Home
Blog
Smishing Text Message Scams: How to Spot Them, Verify Suspicious Texts, and Report Them

Smishing Text Message Scams: How to Spot Them, Verify Suspicious Texts, and Report Them

Reviewed by
Table of Contents

Key Takeaways

You get a text saying your package is stuck at a depot and you need to confirm your address. Or your bank flags an unauthorized charge and asks you to verify your card number. Both sound urgent. Both feel real.

Neither one is.

Smishing, SMS phishing, has quietly become one of the most effective scams running right now. Consumers lost $470 million to text message scams in 2024 alone, according to FTC data reported by Cybernews. That's five times the amount reported in 2020. The messages haven't changed much, but the volume has exploded, RoboKiller estimates Americans received 19.2 billion spam texts in December 2023 alone, which works out to roughly 63 per person.

Spotting a smishing text is only part of the problem. The harder questions are what to do next. Do you click to investigate? Call the number? Ignore it? This guide walks through all three steps: how to recognize a smishing text, how to verify it without putting yourself at risk, and how to report it so it doesn't keep catching other people.

What smishing actually is (and why it works)

Smishing is a type of phishing attack delivered over SMS. The mechanics are simple: a scammer sends a text impersonating a trusted source, a delivery company, your bank, a government agency, or even your employer, and tries to get you to either click a link or hand over personal information.

What makes it effective isn't technical sophistication. It's psychological pressure. Smishing texts tend to create a sense of urgency. Your package won't arrive. Your account is frozen. You owe a fine and have 24 hours. That urgency short-circuits the instinct to stop and think.

Text messages also feel more personal than email. You share your number with fewer people, so a text from an unknown sender triggers less suspicion than an unsolicited email. And unlike email, there's no spam folder catching bad messages before they reach you.

According to the US Postal Inspection Service, smishing scammers often disguise themselves as government agencies, banks, or well-known companies specifically to borrow credibility. The more familiar the name, the more likely you are to comply.

The most common smishing texts right now

The FTC's 2024 data identified a few recurring formats. Knowing what the playbook looks like helps.

Fake package delivery alerts are the most common. A text claims a delivery failed or requires action on your part, usually a small fee or address confirmation via a link. USPS, FedEx, and UPS are routinely impersonated. The real USPS will never send you a link in a tracking text unless you requested it.

Fake bank fraud alerts impersonate your financial institution, warning of a suspicious charge and asking you to verify your account. Banks don't ask for card numbers or PINs over text.

Task scams are newer. Someone texts offering you easy online work, liking videos, rating products, then eventually pressures you to invest your own money to unlock your earnings. The FTC flagged these specifically in its 2024 consumer alerts.

"Wrong number" messages start innocent. Someone texts the wrong contact, you respond, a friendly conversation begins, and eventually it steers toward a scam, often a fake investment opportunity or romance fraud.

Government impersonation texts claim you owe a toll road fee, have an unpaid tax bill, or need to verify your Social Security number. Government agencies don't initiate contact over text.

How to spot a smishing text: the warning signs

Most smishing texts share a few telling characteristics. None of them is proof on its own, but two or three together should put you on alert.

  • You didn't initiate the contact. A text from your bank about a transaction you didn't make, or from a courier about a package you didn't order, is a red flag by default.
  • It creates pressure to act quickly. Real organizations give you time to respond. Urgency is a manipulation tool.
  • The link looks strange. Shortened URLs, strings of random characters, or a domain that's almost-but-not-quite right (think usps-delivery-notice.com instead of usps.com) are common.
  • It asks for sensitive information. Legitimate businesses don't request account numbers, passwords, PINs, or Social Security numbers via text.
  • The sender's number is unfamiliar. Scammers sometimes spoof real numbers, but many use random strings of digits or international numbers.
  • Don't rely on spelling or grammar to give it away. Scam texts used to be full of typos, but many are now polished and professional-sounding. A clean, error-free message can still be a scam, so weigh it alongside the other signs above.

One thing to keep in mind: even if only one of these applies, don't click the link to investigate. That's the riskiest move you can make.

How to verify a suspicious text without clicking anything

This is where most people make a mistake. They click the link "just to check", and that's often enough for the scammer to log your device or redirect you to a credential-harvesting page.

The safer way to verify is to go around the text entirely.

Go directly to the official source. If a text claims to be from your bank, close the message and open your bank's official app or type the bank's real URL into your browser. Log in there and check for any actual alerts. If something was really wrong, it'll show up in your account.

Call the organization using a number you find independently. Don't call a number provided in the suspicious text. Look it up on the organization's official website or on the back of your credit or debit card.

Check your real tracking info. If the text claims to be from USPS, FedEx, or UPS, go to the carrier's official website and enter your tracking number there. You'll immediately see whether there's a real issue.

Search the message text online. Paste a portion of the message into a search engine. Scam messages tend to circulate widely, and you'll often find other people reporting the exact same one.

The CISA recommends exactly this approach: if a message looks suspicious, go directly to the organization's verified website and pull contact information from there, not from the message itself.

What to do if you already clicked

It happens. You clicked a link before you realized what it was. Here's what to do.

Don't enter any information on the page that opened. Even if it looks completely real, close it immediately.

Notify your financial institution. The US Postal Inspection Service recommends doing this even if you didn't submit anything on the page, because some pages collect device data on load. Your bank can monitor for unusual activity.

Change passwords for any accounts that may be at risk. If the scam was impersonating your bank or email provider, change those passwords from a separate, trusted device.

Run a security scan on your device. Some smishing links attempt to install malware. A security tool that scans your phone and computer can catch anything that made it through.

Monitor your credit. If you entered any personal information, consider placing a fraud alert or credit freeze with the major credit bureaus.

How to report smishing texts

Reporting takes about two minutes and genuinely helps. Reports feed into databases used by carriers, law enforcement, and government agencies to identify patterns and shut down active scam operations.

Here's where to send them:

  • Forward the text to 7726 (SPAM). This shortcode works across most major US carriers. Forwarding the message sends the sender's number to your carrier for review.
  • Report to the FTC at [ReportFraud.ftc.gov](https://reportfraud.ftc.gov). The FTC uses these reports to identify active fraud trends and take enforcement action.
  • File a complaint with the FBI's Internet Crime Complaint Center at [ic3.gov](https://www.ic3.gov/complaint). Particularly useful if you lost money or shared financial information.
  • For USPS-related smishing, email spam@uspis.gov. Include the text of the message, the sender's number, and a screenshot.
  • Report it to the impersonated company. Banks, delivery companies, and retailers have fraud teams watching for this.

The FCC recommends contacting the sender's company directly so they can alert others and work with law enforcement.

How to protect yourself going forward

A few habits reduce the chances of being caught out again.

Don't respond to unknown senders, even to opt out. Replying confirms your number is active and often leads to more messages. Turn on your phone's built-in spam filtering if it has one, both iOS and Android offer this. Be cautious about where your phone number gets shared; data breaches and third-party apps are common sources for the lists scammers use.

If you want a more proactive layer of protection, Guardio can help on two fronts. On iOS, Guardio's Text Message Filter automatically routes malicious texts to your junk folder before you ever see them. And on both phone and computer, Guardio's browsing protection checks links in real time and blocks malicious URLs, including ones buried in smishing texts, so even if you do click, the threat is stopped before it reaches you.

Conclusion

Smishing works because it's fast, familiar, and built to slip past your instincts. The good news is the countermeasures are just as straightforward: slow down, verify independently, and report what you see. Two minutes spent forwarding a text to 7726 and filing a report at ReportFraud.ftc.gov isn't just protecting yourself, it's feeding the system that helps catch these operations before they reach the next person.

Get a free security scan with Guardio today and stay protected from smishing and other scams, on your phone and in your browser.

CMS-based CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
Default CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
CMS-based "Did you know?" block
Did you know?
Default "Did you know?" block
Did you know?

Make sure you have a personal safety plan in place. If you believe someone is stalking you online and may be putting you at risk of harm, don’t remove suspicious apps or confront the stalker without a plan. The Coalition Against Stalkerware provides a list of resources for anyone dealing with online stalking, monitoring, and harassment.

Guardio Security Team
Guardio’s Security Team researches and exposes cyber threats, keeping millions of users safe online. Their findings have been featured by Fox News, The Washington Post, Bleeping Computer, and The Hacker News, making the web safer — one threat at a time.
Tips from the expert

Related articles

FAQs

What is smishing?

Smishing is a form of phishing that uses text messages rather than email. Scammers impersonate trusted organizations, banks, delivery companies, government agencies, to trick you into clicking a link or handing over personal information.

How can I tell if a text is a smishing scam?

Common signs include unexpected contact from a company you didn't reach out to, a link with an unfamiliar or odd-looking domain, urgency or threats, and requests for sensitive information. Spelling and grammar are no longer reliable tells, since many scam texts read cleanly now. When in doubt, don't click, go directly to the organization's official website instead.

What should I do if I click a link in a smishing text?

Close the page immediately without entering any information. Then notify your bank, change passwords for relevant accounts, run a security scan on your device, and monitor your credit for unusual activity.

How do I report a smishing text?

Forward it to 7726 (SPAM) via your messaging app. You can also file a report with the FTC at ReportFraud.ftc.gov, with the FBI at ic3.gov, or, if it impersonates USPS, by emailing spam@uspis.gov.

Can smishing texts install malware just by clicking the link?

Yes, some links are set up to automatically download malware when opened, without requiring you to enter any information. This is why clicking 'just to see' is never safe.

Why are smishing scams increasing?

Text messaging has higher open rates than email and fewer built-in filters. Scammers have also adopted tools that make it easy to send messages at massive scale, RoboKiller tracked 19.2 billion spam texts in a single month in the US alone.

Is it safe to text back to tell the sender to stop?

No. Responding confirms your number is active and often results in more messages. Block the number and report it instead.

What are the most common types of smishing text scams?

The FTC's 2024 data named fake package delivery alerts, bank fraud alerts, task scams promising easy online work, and 'wrong number' messages that evolve into romance or investment scams as the most reported types.

Table of Contents
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now