“Your account is locked” bait links and fake alerts.
Phishing texts (also called smishing) are fake messages designed to panic you into tapping a link. They impersonate banks, delivery companies, toll authorities, streaming services — anyone you might plausibly have an account with.
The link leads to a lookalike login page that harvests whatever you type: passwords, card numbers, one-time codes. The messages are mass-blasted to millions of numbers, so getting one doesn't mean you were targeted — but answering one can cost you everything in that account.
How the scam works
1
The hook
A text claims something urgent: your account is locked, a package can't be delivered, an unpaid toll is about to become a fine.
2
The link
It points to a domain that looks almost right — chase-secure-alerts.com instead of chase.com. On a phone screen, the difference is easy to miss.
3
The harvest
The fake page asks you to "verify" your login, card number, or a one-time code. Everything you type goes straight to the scammer.
4
The takeover
With your credentials — and especially with a one-time code — they log into the real account and move money or lock you out.
Red flags to watch for
!
Unexpected urgency
You weren't expecting a package, don't use that toll road, or didn't try to log in anywhere.
!
A link you're told to tap
Real banks tell you to open their app. Scammers need you to use their link.
!
A lookalike or shortened domain
Extra words, hyphens, or odd endings: chase-alerts.net, usps.delivery-fix.com, bit.ly links.
!
Requests for one-time codes
No legitimate company asks you to read back a code they texted you. That code is how scammers beat two-factor authentication.
!
Generic greeting, weird grammar
"Dear customer" plus slightly-off phrasing is a classic mass-blast tell.
What to do
✓
Don't tap — go direct
Open the company's real app or type its address yourself. If something is actually wrong, it'll be visible there.
✓
Check the number or link with Scambook
Paste the message into our free checker or look up the sender's number — reported phishing campaigns show up fast.
✓
If you already entered a password
Change it immediately, enable two-factor authentication, and change it anywhere else you reused it.
✓
If you entered card details
Call your bank using the number on the back of your card and ask them to block the card and watch for fraud.
✓
Report and delete
Forward the text to 7726 (SPAM), report it at reportfraud.ftc.gov, then delete it.
Frequently asked questions
I tapped the link but didn't type anything. Am I safe?
Almost certainly yes. Simply opening a phishing page rarely infects a modern phone. The danger is in what you type. Close the page, delete the text, and don't tap it again.
Why do phishing texts come from normal-looking phone numbers?
Scammers use cheap VoIP numbers and rotate them constantly, or spoof the sender entirely. That's why the number alone isn't proof either way — check the message content and the link.
My bank really does text me. How do I tell the difference?
Real bank texts never ask you to tap a link and log in, and never ask for codes or card numbers. When in doubt, open your banking app directly — never through the text.