Smishing is phishing conducted over text message: a fraudulent SMS designed to trick the recipient into revealing sensitive information, clicking a malicious link, or sending money, typically by impersonating a trusted organization such as a bank, delivery service, government agency, or employer. The name is a blend of "SMS" and "phishing," and the technique works for the same reason legitimate texting works: people read texts quickly and tend to trust them.
The Federal Trade Commission (FTC), the Federal Communications Commission (FCC), and the FBI's Internet Crime Complaint Center (IC3) all publish standing warnings about smishing, and the toll-package scam or "wrong number" opener has probably visited your own phone. This guide defines smishing precisely, catalogs the common forms, gives the red-flag checklist and reporting steps, and covers the flip side: how legitimate organizations should text so their messages never resemble the scams.
Key takeaways:
- Smishing is social engineering by SMS: impersonation plus urgency plus a link or request, aimed at credentials, payment data, or direct payment.
- The dominant patterns impersonate deliveries, banks, government agencies, employers, and tech platforms, or open with a friendly "wrong number" text that grows into a fraud relationship.
- The universal defense is out-of-band verification: never act on the message itself; contact the organization through a channel you already know.
- Report smishing by forwarding to 7726 (SPAM), reporting at ReportFraud.ftc.gov, and, for losses, filing with the FBI at ic3.gov.
How smishing works
Nearly every smishing message assembles the same four parts:
- Impersonation. The sender claims to be an entity you plausibly deal with: a national bank, a package carrier, a toll authority, the IRS, your employer's CEO, a streaming service.
- A pretext with urgency. Something is wrong or time-limited: a package held, an account locked, an unpaid toll, a fraud alert, a prize expiring. Urgency is the engineering; it is there to beat your reflection.
- The hook. A link to a counterfeit login or payment page, a number to call staffed by the scammer, or a direct request (gift cards, wire transfer, "verification" codes).
- The harvest. Credentials get used or sold; card data gets drained; one-time passcodes let the attacker into real accounts; small "toll" payments capture card numbers for larger fraud.
Two structural details make SMS attractive to attackers: link previews are minimal (a shortened or look-alike URL is harder to inspect on a phone), and sender identity is weakly presented (a bare number, or an alphanumeric label, with no verified branding in standard SMS).
The common species of smishing
| Pattern | Typical message | The tell |
|---|---|---|
| Delivery scam | "Your package could not be delivered. Confirm your address: [link]" | You are not expecting anything, or the link is not the carrier's domain |
| Bank or fraud alert | "Suspicious charge detected. Verify your account now: [link]" | Banks do not ask for credentials or full card numbers by text |
| Toll or fee scam | "Unpaid toll balance. Pay now to avoid penalties: [link]" | Mass-sent regardless of whether you drove anywhere; odd domains |
| Government impersonation | "IRS: your refund is on hold" or benefits suspension threats | The IRS states it does not initiate contact by text about refunds or penalties |
| Boss or gift-card scam | "Are you free? I need a favor. It's urgent." (then: buy gift cards) | New number, urgency, secrecy, unusual payment method |
| Verification-code theft | "Your code is 123456" followed by "we sent you a code, please read it back" | Anyone asking you to share a one-time code is the attack itself |
| Wrong-number romance or investment | "Hi, is this Sarah? Sorry, wrong number! You seem nice..." | Strangers cultivating conversation that drifts toward investments or crypto |
The red-flag checklist
Run any suspicious text against these questions:
- Did I expect this? Unprompted contact about accounts, packages, or payments is the number-one flag.
- Is it pushing urgency or fear? Deadlines measured in hours, threats of arrest, suspension, or loss.
- Where does the link actually go? Look for misspelled or look-alike domains, extra words, or URL shorteners hiding the destination. When in doubt, do not tap.
- Is it asking for what no legitimate sender requests by text? Passwords, full card or Social Security numbers, one-time codes, gift cards, wire transfers, or crypto payments.
- Does the sender check out? Real organizations text from consistent, often short-code, numbers you can verify on their website; scammers rotate random numbers and email-style addresses.
And the one behavior that defeats nearly all of it: verify out of band. If the message claims to be your bank, call the number on your card. If it claims to be a carrier, open the carrier's app or type its website yourself. Never use the phone number or link the message provides; the message is the only thing the attacker controls.
If you get one, and if you fell for one
Reporting a smishing text:
- Forward the message to 7726 (spells SPAM), the carrier-industry reporting service, which helps networks block the sender.
- Report it to the FTC at ReportFraud.ftc.gov; the FTC also maintains consumer guidance on recognizing text scams.
- If money was lost or accounts compromised, file a complaint with the FBI's Internet Crime Complaint Center at ic3.gov.
- Use your messaging app's report-junk feature, then delete the message. Do not reply, even "STOP", to an obvious scam; replies confirm the number is live.
If you already clicked or paid: change the affected passwords immediately (and anywhere they were reused), enable multi-factor authentication, contact your bank or card issuer to dispute and reissue, place a fraud alert or credit freeze with the credit bureaus if identity data was exposed, and report as above. Speed limits the damage.
The organizational flip side: texting without looking like a scam
Every smishing wave erodes trust in legitimate messages, so organizations that text, clinics, schools, nonprofits, agencies, businesses, carry a share of the defense. The practices that separate real messages from scams are the same ones the industry codifies:
- Send from registered, consistent numbers. US organizational traffic runs on registered routes (10DLC and verified toll-free) under CTIA guidelines, and recipients learn your number.
- Identify yourself in every message, and never rely on the recipient guessing.
- Text only people who opted in, under the Telephone Consumer Protection Act (TCPA, 47 U.S.C. 227), and honor STOP instantly. Scammers cannot replicate a consent relationship.
- Link predictably. Use your own domain, announced in advance ("links from us will always be fransis.ai") and skip URL shorteners that hide destinations.
- Never ask for sensitive data by text. Payment happens on your secure site; codes are never requested back; staff never ask for passwords. Publish these rules to your audience so deviations read as fraud.
- Prepare an impersonation response: if scammers spoof your brand, warn your list from your known number, post guidance on your site, and report the campaign.
Platform-level protections, access controls, audit trails, and encryption of data in transit and at rest, sit underneath these practices; the enterprise SMS security guide covers that layer, and the deliverability guide explains how carrier filtering fights bulk abuse. Details of the platform trust model live on our security page.
Frequently asked questions
What is smishing in simple terms?
Smishing is phishing by text message: a scam SMS that impersonates a trusted organization and uses urgency to push you into clicking a malicious link, revealing credentials or codes, or sending money. The name combines "SMS" and "phishing."
What are the most common smishing scams?
Fake delivery notices, bank fraud alerts, unpaid-toll demands, government impersonation (IRS, benefits), boss-needs-gift-cards messages, requests to share one-time verification codes, and "wrong number" texts that build toward investment or romance fraud.
How can you tell if a text is smishing?
Check for the pattern: unexpected contact, urgency or threats, a suspicious link or unusual payment request, and demands for information no legitimate sender requests by text. Verify any claim through a channel you already trust, the number on your card, the official app, never through the message itself.
How do I report smishing texts?
Forward the text to 7726 (SPAM) so carriers can block the sender, report it to the FTC at ReportFraud.ftc.gov, and file with the FBI's IC3 at ic3.gov if you lost money or data. Then report as junk in your messaging app and delete without replying.
How do legitimate organizations avoid looking like smishing?
By texting only opted-in recipients from registered, consistent numbers, identifying themselves in every message, linking only to their own announced domain, never requesting sensitive data by text, and honoring STOP instantly, practices required by the TCPA and CTIA guidelines and visible to recipients.
Conclusion
Smishing is old-fashioned confidence fraud wearing text messaging's trusted clothes, and the defense is correspondingly old-fashioned: slow down, verify through channels you already know, and report what you catch. For organizations, the lesson is symmetrical, trust is the whole asset. Text with consent, consistency, and restraint, and your messages stay recognizable as the real thing in an inbox where the fakes keep coming.
Building a texting program your audience can trust on sight? Contact the FRANSiS team to see verified organizational messaging with consent, security, and compliance handled by design.


