SMS-based fraud, often called smishing (SMS phishing), has undergone a significant shift over the past several years. Where it was once characterized by bulk generic messages, "You've won a prize, click here," it now frequently arrives with context that feels specific: your first name, a package tracking number, a reference to your bank or a service you use, or a detail about a recent activity that gives the message plausibility.
Understanding what changed and how helps explain why these messages succeed at higher rates than generic blasts ever did, and what to look for when a text arrives that seems almost right.
What Smishing Is and Why It Is Different From Phone Calls
The defining feature of SMS-based fraud is the link. The goal of most smishing messages is to get the recipient to tap a URL that leads to a credential-harvesting site, a payment page, or a download of malicious software. The text message is the delivery mechanism. The harmful action happens on the web.
This differs from voice-based phone scams, where the scammer interacts directly with the victim to extract payment or information during the call. Smishing scales differently: one operation can send millions of messages automatically, with personalization at each one, waiting for a portion of recipients to tap the link. No human interaction is required until after someone has already clicked, entered their banking credentials, or authorized a payment.
The lower cost of this approach makes the economics different from voice scams. Even a very small conversion rate on a large send can be profitable. This is part of why volume has increased, the marginal cost of one additional message is nearly zero.
Where the Personalization Comes From
The shift toward personalized smishing messages is driven by the availability of large data sets assembled from data breaches, data broker aggregations, and social media scraping. A name, phone number, physical address, and known service subscriptions can often be assembled for a given person from multiple sources that have been involved in reported data exposure events.
This means a message that says "Hi Sarah, your USPS delivery for [partial address] requires confirmation" is not based on any actual interaction with USPS. It is based on publicly or semi-publicly available data about Sarah's name, phone number, and address. The tracking number may be entirely invented or may be a real tracking number format. From the recipient's perspective, the message looks plausibly genuine.
The more dangerous variant uses contextual information from recent activity: a message that arrives after a real online purchase and references a carrier that the person actually used, or a bank notification that references the bank the person actually banks with. This level of specificity requires more targeted data gathering, but it is increasingly common in well-resourced fraud operations.
The Most Common Smishing Templates in the US Right Now
Based on what we see in the consumer fraud reporting ecosystem, these are the most prevalent categories:
- Package delivery issues: A USPS, FedEx, or UPS delivery has a problem and requires a small redelivery fee or confirmation. The fee is low enough to seem trivial, but the payment form captures card details used for much larger unauthorized charges later.
- Bank fraud alerts: A "suspicious transaction" on your account requires your confirmation to prevent freezing. The link leads to a login page that looks like your bank's site but captures credentials.
- Toll violations: An unpaid toll is pending with a small fine that will increase if not paid. These are particularly common in areas with active toll infrastructure and have been reported across multiple states.
- Government benefit notifications: A stimulus payment, refund, or benefit update requires account confirmation. These track the news cycle and appear more frequently around actual government payment periods.
- Prize or offer confirmations: You have a reward from a loyalty program that expires soon and requires claiming.
The thread connecting all of these is a low-urgency action with a small barrier to compliance, combined with something familiar and plausible enough to reduce the skepticism that would apply to an obviously suspicious message.
Why SMS Creates a Different Context Than Email
Email phishing has been a persistent threat for decades, and most people have developed some intuition about suspicious emails. A message from a bank that arrives as spam is handled differently than a text that vibrates your pocket and sits in the same thread as family messages.
SMS carries a psychological trust that email does not. The same information in an email ("Your package requires action") and in a text message is processed differently. Part of this is the channel's associations: we text people we know. Part of it is the interface: there is no spam folder equivalent in the native SMS experience. Part of it is context: a text on a phone you are already using for daily personal communication feels like an extension of your personal space.
This psychological difference is exactly what makes smishing effective at conversion rates that exceed equivalent email phishing campaigns. The surface area of trust is different.
The simplest rule: Any link in an unsolicited text message should be treated as potentially malicious. If the message is about a package, go directly to the carrier's official site or app. If it is about your bank, open your banking app directly. Never tap through to verify from the text itself.
What Good Responses Look Like
We're not saying that all unexpected text messages are fraud. We're saying that the appropriate response to any text that asks you to tap a link and provide personal or payment information is to go directly to the source through a known channel, not through the link.
For organizations, registering a short code with a carrier for official SMS communications gives recipients a verifiable channel for legitimate messages. Consumers can look up whether a short code belongs to the company it claims to represent.
For individuals, keeping the navigation rule clear, never follow a link in an unsolicited text to provide personal information, removes most of the risk regardless of how convincing the message is. Even the most personalized smishing message cannot make tapping a link safe. The solution is not to outsmart the message, it is to not follow the link, period.
How Smishing Connects to Voice Scams
A pattern that has become more common in organized fraud operations is using a smishing message to establish a pretext before a follow-up phone call. The text arrives first, with a "case number" or reference number. Then a voice call follows referencing the same case number, which validates the caller in the recipient's mind because they already received a related message.
When Savi detects conversational patterns associated with fraud during a voice call, we are looking at the call itself. But the setup that made the call seem credible may have happened in a text thread. This multi-channel approach makes each individual element seem more legitimate because the other element appears to corroborate it. Recognizing that the two can be coordinated is part of understanding how current fraud operations are structured.