“Your package couldn’t be delivered — click here.” “Suspicious activity on your bank account, verify now.” “You owe an unpaid toll.” These texts are designed to make you panic and tap before you think, and one tap can hand a scammer your passwords or your money. The good news: phishing texts follow a pattern, and once you can spot it, they’re easy to ignore. Here’s how.
What “smishing” is after
Phishing by text (sometimes called “smishing”) wants one of two things: to get you to tap a link that leads to a fake login page that steals your password, or to get you to reply with information — a code, a card number, personal details. It works by impersonating someone you trust (your bank, a delivery service, the government, even your own boss) and adding urgency so you act on reflex.
Distrust urgency and threats
The number-one red flag is pressure: “Act now,” “Your account will be closed,” “Final notice,” “You’ll be arrested.” Real institutions rarely threaten you by text to act within minutes. That manufactured panic is the whole tool — it’s meant to shove you past the moment where you’d normally stop and think.
Inspect the link without tapping it
Look at the actual web address. Scammers use lookalikes: amaz0n-support.com, usps-redelivery.net, or random shortened links. The real company’s site is a clean domain (amazon.com), not a jumble with extra words, hyphens, or a weird ending. When in doubt, don’t tap — go to the company’s app or type its real address yourself.
The golden rule: never click a link or call a number from an unexpected text. If “your bank” texts about a problem, open your bank’s official app or call the number on the back of your card — not anything the text provides. Contacting them through a channel you chose defeats the entire scam.
Notice the other tells
Watch for a generic greeting (“Dear customer” instead of your name), odd grammar or spelling, a message from a random personal phone number or email claiming to be a big company, and requests for information the company already has. Any one of these should make you suspicious; two or more is a near-certain scam.
Never share codes, passwords, or card numbers by text
No legitimate company will text you asking for your password, full card number, SSN, or a one-time verification code. That last one is huge: scammers who already have your password will trigger a login and then text you pretending to be the company to get the code that lets them in. Your bank will never ask you to “read back” a code — anyone who does is trying to hijack your account.
Verify independently, then report and delete
If a text might be real (a delivery, a bill), confirm through the official app or website you already use — check your real order history or account. If it’s a scam, don’t reply (even “STOP” tells them the number is live). Forward it to 7726 (SPAM) to report it to carriers, report to the FTC, then delete and block. Replying or tapping only marks you as a target for more.
If you did tap a link and enter a password, act fast: change that password immediately (and anywhere you reused it), turn on two-factor authentication, and watch the account for fraud. If you shared card or bank details, call your bank to freeze or reissue. Quick action limits the damage.
Build a safety net before you’re targeted
The strongest protection is set up before a phishing attempt, so that even a stolen password isn’t enough. Turn on two-factor authentication on your email, bank, and important accounts — ideally with an authenticator app rather than text codes, since codes can be phished. Use a password manager so every account has a unique password; then one leaked password can’t unlock the rest of your life. And treat your email account as the crown jewel: it’s the reset button for everything else, so give it your longest password and strongest 2FA. With these in place, a scammer who tricks one password out of you still hits a locked door — which turns a potential disaster into a minor “change that password” chore.
Phishing texts weaponize urgency to make you tap without thinking. Distrust threats and deadlines, inspect links without clicking, and never share passwords, card numbers, or one-time codes by text. When a message claims to be your bank or a delivery service, verify through the official app or a number you look up yourself — never through the text. Forward scams to 7726, then block and delete.
Quick questions
Is it dangerous just to open the text?
Opening and reading a text is generally safe — the danger is tapping links, replying, or calling numbers in it. Don’t interact; just inspect, then delete.
They already know my name — is it real?
Not necessarily. Data breaches leak names, emails, and phone numbers constantly, so scammers often personalize messages. A correct name doesn’t make a suspicious link or urgent demand legitimate.
What does forwarding to 7726 do?
It reports the spam text to your mobile carrier so they can investigate and block similar messages. It’s free and takes seconds — a small step that helps shut scammers down.
I clicked the link but didn’t enter anything — am I okay?
Usually yes; the real risk is entering credentials or installing something. To be safe, don’t enter any info, close the page, and if it prompted a download, don’t open it. Watch your accounts and run a security scan if unsure.


