Your package could not be delivered. Your toll payment is overdue. Your bank has flagged a purchase. Each text arrives with a link, each demands a small action, and each is part of the same flood: smishing, phishing by SMS, which has grown into one of the highest-volume scams running because it costs almost nothing to send a million texts and a fraction of a percent of people are mid-move, mid-trip, or mid-errand and genuinely expecting a package.

Why text beats email for scammers

Three structural advantages. Texts have no spam filtering worth the name, so everything arrives. Texts are read reflexively, usually within minutes, often mid-task, when guard is lowest. And texts strip away the signals people learned to check in email: no sender domain to inspect, no hover-to-preview, just a shortened link and a sentence. The tells that survive in email survive here too, but the medium hides them better.

The volume also has a supply-side explanation: phone numbers by the hundred million, courtesy of years of breaches. Yours is on the list. That is why you get them; it was never personal.

What tapping the link actually does

Usually one of two things. Most commonly, a fake payment page: the "$1.45 redelivery fee" or "$6.99 toll" exists to harvest the card number, and the small amount is the point, because nobody hesitates over pocket change. The card is then sold or drained properly later. Alternatively, a fake login page for your bank, Apple ID, or email, harvesting credentials plus, per the standard play, the two-factor code you helpfully relay. Merely opening a link is rarely catastrophic on an updated phone; what you type afterward is the harvest. Which is worth knowing, because having tapped is recoverable. Having paid or logged in is what needs the response below.

The two-second habit

Never resolve anything through a link that arrived by text. Package texts get checked in the carrier's app or by the tracking number you already have from the retailer. Toll texts get checked at your state's actual toll site. Bank texts get checked in the bank's app. Same principle as scam calls: it is not about spotting the fake, it is about never using their door. Delete, and where your phone offers it, tap Report Junk.

If you already entered something

A card number: call the bank, kill the card, enable transaction alerts, and watch for tiny test charges over the following weeks. Credentials: change that password now, everywhere it was reused, and check the account's recovery settings and sessions. A two-factor code: treat the account as compromised, not merely exposed, and work through the first-24-hours sequence. And in every case, expect follow-up attempts: entering anything marks your number as live, and live numbers get resold.

Keep reading

Texts and calls both herd you toward the same destination: a counterfeit website. Here is how to inspect one before it costs you:

How to Spot a Fake Website Before You Type Anything

Lookalike domains, cloned shops, and too-good prices. The three checks that take thirty seconds, and the payment choice that limits the damage.

← Back to all guides