download started, do not open it — delete the file.
How do I report a scam text?
In the US and UK, forward the message to 7726 (SPAM) — it's free. Then report it to the authorities: the FTC (reportfraud.ftc.gov) or IC3 (ic3.gov) in the US, Action Fraud in the UK, ReportCyber in Australia. If you lost money, contact your bank immediately.
Can my bank text me a link?
Major banks state that their official texts do not contain login links and never ask for credentials. When in doubt, use the official app or the number printed on the back of your card.
Une personne sur deux a déjà reçu ce type de message. Partagez avant qu'elle ne tombe dans le piège.
Envoyer ce guide sur WhatsApp