Phishing texts ("smishing") are the highest-volume scam in existence — billions are sent every year. The goal is simple: get you to tap a link and type your password or card number into a fake site.
The 5-second checklist
Who's it from? Real companies text from consistent short codes. A bank alert from a random 10-digit number — or worse, an email address — is fake.
Where does the link go? Look at the actual domain. "chase-secure-verify.com" is not chase.com. Weird subdomains, misspellings, and link shorteners on "official" alerts are all red flags.
Is it urgent? "Your account will be suspended in 24 hours" is a pressure tactic. Real companies don't operate on countdown timers.
Did you expect it? A delivery notice when you're not expecting a package, a toll bill when you haven't driven anywhere, a prize you never entered for. Unexpected = suspicious.
Does it ask for credentials or payment? No legitimate text asks you to "verify" your password, SSN, or card number via a link.
When in doubt, check it
Never tap the link. Go to the company's app or website directly. And if you're not sure, paste the text into Scambook — phishing scripts are the most common pattern in our database, and lookalike domains get flagged the moment the first user checks one.