Skip to content
Independent consumer protection publication Educational guidance — not legal or financial advice

Protection Guide

Smishing Scam Examples: How to Spot Fraudulent Text Messages

Last updated: July 13, 2026 by the ScamReporting Editorial Team. We revise guides when scam tactics change, agencies issue new advisories, or readers report outdated steps. Editorial policy & corrections.

July 2026 update: Our editors refreshed this guide based on recent FTC advisories and reader reports. See the latest alerts and weekly digest.

Daily editor note (Jul 13, 2026): We added a quick reminder based on the fraud patterns reported to us this week. See our latest alerts.

Daily editor note (Jul 3, 2026): We added a quick reminder based on the fraud patterns reported to us this week. See our latest alerts.

Phishing & smishing protection hub: Primary guide for fraudulent texts and links. Deep dive: how phishing scams work · QR code phishing.

Smishing (SMS phishing) sends fraudulent text messages to steal credentials, install malware, or trick you into sending money. Smishing volume surged in 2026 as consumers trust texts more than email.

Common Smishing Scam Examples

1. Package delivery scams

“USPS: Your package is held — pay $1.99 re-delivery fee.” Links to a fake payment page harvesting card data.

2. Bank fraud alerts

“Chase: Did you approve a $2,400 Zelle transfer? Reply YES or call this number.” Leads to Zelle refund trick social engineering.

3. Toll road / parking fines

“Pay your outstanding toll within 24 hours to avoid penalty.” Targets drivers with urgency.

4. Job interview texts

“Your resume was selected — click to schedule interview.” Collects personal data or installs spyware.

5. Two-factor code phishing

“Your verification code is 847291 — reply to confirm account.” Scammer is logging into your account and needs your OTP.

Smishing Text Scam Signs — educational infographic
Open apps directly — never tap links in unsolicited texts.

Smishing Red Flags

  • Unexpected texts from unknown short codes or numbers
  • Links using URL shorteners (bit.ly, tinyurl)
  • Urgent deadlines (“24 hours,” “account suspended”)
  • Requests to reply with personal info or verification codes
  • Poor grammar or mismatched sender name vs. link domain

What to Do If You Receive a Smishing Text

  1. Do not click links or call numbers in the message
  2. Delete the text and block the sender
  3. Verify independently via the official app or website typed manually
  4. Never share OTP codes — your bank will never text asking for them
  5. Report by forwarding to 7726 (SPAM) in the US

If You Clicked a Smishing Link

  1. Disconnect from WiFi if you entered credentials
  2. Change passwords from a clean device
  3. Enable 2FA on affected accounts
  4. Monitor bank and credit card statements
  5. Report at ScamReporting.org

Related: Phishing scams guide | QR code scams | Stay safe tips

Last reviewed: July 2026.

Reported the Text? Report the Website and Sender Too

A smishing text usually points to a fraudulent site. After you delete the message, take the reporting a step further:

Frequently Asked Questions

What is smishing?

Smishing is phishing via SMS text message — fraudulent texts with malicious links or requests for personal information.

Should I reply STOP to scam texts?

Replying can confirm your number is active. Block and report instead.

How do I report scam text messages?

Forward to 7726 (SPAM) in the US, report to the FTC, and ScamReporting.org.

Related Phishing Guides

Was this guide helpful?

Your feedback helps us prioritize updates. We do not collect any personal data.