Scam › Module 1 › Lesson 3
SMS Phishing (Smishing)
How fake package, bank, and delivery texts steal codes—and how to verify before you tap
Opening
Your phone is a phishing inbox now
Delivery texts, "KYC update," unpaid tolls, bank alerts, and "Your OTP was used" messages flood phones every day. On a small screen it is harder to inspect URLs—and that is the point. Smishing (SMS phishing) succeeds because people trust texts more casually than email.
1. How Smishing Usually Works
You get a short scare or convenience message: package held, account restricted, prize waiting, unpaid fine. A link opens a mobile page that looks like a carrier, courier, or bank. You type a password or one-time code. Sometimes there is no fancy site—just a reply asking you to send a code "to cancel a transaction." That is still phishing: the attacker already triggered a login or reset and needs your OTP.
2. Red Flags in Texts
Unknown short links
bit.ly / tiny weird domains that do not match the brand you expect.
Sender mismatch
Your bank usually uses a known sender ID; random local numbers pretending to be "Support" are suspicious.
OTP fishing
Anyone who asks you to share a one-time password is attacking you. Banks never need your OTP via SMS reply.
Threat + timer
"Pay today or face legal action" with a sketchy link is a classic pressure play.
3. Safe Response Habits
Do not tap the link. Open the official app, call the number printed on your card/bill (not the number in the text), or check the package status on the carrier's real website typed by you. If you already tapped and entered a password: change it from a clean device/session, enable MFA, and check for new forwarding rules or unknown logins.
Silence the bait
Mark obvious spam, block the sender, and never "unsubscribe" through a suspicious link—that can confirm your number is active.
Knowledge Check
What is smishing?
Multiple choice
Knowledge Check
True or False: Your bank may ask you to reply with your OTP to cancel a fake transaction.
True or False
Knowledge Check
What should you do with a suspicious "package held" text link?
Multiple choice