What it is
Smishing is phishing delivered by SMS or messaging apps. It poses as a courier, bank, agency or toll operator and pushes you to tap a link or reply. The sender can be spoofed and sometimes the message appears in the same thread as genuine ones.
How it works
- 1A message arrives with a reason for urgency: a parcel to release, an unpaid toll, a suspicious account access.
- 2The link leads to a clone site asking for details or a card.
- 3The data and codes you give are used in real time to make purchases or access accounts.
- 4Often a call from a fake operator follows to “fix it”.
How to spot it
- Shortened links or unusual domains
- Urgency and small amounts to pay right away
- They ask you to call back or reply with a code
- The message sits in the same thread as genuine bank texts: no guarantee
How to defend
- Do not tap links: open the official app or site by typing the address
- Never share codes received by SMS
- Use virtual or spending-limited cards for online purchases
- Turn on push notifications in your bank app
- Block and report the number
If you think you have been hit
- Block the card from the app or by calling the bank
- Change the passwords you used and enable multi-factor authentication
- Dispute any unauthorised transactions
And there are many, many more
The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.
Contact meOther attacks
Watch the Shorts on YouTubeMatteo Russo · Updated October 2026