Scam › Module 1 › Lesson 3
SMS Phishing (Smishing)
How fake package, bank, and delivery texts steal codes—and how to verify before you tap
Opening
Your phone is a phishing inbox now — short screens hide hosts, and taps are faster than thought.
Delivery texts, unpaid tolls, "KYC update," bank alerts, and "your code was used" messages arrive on a screen that shows two lines and a blue link. Email at least lets you hover. SMS is built for a thumb. That is smishing: phishing delivered as text (and often as chat apps that look like SMS). People treat texts as more personal than mail. Attackers count on that intimacy plus the missing URL preview. This lesson stays defensive. You will not tap sample links. You will not reply to fictional numbers. You will write a verification habit: official app or the phone number printed on your card or last bill — never the number or URL inside the surprise SMS. Topic 4's MFA codes are a prize here: a text that says "send us the code we just texted" is not support. It is their login waiting on your have-factor.
1. Why SMS wins: small screen, one tap, borrowed intimacy
A laptop email client can show a full From domain and a hovered href. A lock-screen SMS shows a sender ID that may be a short code, a local number, or a spoofed brand name, plus a truncated sentence. The link is often a shortener. You cannot long-press as carefully while walking. Urgency copy ("held at depot," "toll unpaid — court," "account restricted") is sized for that glance. Trust is the courier or bank you already use. Authority is "do not ignore this fine." The mechanisms from lesson 1 did not change. The UI removed your inspection tools. Treat every unexpected text link as untrusted until you verify on a channel you started.
Sender IDs are not certificates. Brands sometimes use alphanumeric senders; criminals also display brand-like names depending on the country and the gateway. A random mobile number claiming to be "Support" is a mismatch. A "bank" text that does not match the sender pattern you have seen for years is a mismatch. You do not complete the check by tapping to see the landing page. You open the app you already installed, or you dial the number on the physical card. If the app shows no alert, the SMS was the attack, not the bank.
2. MFA code theft: the text that asks for the code you just received
Topic 4 taught SMS 2FA as a weak have-factor because the number can be moved — that is a risk to you, not a how-to. Smishing adds a simpler steal: they already started a login or password reset with an email they stuffed or guessed. The real service texts you a one-time code. A second message (or the same thread, or a voice call) says "reply with the code to cancel," "read me the numbers," or "we sent a code, forward it to verify you." If you send it, you finish their authentication. Banks, shops, and authenticators never need you to volunteer a live OTP to a stranger. The code is proof of possession. Giving it away is handing them the second lock.
The same pattern appears as "unusual sign-in — tap to confirm it was you" on a lookalike page that then asks for the code. Confirming in the official app is different from confirming in a page the SMS opened. Habit: if you did not start a login, a surprise OTP is a signal to refuse and to check the official app's session list — not to type the code into the message's destination. If you already typed it, rotate the password from a clean session and review Topic 4 recovery: backup codes offline, not in the compromised inbox.
3. Package, toll, and bank scripts are urgency templates — verify without the SMS link
Courier script: package held, tiny customs fee, scan a QR, enter card details. Toll/fine script: unpaid road charge, legal language, short deadline, payment link. Bank script: KYC expired, card blocked, "verify identity." The facts may be false; the pressure is real. Real carriers have apps and tracking numbers you already have in an order email. Real toll authorities have sites you type or apps from the official store you already use — not a surprise SMS. Real banks put numbers on cards. None of them need you to authenticate through a text you did not expect. If you did order a package, open that shop's app. If you did not, ignore the text; do not "unsubscribe" through its link (that can confirm the number is alive).
Voice (vishing) is the same ask with a human timer: "stay on the line while we send a code." Hang up. Call the card number. Do not practice this against a bank. Do not call numbers from the suspicious SMS. The verification habit is one sentence you should be able to write from memory: I do not tap surprise links; I open the official app or dial the number printed on my card or last paper bill.
4. Wrong vs right: tapping to "check the tracking page" vs starting your own channel
Worked failure — same package scare, opposite URL. Right never taps the sample or a live surprise link.
Wrong
Tap the SMS link because the fee is only $1.99. Forward the OTP "to cancel." Call the number in the text. Reply STOP on a thread you do not trust. Screenshot the code into group chat. Visit the fictional host in the sample "to see the kit." That is how harvest and malware start on a phone, and how MFA is stolen.
Right
Do not tap. Open the carrier or bank app you already have, or type a hostname you already know, or dial the printed card number. If there is no matching alert, delete/block the SMS. Write the habit in the lab file next lesson. Keep Topic 4 unique passwords and MFA; never donate the code. Report junk in the phone's SMS app when the OS offers it.
5. Practical: write the verification habit — never tap the sample
Copy the habit into your own words on paper. Then classify the fictional SMS in the code block: package vs bank vs OTP steal. List flags (shortener or lookalike host, timer, authority, code ask). Do not tap, do not SMS the sample number, do not load parcel-hold.example. The next lesson is a lab on email samples with the same discipline.
Fictional SMS + verification habit — do not tap
# FICTIONAL texts. Do NOT tap, call, or SMS these. # A) Package script # From: local number # "Your parcel is held. Pay $1.99: https://fedx-delivery-alerts.example/pay" # B) OTP steal (MFA) # From: "Support" # "We tried to sign in. Reply with the code we just texted to CANCEL." # C) Bank/KYC script # "Account restricted. Update KYC: https://paypa1-security.example/kyc" # Write YOUR habit (fill blanks on paper): # I do not tap surprise SMS links. # I verify in: official app / number printed on my card or bill # I never send: OTP / password / card CVV # If I did not start a login, a surprise code means: refuse, check app sessions # NEVER: visit fedx-delivery-alerts.example or paypa1-security.example # NEVER: reply with a live MFA code # NEVER: call the number inside a scare text — use the card/bill number
Mission: the habit you can say out loud
1) Write one sentence: verify via official app or the phone number on your card/bill, never the SMS link. 2) Explain in two lines why "send the code we just texted" is MFA theft, tying to Topic 4's second factor. 3) Classify fictional samples A/B/C as package, OTP steal, or KYC — flags only, no taps. Never visit sample hosts. Never reply to sample numbers.
Stuck? Ask Cyberlium AI Mentor
If SMS 2FA vs smishing still collides, ask for a hint — not a number to call. Try: "Hint only: why must I never reply with a code that just arrived, and why is the number on my card safer than the number in a package-held text — without me tapping fedx-delivery-alerts.example?" You still write the habit yourself.
You now treat the phone as a phishing inbox: small screens hide hosts, taps skip inspection, and package/toll/bank copy is urgency plus borrowed trust. The OTP-forward text is MFA theft, not cancellation. Verification is a channel you start — app or printed number — never the SMS. Next — Lab — Spot the Phishing Email — you score fictional messages with written flags and keep notes in a 600-mode file. Still no visits.
Knowledge Check
APPLY: A text says your parcel is held and offers https://fedx-delivery-alerts.example/pay. You did order something last week. Safe move?
Multiple choice
Knowledge Check
APPLY: You get a real-looking bank SMS: "Reply with the code we just sent to cancel a transfer." You did not start a transfer. What is happening?
Multiple choice
Knowledge Check
APPLY: True or False: Long-pressing an SMS link to read the host is inspection; opening it in the in-app browser to "confirm it is fake" is still a visit and is out of scope.
True or False