Skip to content
Safety & Privacy

Smishing: SMS Phishing Attacks

Back to Security Center

Your safety guides how we build. Read this at your own pace, and reach our team any time from the Security Center.

What Is Smishing?

Smishing (a combination of "SMS" and "phishing") is a cyberattack delivered via text message. Criminals send fraudulent SMS messages that impersonate trusted organisations, such as banks, delivery companies, government agencies, and online platforms, in an attempt to trick you into taking a harmful action. This might involve clicking a link to a fake website, calling a fraudulent phone number, downloading malware, or replying with personal information.

Smishing is particularly effective because text messages have a much higher open rate than emails. Most people read a text message within minutes of receiving it, and the limited screen space on a mobile device makes it harder to scrutinise links and sender details.

Common Smishing Scenarios

Criminals tailor their smishing attacks to exploit situations that people encounter in everyday life:

Fake Delivery Notifications

"We attempted to deliver your parcel today. Please reschedule your delivery here: [link]." These messages spike during busy shopping periods such as Black Friday and the Christmas season. The link leads to a convincing replica of a courier's website, where you are asked to enter personal details and pay a small "redelivery fee", which captures your card information.

Bank Alert Messages

"Unusual activity detected on your account. Verify your identity immediately: [link]." These messages exploit fear and urgency. The linked website replicates your bank's login page, capturing your username, password, and sometimes even your one-time verification code. Legitimate banks will never ask you to verify your identity through a link in a text message.

HMRC Tax Refund Messages

"HMRC: You are owed a tax refund of GBP 437.80. Claim now: [link]." HMRC will never notify you of a tax refund via text message. These scams exploit the appeal of unexpected money and direct you to a fraudulent website designed to steal your personal and financial details.

Subscription and Account Messages

"Your subscription is about to expire. Update your payment details to avoid service interruption: [link]." These messages impersonate streaming services, app stores, or other subscription platforms and aim to capture your card details.

How to Identify Smishing Messages

Developing a critical eye for text messages can prevent you from falling victim to smishing attacks:

Reporting Smishing Messages

In the UK, you can report suspicious text messages by forwarding them to 7726. This is the number used by all UK mobile networks to collect reports of spam and scam messages. The process is simple:

  1. Forward the suspicious message to 7726.
  2. Your network provider will respond asking for the phone number the message was sent from.
  3. Reply with the sender's number.

This reporting mechanism feeds into a national database used by telecommunications providers and law enforcement agencies to identify and block scam campaigns. You can also report smishing to Action Fraud and to the NCSC by forwarding suspicious emails to report@phishing.gov.uk (for email-based phishing) or by using their online reporting tools.

What to Do If You Have Responded to a Smishing Message

If you have already clicked a link, entered personal details, or provided financial information in response to a smishing message, take these steps immediately:

Smishing attacks continue to evolve in sophistication. Maintaining a default position of scepticism toward unsolicited text messages, verifying claims through official channels, and reporting suspicious messages all contribute to reducing the effectiveness of these attacks for everyone.

Back to Security Center

Meet people, safely.

ID checks you can see, real dinners, and a team that has your back. See how it works.

KF.Social
Go for dinner. Leave with friends.
Get the app