Smishing (SMS phishing) exploits small screens, tiny fonts, and impulsive taps — especially when the text mentions a parcel, a fine, a blocked account, or an “urgent” app update.
The pattern mirrors e-mail: urgency + a link outside the official app. Channels include SMS, WhatsApp, Telegram, Signal, or even workplace chat if a colleague’s account was stolen.
Common lures
- Delivery scams — “Pay €1.50 to release your parcel” with a fake payment page. Real carriers usually use their app or a tracking URL on their domain, not random SMS links.
- Customs or postal fees — pressure to pay within hours. Verify via the official site or listed hotline, not the number embedded in the SMS.
- Fake bank alerts — suspicious payment + login link. Open the bank app from the store you installed yourself, not from the message.
- WhatsApp from a “friend” — a hijacked account asks for “the code SMS you just got” (they are resetting your account) or to pay an invoice. Call your contact on a number you dial yourself.
- Job offers and premium-rate traps — short links to harvest data or sign you into costly services.
Why phones tilt the odds toward attackers
People often read mail at a desk; they read SMS in queues, on transit, or half-asleep — lower attention, higher mistakes. Push notifications feel more urgent than an open laptop.
Android sideloaded APKs bypass store review; iOS scams often use convincing web fakes for Apple ID or banking. Rule: no installs or logins from links in unsolicited texts.
Rules for home and work
- Banks and payments only via official apps or bookmarks you open yourself.
- For odd SMS, call the institution using the number from its official website — not from the text.
- Train non-IT roles too: front desk, drivers, warehouse — they see parcel and fine scams often.
- Report spam to your carrier where available.
Mail authentication (SPF/DKIM/DMARC) does not apply to SMS — you rely on verification channels and policy. Related: e-mail phishing, fake banking messages, vishing.