← All resources
Guide

Smishing: how to spot fake text-message scams

That “missed delivery” text or “suspicious bank login” alert may be a scam called smishing. Text-based attacks are surging — here’s how to recognise them and what to do.

Guide · 5 min read · By SafeToOpen Research · June 2026

Smishing — phishing by SMS — is one of the fastest-growing scam channels. As people got warier of email, attackers moved to text, where messages feel personal and urgent and the small screen hides the warning signs. Recent reporting shows smishing up around 40% and over a third of phishing now arriving via SMS or messaging apps. [1]

~40%
Growth in smishing (SMS phishing) in recent reporting; 35% of phishing now uses SMS or messaging apps. [1]

The texts to watch for

Why texts are so effective

On a phone, the full web address is usually hidden, so a fake link is harder to inspect than on a computer. Texts also feel more immediate and personal than email, and link shorteners hide the true destination entirely. Attackers know that switching you from a big screen to a small one makes the signs of a scam harder to spot.

How to handle a suspicious text

  1. Don’t tap the link. If it claims to be your bank or a courier, open their official app or type their website yourself.
  2. Don’t reply — not even “STOP.” A reply confirms your number is live and reachable.
  3. Never share a one-time code. No real company will text and then ask you to read back your verification code.
  4. Check the number, but don’t trust it. Caller ID and sender IDs are easily spoofed.
  5. Report and delete. In many countries you can forward spam texts to 7726 (SPAM). Then delete it.

When you’re not sure

Plenty of texts sit in a grey area — it might be your bank. The safe habit is never to act through the text itself: go to the source independently. And remember that a smishing link leads to the same kind of fake web page as any other phishing attack — so protection that inspects pages in your browser still helps once a link is opened.

Protection that follows the link

If a text link opens in your browser, SafeToOpen Browser Security inspects the page and blocks it if it’s a fake — before you enter anything.

How Browser Security works →

The takeaway

Smishing trades on urgency and the blind spots of a small screen. Don’t tap links, don’t reply, never share one-time codes, and always reach companies through their official app or site — not the text. Treat an unexpected text exactly as you’d treat an unexpected email.

See it for yourself

SafeToOpen blocks fake and malicious pages in your browser — free to start.

See plans →

Sources

  1. Phishing channel statistics (smishing +40%, 35% of phishing via SMS/messaging), cited in StationX. stationx.net

External statistics are attributed to their original publishers and were accurate at the time of writing. Figures from industry reports vary by methodology and period; we link to primary sources so you can verify them.