Smishing (SMS phishing)
In plain terms
The same trap as phishing, but by text message. The message looks like it's from your bank, and the link leads to a fake page. On a phone, the address is truncated — which is what makes SMS more effective than email for this.
Definition
Smishing is a text-message scam that imitates a trusted organization (often a bank) to push the victim into clicking a fraudulent link or sharing sensitive information.
How it works
The attacker sends a text message that appears to come from your bank, announcing an urgent problem (blocked card, suspicious transfer). The message contains a link to a fake site imitating the bank's interface, where the victim enters their credentials or card code, immediately captured by the attacker. SMS is a particularly favorable medium for the attacker: the link's address is truncated, the sender is just an editable label, and legitimate and fraudulent messages sometimes land in the same conversation thread.
Warning signs
- Unsolicited message announcing an urgent problem
- Shortened link or domain that doesn't match the bank's official site
- Request to enter a password or code from an SMS link
- Very short deadline imposed ("within 30 minutes")
- Message appearing in the same thread as real texts from the bank
How to verify
Never click the link you received. Open your bank's official app or call the number on the back of your card to verify.
What to do
Delete the text. If you have doubts about your account, contact your bank through an official channel, never through the received link.
If it already happened
Immediately contact your bank to block your card or account, change your passwords, and report the scam to the relevant authority.
Test yourself
A text message says your card is blocked and gives you thirty minutes to react.
Start the simulationFrequently asked questions
- The text appeared in the same conversation as my bank's real messages — how is that possible?
- Yes, it's possible. The sender name shown for a text message is just a label, which can be chosen by the sender. Two messages carrying the same label get grouped by the phone, placing the fraudulent message right among the real ones. A message's position in a thread proves nothing.
- Should I reply STOP to avoid being contacted again?
- No. Replying confirms the number is active and being read, which increases the number of messages received afterward. Delete the message and report it through your carrier's fraud-reporting channel if you want to flag it.
Related attacks
Official sources
This article is part of the Social engineering family. Last updated: 2026-08-31.