A smishing scam — “SMS phishing” — is a fraud carried out through text messages. Your phone buzzes with what looks like an urgent alert: a package that can’t be delivered, suspicious activity on your bank account, an unpaid toll. The message includes a link or a number to call. But the sender isn’t your bank, the post office, or the toll authority — it’s a criminal, and the link leads to a trap designed to steal your money or your identity.
Text-message scams are among the most reported frauds in the United States. The FTC reports that people lost $470 million to text scams in 2024 alone — more than five times the 2020 figure. And the FBI’s Internet Crime Complaint Center found that phishing and spoofing (which includes smishing) was the single most-reported cybercrime type in 2024, with 193,407 complaints. Here’s how these scams work and how to see through them.
What Is a Smishing Scam?
Smishing is phishing delivered by SMS (or messaging apps). Like email phishing, its goal is to get you to hand over sensitive information — passwords, account numbers, Social Security numbers, card details — or to install malware on your phone. The FTC describes the core trick: scammers send fake text messages to trick you into giving them personal information, promising prizes or help on the one hand, or inventing account problems and fake invoices on the other.
Smishing works because texts feel personal and urgent. Most people open a text within minutes, and a message that appears to come from a familiar brand short-circuits our skepticism.
The Most Common Smishing Scams (FTC’s 2024 Data)
The FTC analyzed 2024 text-fraud reports and identified five dominant types, estimated to account for about half of all reported text frauds:
1. Fake package delivery problems
The most reported text scam of 2024. Messages — usually impersonating the US Postal Service — claim there’s a problem with a delivery and link to a website that looks like the real USPS site but isn’t. Victims are asked to pay a small “redelivery fee,” which is really a trick to capture their credit card or even Social Security number. The FTC warns that a text claiming to be from USPS, FedEx, or DHL about unpaid postage or a missed delivery is very likely from a scammer: the click takes you to a look-alike site where anything you enter goes straight to the criminal.
2. Phony job opportunities and “task scams”
A newer wave: unexpected texts offering vague work — rating products or apps for easy money. Victims are eventually told to send money to “unlock” their earnings, and never see it again. If you didn’t apply for a job, a recruiter texting you out of the blue is a red flag.
3. Fake fraud alerts
Texts about “suspicious activity” or a large purchase you didn’t make, often appearing to come from your bank or Amazon. They ask you to reply YES/NO or call a number, connecting you to a fake “fraud department” that pressures you into moving money “to keep it safe” — straight to the scammers. The FTC notes these operations quickly escalate, claiming all your money is at risk.
4. Bogus unpaid toll notices
Texts impersonating highway toll programs (SunPass, FasTrak, and others) demanding payment for an unpaid balance via a link. Neither the charges nor the message are real; the goal is your card and personal details.
5. “Wrong number” texts that lead to investment scams
An innocent-looking “hello” or “do you want to get coffee?” starts a friendly conversation — sometimes with romantic undertones — that pivots to “successful investing” on a bogus platform. Victims report losing tens of thousands of dollars.
URL Tricks: How Scammers Make Links Look Legitimate
Before you ever tap a link, know the disguises:
- Look-alike domains:
usps-track-package.cominstead ofusps.com, or subtle misspellings (arnazon,fedexx). Always read the domain carefully — scammers register convincing fakes. - URL shorteners: A
bit.lyort.lylink hides the real destination entirely. Legitimate companies rarely send shortened links for account or payment matters. - Odd top-level domains: Be wary of
.top,.xyz,.vip, or other unusual endings on a message claiming to be from a major brand or government agency. - HTTP instead of HTTPS, or long confusing paths: Extra subdomains like
usps.delivery-update.secure-login.comare designed to put a trusted word where you’ll notice it while the real domain is something else entirely. - Spoofed sender names: The “sender” field on a text can be faked, so a message labeled “USPS” or your bank’s name proves nothing by itself.
The safest rule, per the FTC: never click links in unexpected texts, period. If you think the message might relate to something real, open the company’s official app or type its website address yourself.
Red Flags: Smishing Scam Checklist
Check any suspicious text against this list:
- It’s unexpected — you weren’t waiting for a delivery, didn’t enter a contest, and don’t owe a toll.
- It creates urgency — “act now,” “account suspended,” “final notice,” “package will be returned today.”
- It contains a link or a callback number — especially shortened URLs or numbers you don’t recognize.
- It asks for personal or financial information — account numbers, passwords, card details, Social Security number. The FTC is explicit: legitimate companies won’t ask for account information by text.
- It promises something free or too good to be true — gift cards, prizes, low-interest credit cards, loan help you never requested.
- It threatens consequences — frozen accounts, legal action, missed deliveries.
- The sender is a random long number or email address — or a brand name you can’t verify.
- Grammar, spelling, or formatting feels off — though note that many smishing texts are now well-written, so clean copy doesn’t mean safe.
- It asks you to reply, even “STOP” — replying confirms your number is active and can invite more scam attempts.
One red flag is enough to treat the message as suspicious.
How to Verify Any Suspicious Message Safely
Never use the contact details in the message itself. Instead:
- Go direct. Open the company’s official app or type its official website address into your browser. Log in and check for alerts, tracking info, or account notices there.
- Call a number you trust. For banks, use the number on the back of your card. For deliveries, use the tracking number from the retailer’s own site or your order confirmation email — not the text.
- Check the real policy. For example, the real USPS won’t text you out of the blue about a delivery (unless you requested tracking updates) and will never demand payment to redeliver a package.
- Search the message text. Paste a distinctive phrase into a search engine with the word “scam” — if it’s a known campaign, others have likely reported it.
- When in doubt, do nothing. Delete the message. A legitimate company will reach you through official channels about anything truly important.
What to Do If You Already Clicked or Replied
Don’t panic — act methodically:
- Only tapped the link, entered nothing? Your immediate risk is low, but don’t enter anything. Close the page, and consider running a security scan on an Android device.
- Entered a password? Change it immediately from a trusted device — and change it everywhere else you reused it. Turn on two-factor authentication (preferably an authenticator app, not SMS codes).
- Entered card or bank details? Call your bank or card issuer right away using the number on your card. Ask about freezing the card and disputing charges.
- Sent money or gift card codes? Contact your bank immediately and report to the FTC and FBI’s IC3 — recovery is hardest here, so speed matters.
How to Report a Smishing Scam
Reporting helps carriers and law enforcement shut these operations down:
- Forward the text to 7726 (SPAM). This alerts your wireless provider and helps it block similar messages.
- Report in your messaging app. Both iPhone Messages and Android’s Google Messages let you report spam or junk directly.
- Report to the FTC at ReportFraud.ftc.gov.
- Report to the FBI’s IC3 at ic3.gov, especially if you lost money or the text impersonated a government agency.
- For USPS impersonation specifically, the Postal Inspection Service also accepts reports — and never engage with the sender.
The FTC’s standing advice is simple: never click links or respond to unexpected texts. If it might be legitimate, contact the company through a channel you know is real.
The Bottom Line on Smishing Scams
A smishing scam succeeds by borrowing trust — your bank’s name, the post office’s logo, a toll authority’s branding — and adding urgency. The defense is equally simple and always works: don’t click, don’t reply, verify through the official app or website, then report and delete. Make that your reflex, and smishing loses its power over you.
Sources
- Federal Trade Commission, “Top text scams of 2024” (Data Spotlight, April 2025) — http://www.ftc.gov/news-events/data-visualizations/data-spotlight/2025/04/top-text-scams-2024
- Federal Trade Commission, “How to Recognize and Report Spam Text Messages” — https://consumer.ftc.gov/articles/how-recognize-and-report-spam-text-messages
- Federal Trade Commission, “Think that text message is from USPS? It could be a scam” (April 2025) — https://consumer.ftc.gov/consumer-alerts/2025/04/think-text-message-usps-it-could-be-scam
- FBI Internet Crime Complaint Center, “2024 Internet Crime Report” — https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
Last reviewed: October 2026
This article is for education only and is not financial or legal advice.