Back to all articles

Smishing: scam SMS, WhatsApp, and “your parcel is waiting”

Smishing (SMS phishing) exploits small screens, tiny fonts, and impulsive taps — especially when the text mentions a parcel, a fine, a blocked account, or an “urgent” app update.

The pattern mirrors e-mail: urgency + a link outside the official app. Channels include SMS, WhatsApp, Telegram, Signal, or even workplace chat if a colleague’s account was stolen.

Common lures

  • Delivery scams — “Pay €1.50 to release your parcel” with a fake payment page. Real carriers usually use their app or a tracking URL on their domain, not random SMS links.
  • Customs or postal fees — pressure to pay within hours. Verify via the official site or listed hotline, not the number embedded in the SMS.
  • Fake bank alerts — suspicious payment + login link. Open the bank app from the store you installed yourself, not from the message.
  • WhatsApp from a “friend” — a hijacked account asks for “the code SMS you just got” (they are resetting your account) or to pay an invoice. Call your contact on a number you dial yourself.
  • Job offers and premium-rate traps — short links to harvest data or sign you into costly services.

Why phones tilt the odds toward attackers

People often read mail at a desk; they read SMS in queues, on transit, or half-asleep — lower attention, higher mistakes. Push notifications feel more urgent than an open laptop.

Android sideloaded APKs bypass store review; iOS scams often use convincing web fakes for Apple ID or banking. Rule: no installs or logins from links in unsolicited texts.

Rules for home and work

  • Banks and payments only via official apps or bookmarks you open yourself.
  • For odd SMS, call the institution using the number from its official website — not from the text.
  • Train non-IT roles too: front desk, drivers, warehouse — they see parcel and fine scams often.
  • Report spam to your carrier where available.

Mail authentication (SPF/DKIM/DMARC) does not apply to SMS — you rely on verification channels and policy. Related: e-mail phishing, fake banking messages, vishing.