Phishing texts (also called smishing) are fake messages designed to panic you into tapping a link. They impersonate banks, delivery companies, toll authorities, streaming services — anyone you might plausibly have an account with.
The link leads to a lookalike login page that harvests whatever you type: passwords, card numbers, one-time codes. The messages are mass-blasted to millions of numbers, so getting one doesn't mean you were targeted — but answering one can cost you everything in that account.
How the scam works
1
The hook
A text claims something urgent: your account is locked, a package can't be delivered, an unpaid toll is about to become a fine.
2
The link
It points to a domain that looks almost right — chase-secure-alerts.com instead of chase.com. On a phone screen, the difference is easy to miss.
3
The harvest
The fake page asks you to "verify" your login, card number, or a one-time code. Everything you type goes straight to the scammer.
4
The takeover
With your credentials — and especially with a one-time code — they log into the real account and move money or lock you out.
Red flags to watch for
!Unexpected urgency
You weren't expecting a package, don't use that toll road, or didn't try to log in anywhere.
!A link you're told to tap
Real banks tell you to open their app. Scammers need you to use their link.
!A lookalike or shortened domain
Extra words, hyphens, or odd endings: chase-alerts.net, usps.delivery-fix.com, bit.ly links.
!Requests for one-time codes
No legitimate company asks you to read back a code they texted you. That code is how scammers beat two-factor authentication.
!Generic greeting, weird grammar
"Dear customer" plus slightly-off phrasing is a classic mass-blast tell.
What to do
✓Don't tap — go direct
Open the company's real app or type its address yourself. If something is actually wrong, it'll be visible there.
✓Check the number or link with Scambook
Paste the message into our free checker or look up the sender's number — reported phishing campaigns show up fast.
✓If you already entered a password
Change it immediately, enable two-factor authentication, and change it anywhere else you reused it.
✓If you entered card details
Call your bank using the number on the back of your card and ask them to block the card and watch for fraud.
✓Report and delete
Forward the text to 7726 (SPAM), report it at reportfraud.ftc.gov, then delete it.
Frequently asked questions
I tapped the link but didn't type anything. Am I safe?
Almost certainly yes. Simply opening a phishing page rarely infects a modern phone. The danger is in what you type. Close the page, delete the text, and don't tap it again.
Why do phishing texts come from normal-looking phone numbers?
Scammers use cheap VoIP numbers and rotate them constantly, or spoof the sender entirely. That's why the number alone isn't proof either way — check the message content and the link.
My bank really does text me. How do I tell the difference?
Real bank texts never ask you to tap a link and log in, and never ask for codes or card numbers. When in doubt, open your banking app directly — never through the text.
Got a message that looks like this scam?
Paste it into Scambook's free AI checker for an instant verdict, or look up the phone number or website that contacted you.