How to Recognize and Avoid Smishing (SMS Phishing) Texts

Tap an item for practical ways to spot a smishing text before it costs you anything.

What smishing (SMS phishing) is

Smishing combines "SMS" and "phishing": a scam that plants a malicious link in a text message to steal personal or financial information, or trick you into installing a malicious app.

The classic delivery and government-agency impersonation pattern

Texts like "track your package," "unpaid fine notice," or "benefit refund available" imitate ordinary, believable messages specifically to get you to tap the link inside.

Why a shortened link deserves extra suspicion

A shortened URL hides where it actually leads, so it's hard to tell you're being sent to a malicious site until it's too late β€” treat any shortened link arriving by text with real caution.

How to report a suspected smishing text

Use your phone's built-in spam-report feature for a suspicious text, or report it to your carrier or your country's cybercrime and consumer-fraud reporting line.

Be wary of a text pushing you to install an app

A text link that asks you to install an app file directly, outside your phone's official app store, is very likely malicious and should never be installed.

Call the organization directly to confirm

If a text looks suspicious, don't call the number written in the message β€” look up the organization's official phone number on its real website and call that instead to confirm whether it's genuine.

How one text message starts real damage

Since checking texts has become a constant, everyday habit on a smartphone, smishing blends into that routine naturally. Because it mimics common, believable content like a delivery notice or a government message, building the habit of checking the link and sender number matters.

A shortened link is harder to inspect on a small screen

A phone's screen leaves little room to preview a full web address before tapping, which is exactly why a shortened or truncated link is riskier on mobile than on a desktop browser. When in doubt, don't tap the link at all β€” open the organization's official app or type its known web address in manually instead.

Frequently Asked Questions

Is it dangerous just to open a smishing text?

Simply reading the text is generally safe. The real risk comes from tapping the link inside or installing an attached file, which can lead to malware infection or a data leak.

What should I do if I already tapped a smishing link?

Turn off mobile data and Wi-Fi right away, uninstall any suspicious app you may have installed, run a security scan, and change the passwords on your important accounts.