How Can I Tell If a Text Message Is a Scam?

Information current as of 09/12/2026.

A text message may be a scam—also called smishing—if it unexpectedly impersonates a trusted organization, creates urgency, asks for personal or financial information, or directs you to a link, attachment, download, or phone number. Do not click, reply, call, open attachments, or share credentials; verify the claim through an official website, app, or contact method you find independently. Report the message through available spam-reporting tools and delete it after preserving evidence if you may need to report it.

Warning signs of a scam text

Text-message phishing is commonly called smishing. Be cautious when an unexpected message claims to come from a bank, service provider, government body, delivery company, or another trusted organization. A familiar sender name, logo, or phone number does not prove the message is genuine because senders and identities can be spoofed or impersonated.

Common warning signs include:
– Pressure to act immediately or fix, verify, update, or reactivate an account.
– Requests for passwords, PINs, security codes, personal information, payment details, or other financial information.
– Links, especially shortened or unfamiliar URLs, attachments, downloads, or invitations to start a conversation.
– Claims about an account, payment, invoice, or delivery problem that you were not expecting.
– Unusual formatting or poor writing. However, writing quality alone is not a reliable test; a scam can also be professionally written.

What to do when a text looks suspicious

Do not click links, open attachments, download files, reply, call a number in the message, or provide information. Do not use contact details supplied by the suspicious text to verify it. Instead, open the organization’s official app, type a known website address yourself, or find a phone number through an independently obtained official source.

If the message is spam or phishing, use the spam-reporting feature in your messaging app or device when available, and follow reporting options provided by your mobile provider or the organization being impersonated. Do not reply to the suspicious message. Preserve the message or screenshots first if the content may be useful for reporting, then delete or quarantine it.

If you clicked or shared information

Stop interacting with the message and do not provide anything else. Change any exposed passwords or credentials, and enable multi-factor authentication where available. Contact the affected provider or financial institution through an official channel, especially if payment or financial information was disclosed. If you downloaded something or suspect malware, update and scan the device using trusted security tools, and seek appropriate technical help.

Sources