Security

Smishing

Phishing sent by text message. A message about a parcel, payment or account problem urges you to tap a link or reply. Check the claim in the genuine app or website rather than using the link.

How it works

Smishing is phishing delivered through text messages. The attacker tries to turn a short message into a harmful action, such as opening a false sign-in page, paying an invented fee or contacting a fraudulent support number. A familiar brand name in the message is not verification of its sender.

A practical example

An unexpected delivery text might claim that a parcel is waiting for an address correction. Its linked page could request card information for a small fee. The important question is whether the claim can be confirmed through the carrier’s real service, not whether the message looks professionally written.

What to check

Open the service through its known app or a separately obtained official address instead of the text’s link. Compare the claim with genuine orders or account activity. Do not reply with passwords or verification codes. Preserve relevant evidence and use the phone’s reporting or blocking options if appropriate.

Limits and safe use

Not every unsolicited text contains malware, and receiving one does not mean the phone has been hacked. If information was entered or money sent, the response depends on what was exposed: contact the relevant provider through a trusted channel and secure affected accounts. Blocking the sender alone does not reverse an earlier transaction.

Technical sources

← All glossary terms