What is smishing? How it compares to phishing and vishing

Sharon Wu Sharon Wu Author CFEI®, OmniWatch Advisor
What is smishing? How it compares to phishing and vishing

“USPS ALERT: your package is on hold—update your address here now for redelivery.” If you’ve gotten a text like that in the last few months, you’ve encountered smishing, even if you didn’t know the term. So, what is smishing? It’s a scam that uses text messages to get your financial or personal information, usually by pretending to be a company or agency you already trust.

Smishing (a mashup of “SMS” and “phishing”) has exploded as we rely more on our phones. And scammers know a text feels more urgent and personal than an email. We’ve seen fake delivery alerts, bogus toll notices, and “wrong number” texts that turn into weeks-long cons. It’s also easy to confuse it with its cousins, phishing and vishing, even though each one tricks you through a different channel. Below, we’ll explain what separates them, how these scams work, and what to watch for before you tap a link—plus what the law says, how to report a scam text, and what to do if you’ve already tapped.

This article was created in partnership with OmniWatch, who compensated me for my time and writing services. While they covered the cost of my time, all opinions and recommendations in this article are completely my own.

Key takeaways

  • Smishing, phishing, and vishing are the same con, but they use different channels to reach you.
  • A text feels personal and urgent in a way email doesn’t, which is why people fall for it.
  • Artificial intelligence (AI) has made 2026’s scam texts harder to spot.
  • Urgency and requests for personal information are the biggest red flags.
  • Don’t click suspicious links, and verify the sender before doing anything else.

What’s the difference between smishing, phishing, and vishing?

Phishing, smishing, and vishing are all scams built on the same trick: someone pretending to be a person or company you trust. So what do vishing and smishing refer to, exactly? Vishing is voice phishing (a scam call or voicemail), whereas smishing is the SMS text-message version.

The difference comes down to how the scammer reaches you:

Type

Channel

How it usually shows up

Phishing

Email

A bogus email with a malicious link or attachment, often mimicking a real company

Smishing

Text message

An urgent text claiming to be your bank, a delivery service, or a government agency

Vishing

Phone call or voicemail

A caller posing as tech support, your bank, or a government official to get you talking

Smishing vs. vishing

A smishing text wants you to click a link or reply with sensitive information. Think a fake “your package is delayed” text with a tracking link.

A vishing call skips the link and goes straight for the conversation, like a scammer posing as your bank’s fraud department and asking you to “confirm” your card number out loud.

Sometimes, the two work together. A text tells you to call a number, and the scam happens on the call.

Smishing vs. phishing

Phishing relies on email, so it often includes a fake login page or a malicious downloadable attachment, like an email that looks like it’s from PayPal asking you to “verify” your account.

Smishing skips the download and involves a short, urgent text with a link—built to work fast on a small screen where it’s harder to spot the warning signs.

What is smishing in cybersecurity, and how does an attack actually work?

Most smishing attacks follow the same four-step pattern:

  1. Borrowed trust: The text looks like it’s from your bank, a delivery company like UPS or a retailer like Amazon, or a government office.

  2. Manufactured panic: Your account’s locked. Or your package is stuck. Or you’ve won something, and it’s about to disappear if you don’t act. The specific story doesn’t matter—the goal here is to get you moving before you stop to think.

  3. The push: Now comes the ask. Tap this link. Call this number. Text back these four digits. Whatever it is, it’s something you can do in 10 seconds without thinking twice.

  4. The damage: Click the link, and you land on a lookalike site built to steal your password. Call the number, and someone posing as tech support works you over the phone until you hand over whatever they’re after.

You’ll see this same setup behind most smishing texts with a different disguise each time:

Scam type

The disguise

Bank fraud alert

A charge you’re told to “verify” by logging in

Package delivery

A fake shipping fee you need to pay to release your order

Tax or government notice

A refund or legal notice pressuring you to respond

Account verification

A security code or password reset you never asked for

Why are smishing attacks so effective?

Smishing attacks are particularly effective because of where they land. People open text messages often, and most check a new one within minutes. Because text messages feel more personal than email, people tend to trust them (and reply) more. Scammers count on that instinct instead of trying to outsmart the spam filters email scams have to fight through.

Text messages also give you less to work with. A small screen makes it hard to check where a link leads, so you miss warning signs that would jump out in an email.

A recent FBI warning and FTC numbers put this in perspective:

FBI warning: officials targeted by AI-powered smishing

In 2025, the Federal Bureau of Investigation (FBI)’s Internet Crime Complaint Center (IC3) warned that scammers were targeting government officials and their close contacts with a more advanced version of this scam.

Posing as senior officials, the attackers sent texts that pushed victims toward an encrypted messaging app, in some cases backed by AI voice clips to sound more convincing. Victims who clicked the link risked losing access to their accounts, credentials, and contact list to the scammer.

FTC data: text scams cost Americans five times more than in 2020

Government data backs up how costly this has become. Americans lost $470 million to text-based scams in 2024, up from $85 million in 2020 (that’s five times more), according to the FTC. Individual smishing attacks are getting more convincing. And that’s only what people reported—the FTC notes that many scam losses are never reported at all.

What do smishing texts look like in 2026?

Scam texts today look polished. AI writing tools have wiped out the typos and broken grammar that used to be an easy tell. A fake delivery alert or bank text can look just as legitimate as the real thing.

In 2026, you’ll likely run into these five smishing formats:

Package delivery

This is the FTC’s most-reported smishing format, and it works because almost everyone is expecting a package at any given time.

Example: “FedEx: We attempted delivery of your package, but your address is incomplete. Update it within 24 hours to avoid return: [fake redelivery link].”

Toll scams

You get a text saying you owe a few dollars for a toll, with a much bigger penalty threatened if you don’t pay right now. It doesn’t matter whether you drive anywhere near a toll road—these go out in bulk.

Example: “You have an unpaid toll of $6.75 on your account from 9/2. A $75 late fee applies if not settled within 24 hours—[fake payment link].”

Bank fraud alerts

You get a text saying your bank flagged a suspicious charge, and before you’ve had a chance to think it through, it’s already telling you to reply or call.

Example: “Chase MSG: Did you spend $863.53 at Best Buy just now? Reply YES to confirm, or call 1-800-555-0199 if this wasn’t you.”

Wrong-number messages

You receive a text looking like it’s meant for someone else, and it feels harmless enough to answer. But if you reply, the scammer will keep the conversation going, sometimes for weeks. Eventually, it turns into a pitch for crypto or some can’t-miss investment.

Example: “Hey, are we still on for lunch this Thursday at 12 p.m.?”

Job and task scams

The pitch is easy money for remote work. The catch shows up later, when you’re told to pay a small fee to “release” earnings that were never real to begin with.

Example: “Remote data entry role available, $35/hr, flexible hours. Reply START to begin onboarding today.”

How can you identify a smishing text?

Even a well-written scam text usually gives itself away if you know what to look for:

  • Urgency: The text says something along the lines of “your account will be locked,” “your package will be returned,” or “a fine will double if you don’t act within hours.”

  • Unusual sender information: The message comes from a random long number, a short email-style address, or a number you don’t recognize from past communication with that company.

  • Odd-looking links: The URL is close to the real brand name but not quite right. It might have an extra word or a different ending than the company’s website.

  • Requests for sensitive information: The text asks for your password, PIN, Social Security number, or a one-time verification code. Banks and government agencies don’t ask for these over text messages.

How can you prevent or protect yourself from smishing?

You can’t stop scam texts from landing in your inbox, but you can control what happens next.

A few habits go a long way:

  • Forward the message to 7726. Your carrier can block similar messages once they know about it.

  • Turn on the spam filter in your mobile phone’s settings.

  • Use an authenticator app for account codes instead of text messages, which scammers can intercept.

Even careful people sometimes get a persuasive text. When you’re unsure about a message, OmniWatch’s Scam Protection Center lets you submit it for analysis before deciding whether to respond. And if a smishing attempt does succeed, OmniWatch’s scam protection insurance may help you recover the money you lost, depending on your plan.

What does the law say about smishing, and how do you report it?

Smishing breaks federal law.

Under the Telephone Consumer Protection Act (TCPA), businesses need your consent before sending automated texts, and the Federal Communications Commission (FCC) enforces that rule. It most recently strengthened your right to revoke consent through a 2024 order.

The FTC’s angle is fraud, not consent. Texts that impersonate a bank or government agency violate federal law under its Impersonation Rule. The FBI’s IC3, meanwhile, treats smishing as a cybercrime used to steal money and personal information, and investigates it accordingly.

Reporting a smishing text takes a few minutes and helps shut down the scam for other people too:

  • Forward it to 7726 (SPAM). This free report alerts your wireless carrier to investigate and block the number.

  • File a report at ReportFraud.ftc.gov. This helps the FTC track scam patterns and warn the public.

  • File a cybercrime complaint at IC3.gov if you lost money or had your information stolen.

Scam texts aren’t going anywhere. But your response to them can change.

OmniWatch gives you a place to check any suspicious text, call, or link before you act—backed by scam protection insurance that may help if a scam does get through. And with dark web and identity monitoring included, you’ll know when your information shows up where it shouldn’t.

See how OmniWatch scam protection works

Quick smishing checklist

Run through this list any time you’re unsure about a text. Due diligence takes a few minutes, and it can save you from a costly mistake.

  • Check the sender. An unfamiliar number, a random long string, or a text you weren’t expecting are all reasons for a second look.
  • Notice the pressure. Phrases like “within 24 hours” are designed to make you act without thinking.
  • Question sensitive requests. No bank, agency, or employer asks for your password, PIN, or Social Security number over text message.
  • Inspect the link. Misspellings, extra words, shortened URLs, and QR codes can all hide where you’re actually being sent.
  • Don’t reply, not even “STOP.” Responding tells the scammer that your number is active and can lead to more spam texts.
  • Go straight to the source. Instead of acting on the text, log in through the company’s official site or app.
  • Act quickly if you already clicked or entered information. Change your passwords, call your bank if you shared financial details, and turn on multi-factor authentication where you can.
  • When in doubt, check it with OmniWatch. Submit the message to OmniWatch’s Scam Protection Center for analysis before you respond.

Frequently asked questions

What does smishing mean?

Smishing means using fake text messages to trick you into handing over personal information, sending money, or downloading malware. The word combines “SMS” and “phishing,” and the scam works the same way email phishing does: a message that looks like it’s from a trusted source pushes you to act fast. The difference is the delivery: it arrives on your phone, where you’re more likely to tap first and think later.

What is a smishing attack?

A smishing attack is a scam that uses text messages to pressure you into clicking a bad link, sharing private details, or sending a payment. It typically follows four steps: borrowed trust (posing as your bank or a delivery company), manufactured panic, a quick ask, and the payoff (usually a lookalike login page or a call with a fake agent). It uses the same manipulation tactics as email phishing, but delivers them straight to your phone.

What are some clues that a text message is smishing?

Smishing clues include urgency, a suspicious link, requests for sensitive information, and offers that seem too good to be true. Look at the sender, too: a random 10-digit number or an email-style address where a short code should be is a red flag. Finally, were you even expecting a message at all? A “delivery problem” for a package you never ordered is almost always a scam.

How do you stop smishing text messages?

You can cut down on smishing texts by turning on your phone’s built-in spam filter, blocking numbers that send suspicious messages, and reporting them to your carrier. Forward suspicious messages to 7726 so your carrier can block the sender. But you can’t stop every scam text, so the more reliable defense is a habit: don’t tap links in unexpected texts, and go straight to the company’s official app or site instead.

Is SMS spoofing the same as smishing?

No. Spoofing disguises who a text is really from (usually by faking the sender’s number or name so it looks like someone or a company you know), while smishing is the scam itself (the message trying to steal your money or information). Scammers often spoof the sender to make a smishing text more convincing, which is why a familiar sender isn’t always proof a message is legitimate.

What should you do if you clicked a smishing link?

First, don’t panic. Clicking alone doesn’t always cause harm. If you entered a password, change it right away (and anywhere else you reused it), then turn on multi-factor authentication. If you shared card or bank details, call your bank using the number on the back of your card (not the one from the text). Then report the message to 7726 and reportfraud.ftc.gov so it’s on record.

idea.svg