Smishing (SMS Phishing)
Learn how smishing (SMS phishing) works, how to spot fraudulent text messages, and how to protect yourself. Includes real-life examples, warning signs, and expert safeguarding tips.
Overview
What is smishing?
Smishing — a combination of "SMS" and "phishing" — is a form of fraud carried out via text message. Scammers send deceptive SMS messages designed to trick you into clicking a malicious link, calling a fraudulent number, or handing over sensitive personal information such as banking credentials, passwords, or delivery details.
These messages typically impersonate trusted organisations: postal and courier services (Royal Mail, FedEx, UPS, USPS), banks, government agencies, tax authorities, or popular retailers. The most widespread lure is a fake package delivery notification — a message claiming your parcel could not be delivered and asking you to pay a small fee or confirm your address via a link. That link leads to a convincing fake website engineered to steal your information or install malware on your device.
Smishing is particularly dangerous because most people are far less suspicious of text messages than emails. We are conditioned to act on texts quickly, and mobile screens make it harder to scrutinise sender details or destination URLs before tapping.
Who is targeted: Anyone with a mobile phone number — including people who rarely use email or the internet. Smishing campaigns are frequently blasted to millions of numbers at random, meaning no prior exposure or account is needed to be targeted.
Why it works: Text messages feel personal and immediate. Combined with a convincing cover story — a parcel stuck in customs, an unpaid toll charge, a suspicious login attempt — smishing exploits urgency and trust in familiar brands at a moment when victims are least likely to pause and verify.
Scale & Statistics
How common is this scam?
Smishing has grown explosively in recent years, overtaking email phishing in some regions as the primary method of consumer fraud.
- 3.5 billion smishing messages are estimated to be sent globally every day in 2024
- $330 million in losses were reported to the FTC from text message scams in 2022 alone — the most recent year with complete figures
- RoboKiller reported a 2,500% increase in smishing attacks between 2019 and 2023
- One in three adults in the UK reported receiving a suspicious text message in 2023, according to Ofcom
- Package delivery scams account for more than 26% of all smishing attempts globally, making them the single most common lure
- 82% of people open every text they receive — compared to around 20% for email — making SMS a highly effective attack channel
- 45% of smishing messages in 2024 contained shortened URLs to conceal the true destination of the link
Most affected demographics: adults aged 30–60, smartphone users, and frequent online shoppers.
Sources: FTC Consumer Sentinel Network Data Book 2023; Proofpoint State of the Phish 2024; Ofcom Scam Communications Report 2023; RoboKiller SMS Scam Insights 2024; Enea Mobile Network Security Report 2024
How It Works
How does it work?
Smishing attacks follow a consistent pattern, but the technical methods behind them have become significantly more sophisticated — and more automated — in recent years.
-
The scammer acquires phone numbers — Numbers are obtained through data breaches, purchased from dark web marketplaces, harvested from leaked databases, or simply generated in bulk. A single breach can expose tens of millions of mobile numbers.
-
A lure and impersonation target are chosen — The most common cover stories are parcel delivery failures, unpaid toll charges, bank security alerts, HMRC or IRS tax refunds, and missed court notices. The scammer selects a widely recognised brand to impersonate.
-
A fake website is built — A convincing lookalike of the target organisation's website is constructed, complete with logos, colour schemes, and official-sounding language. It is hosted on a domain designed to look plausible on a small mobile screen (e.g.
royal-mai1-delivery.com). -
The SMS is sent at scale — Using SIM farms, VoIP services, or compromised business messaging accounts, the fraudulent text is sent to thousands or millions of numbers simultaneously. The message contains a shortened or disguised link.
-
The victim taps the link — Believing the message to be genuine, the recipient follows the link and is taken to the fake site, where they are asked to confirm personal details, enter payment card information, or download an app — which may itself be malware.
-
Data is captured or the device is compromised — Submitted information is harvested in real time. If malware is installed, the attacker may gain ongoing access to the device, contacts, banking apps, and stored passwords.
Platforms and tools commonly used: SIM farms, bulk SMS APIs, URL shorteners (Bitly, TinyURL), lookalike domain registration, and mobile-optimised phishing page builders.
Recent variations in 2024–2025:
- Toll road scams surged in early 2024, with the FBI issuing a formal warning after receiving over 60,000 complaints in a single month
- AI-generated smishing now personalises messages using leaked data — including recipient names, postcodes, and recent purchase history — dramatically increasing credibility
- iMessage and RCS exploits allow scammers to bypass carrier-level SMS filtering on some devices
- Callback smishing uses a text to prompt a phone call to a fake customer service line, where a human scammer completes the fraud
Psychological Tactics
What psychological tactics are used?
Smishing is engineered to exploit the way we respond to mobile notifications — quickly, automatically, and without the careful scrutiny we might apply to an email at a desktop computer.
| Tactic | How it is used |
|---|---|
| Urgency | "Your parcel will be returned to sender today unless you act now." A tight deadline forces a snap decision before critical thinking kicks in. |
| Authority | Impersonating Royal Mail, FedEx, HMRC, or your bank creates an immediate compliance reflex — we are used to acting on messages from these institutions. |
| Fear of loss | The threat of a missed delivery, failed payment, or legal fine feels more motivating than the prospect of a reward. Loss aversion is a powerful psychological trigger. |
| Plausibility | Most people are expecting a delivery at any given time. A message about a parcel feels relevant even when sent at random to millions of numbers. |
| Familiarity | Scammers increasingly use your first name, street, or postcode — obtained from previous data breaches — to make the message feel addressed specifically to you. |
| Platform trust | We associate text messages with direct, personal communication. Unlike email, SMS does not have a widely understood spam reputation, so messages feel more credible. |
Mobile devices compound these effects. Small screens truncate sender IDs and URLs. Notifications appear even when we are distracted or multitasking. The combination of cognitive shortcuts and reduced visibility creates ideal conditions for deception.
Real-Life Example
A real-life case
Case: FBI issues national warning as toll road smishing campaign defrauds thousands across the United States (2024)
In early 2024, the FBI's Internet Crime Complaint Center received more than 60,000 complaints in under four weeks relating to a coordinated smishing campaign impersonating state toll collection agencies. Victims received text messages claiming they owed a small unpaid toll — typically between $3 and $12 — with a link to settle the balance and avoid penalties.
The fake sites closely replicated the real portals of E-ZPass, SunPass, and other regional toll operators. Victims who entered their payment card details found their cards subsequently used for fraudulent purchases, with some reporting thousands of dollars in unauthorised charges within hours.
The campaign was traced to a Chinese-language cybercrime toolkit called "Lighthouse," sold as a ready-to-deploy smishing platform on underground forums. The toolkit included pre-built impersonation templates for over 50 US toll agencies, automated SMS sending infrastructure, and real-time credential harvesting dashboards.
The outcome: Thousands of victims suffered financial losses directly. Many more had their card details harvested and sold on, leading to secondary fraud months later. The campaign demonstrated how commercially packaged smishing tools have dramatically lowered the technical barrier for large-scale SMS fraud.
Source: FBI Public Service Announcement I-040524-PSA, April 2024 — ic3.gov; KrebsOnSecurity, "Phishing Texts Impersonate Toll Road Operators," April 2024
Red Flags to Watch
Red flags to watch for
- The message arrives unexpectedly from an unknown or withheld number, or from a sender ID that does not exactly match the real organisation
- It claims there is a problem with a delivery or a small outstanding fee, and asks you to click a link to resolve it urgently
- The link is shortened (e.g. bit.ly, tinyurl.com) or uses a domain that does not match the real organisation's website — look carefully, especially on a mobile screen
- The message uses generic language — "Your parcel," "Your account," "Your vehicle" — with no order reference number, account name, or specific identifying detail
- It asks for payment card details, a bank transfer, or gift card codes via a link rather than through a known official app or website
- The message includes grammatical errors, unusual punctuation, or awkward phrasing inconsistent with official communications
- It threatens an immediate consequence if you do not act — return to sender, legal action, fines, or account suspension — within hours or minutes
- Legitimate organisations you have contacted previously are asking you to re-enter information they already hold
How to Identify
How to identify a smishing message
Ask yourself before acting:
- Am I actually expecting a delivery, or did this message arrive entirely out of the blue?
- Would this organisation contact me via text — and ask me to click a link to resolve a payment or security issue?
- Can I verify this directly through the organisation's official app, website, or customer service number?
Verification steps:
- Do not tap any link in the message. Open your browser and navigate to the organisation's official website by typing the address directly.
- Log in to the courier's or bank's official app to check whether there is actually an issue with your account or delivery.
- Call the organisation using a number found on their official website — not a number provided in the suspicious text.
- Copy the link (without visiting it) and paste it into VirusTotal or Google Transparency Report to check whether it is flagged as malicious.
- Report the message to your national authority (see Further Reading) and then delete it.
Legitimate vs fraudulent — how to tell:
| Legitimate text message | Smishing message |
|---|---|
| Includes your name, order or account reference number | Uses vague language — "your parcel," "your account" |
| Links go to a verified, recognisable domain matching the brand | Links go to a shortened URL or a lookalike domain |
| Never asks for payment details or passwords via a link | Requests card numbers, bank details, or personal data |
| Consistent with previous genuine messages from the same sender | May use a different sender ID, number format, or tone |
| Allows time to respond through multiple channels | Creates immediate pressure to act via a single link |
How to Protect
How to protect yourself
Preventive habits:
- Never tap a link in an unexpected text message — go directly to the organisation's official website or app instead
- Enable spam filtering on your phone: iOS offers "Filter Unknown Senders" in Messages settings; Android devices offer similar controls, and carrier-level filtering is available from most providers
- Register your number with your national do-not-call or spam reporting service to reduce unsolicited contact
- Enable multi-factor authentication (MFA) on banking, shopping, and email accounts — so stolen credentials alone are not enough to access your accounts
- Treat any message requesting payment, even a small amount, with heightened suspicion — legitimate organisations rarely collect fees via a text link
- Keep your phone's operating system and apps updated to patch known security vulnerabilities
If you have already been targeted:
- Do not interact with the message further — do not reply, do not tap the link, and do not call any number it provides
- If you tapped the link or entered any details, contact your bank immediately to freeze your card and report potential fraud
- Change passwords for any accounts that may be affected, starting with email and banking, from a separate, trusted device
- Enable MFA on all affected accounts if not already active
- Report the message to your national cybercrime authority (see Further Reading below)
- Monitor your bank statements and credit file for any unusual activity over the following weeks
Useful tools:
| Tool | What it does | Cost |
|---|---|---|
| Have I Been Pwned | Checks if your phone number or email has appeared in known data breaches | Free |
| VirusTotal | Scans URLs for malware before you visit them | Free |
| Google Safe Browsing | Checks if a website is flagged as dangerous | Free |
| 7726 (SPAM) | Forward suspicious texts to 7726 — the free spam reporting shortcode used in the US, UK, and many other countries | Free |
Video Lesson
Watch: Smishing explained
A clear, accessible explanation of how smishing works, how fraudulent SMS messages are constructed, common lures such as fake delivery notifications and bank alerts, and the steps you can take to protect yourself. Suitable for viewers with no prior cybersecurity knowledge.
Further Reading
Further reading
Official resources
- FBI Internet Crime Complaint Center (IC3) — Report smishing attempts and access the latest cybercrime statistics → ic3.gov
- CISA (Cybersecurity & Infrastructure Security Agency) — Government guidance on recognising and avoiding smishing and mobile fraud → cisa.gov/smishing
- Action Fraud (UK) — Report smishing messages and get advice if you have been targeted → actionfraud.police.uk
- FTC (US Federal Trade Commission) — Report text scams and access consumer guidance on smishing → reportfraud.ftc.gov
Research & reports
- Proofpoint — "State of the Phish 2024" — includes dedicated analysis of smishing trends and mobile phishing volumes → proofpoint.com/state-of-the-phish
- Enea — "Mobile Network Security Report 2024" — detailed breakdown of SMS-based fraud techniques and carrier-level data → enea.com
Investigative coverage
- KrebsOnSecurity — "Phishing Texts Impersonating Toll Road Operators" — in-depth investigation of the 2024 toll smishing campaign and the Lighthouse toolkit → krebsonsecurity.com
Related articles on this platform
- Phishing Email — fraudulent emails impersonating trusted organisations to steal credentials
- Vishing (Voice Phishing) — phone call scams using live or automated voices to deceive victims
- Business Email Compromise (BEC) — phishing that targets payment processes in organisations