20 SMS Fraud Examples and 30 Second Checks to Spot Them

Smishing is SMS phishing: a fraud attempt delivered by text message designed to steal your money, credentials, or personal data. Three moves protect you every time: don’t click the link, verify the claim through the company’s official app or website, and forward the message to 7726 (SPAM). What follows are the exact patterns scammers use, the warning signs in each one, and what to do the moment a suspicious text lands on your phone.
TL;DR:
- Most scam texts rely on predictable templates such as fake delivery alerts, impersonated banks, or urgent government notices, aimed at eliciting quick reaction.
- Recognizing common patterns like suspicious links, urgent language, or unexpected requests for passwords can help identify smishing attempts instantly.
- Verify suspicious messages through official apps or phone numbers and avoid clicking links or sharing sensitive information to prevent theft.
- Reporting scam texts to 7726 or authorities and blocking offending numbers can help reduce the spread of SMS fraud campaigns.
- AI-generated texts, breach-informed personalization, and multi-channel tactics are making smishing messages more convincing and harder to detect.
Table of Contents
- 20 SMS Fraud Examples You’ll Actually Receive
- Your Quick Verification Checklist Before You Click, Reply, or Pay
- What to Do Immediately After You Click or Share Information
- Why Smishing Works: The Techniques Behind Every Fake Text
- How Organizations Detect and Stop SMS Fraud Campaigns
- The Scale of the Problem: What the Numbers Show
- Emerging Trends and New Tactics to Watch
- Legal Consequences for SMS Fraud Perpetrators
- What Mobile Carriers Do to Fight SMS Fraud
- Tools and Apps That Help Block Fraudulent Texts
- Why the Twenty-Example Approach Beats Generic Warnings
- Sources
20 SMS Fraud Examples You’ll Actually Receive
Scammers reuse a small set of templates because they work. The National Council on Aging tracks these as the most common SMS fraud types circulating right now, and most of the twenty below trace directly back to that pattern list.
-
Fake delivery or package alert. “USPS: Your package could not be delivered due to an incomplete address. Update here: [link].” These work because almost everyone is expecting a delivery at any given moment. Red flag: carriers don’t text links for address corrections; they hold packages and notify through official tracking numbers you initiated.
-
Unpaid toll or parking fee demand. “You have an outstanding toll balance. Pay now to avoid a $50 fine: [link].” The dollar amount is always small enough to feel worth paying just to make it go away. That’s the trick. Legitimate toll agencies bill by mail, not text threats.
-
Bank fraud or account locked alert. “Chase Alert: Unusual activity detected on your account. Verify your identity: [link].” This leads to a cloned login page built purely for credential harvesting. Real banks direct you to log in through their app, never through a text link.
-
Prize or gift card win. “Congratulations! You’ve won a $500 Walmart gift card. Claim now: [link].” You never entered this sweepstakes, because it doesn’t exist. Any gift card scam text that requires you to act fast to claim a prize is a lure, full stop.
-
IRS or government impersonation. “IRS Notice: You owe back taxes. Failure to respond within 24 hours will result in legal action.” The IRS communicates by mail first, never demands payment by gift card or wire transfer, and never threatens immediate arrest by text.
-
Family emergency impersonation. “Mom, I lost my phone, this is my new number. I need you to send money for an emergency.” This exploits the panic reflex before you’ve had time to verify anything. Call the family member directly on their known number before sending a cent.
-
Fake job recruiter or task scam. “We reviewed your resume and have a remote position paying $35/hour. Reply YES to start.” Friendly at first, this escalates once you’re hired: you’re asked to pay for “training materials” or receive stolen goods to reship.
-
Fake two-factor authentication code request. “Your verification code is 483920. Someone else may be trying to log in, reply with this code to cancel.” This is a live account takeover attempt in progress. Sharing that code hands the attacker your account.
-
Subscription renewal or fake invoice. “Your Netflix subscription has been renewed for $89.99. To cancel, click here.” The fake charge creates urgency to click without thinking, and the “cancellation” page just harvests your card details.
-
Wrong-number investment scam (pig-butchering). “Hi Jenny, sorry I got mixed up, is this the restaurant?” This starts as an innocent mistake, but the sender keeps chatting for weeks before eventually introducing a “can’t-lose” crypto investment.
-
Spoofed texts from your own number. You receive a text that appears to come from your own phone number, often carrying a malicious link. This is a spoofing technique meant to bypass your natural suspicion of unknown senders, and the FBI’s guidance on spoofing and phishing flags number spoofing as one of the most common enablers of text fraud.
-
Crypto exchange or wallet security alert. “Coinbase Security: Suspicious login detected. Secure your wallet now: [link].” This routes to a fake exchange login that captures your seed phrase or password, draining the wallet within minutes.
-
Fake refund or overpayment. “We accidentally refunded you $750 extra. Please return the difference via gift card.” No legitimate company asks you to repay an “accidental” refund with gift cards; that payment method alone is the tell.
-
Fake debt collector threats. “This is your final notice before legal action for an unpaid debt. Call immediately: [number].” Real debt collectors are bound by the Fair Debt Collection Practices Act and must send written validation notices, not blast threatening texts.
-
Utility disconnection threat. “Your electricity will be shut off today due to non-payment. Pay now: [link].” Utilities generally send multiple written notices before disconnection, never a same-day text demanding immediate card payment.
-
Account reactivation request. “Your Facebook account has been suspended. Verify your identity to restore access: [link].” This grabs your login credentials under the guise of “restoring” an account that was never actually suspended.
-
Fake Apple, Google, or streaming account verification. “Apple ID: Your account was accessed from a new device in Russia. Verify now: [link].” The geographic detail is designed to spike alarm and override your instinct to check first.
-
Student loan forgiveness scam. “You qualify for federal student loan forgiveness. Apply before the deadline expires: [link].” Real forgiveness programs run through your loan servicer or studentaid.gov, never through a countdown-timer text.
-
Gift card payment request (boss impersonation). “Hi, it’s [CEO name], I need you to buy 5 gift cards for a client gift, reimbursement to follow. Can’t talk right now.” This is one of the most common gift card scam texts hitting businesses, timed for when the real executive is traveling or unreachable.
-
Fake toll or parking enforcement app link. A variant of the toll scam sends a shortened link mimicking a state DMV or toll authority’s mobile app. The shortener hides a domain that looks nothing like the real agency once you check it.
Your Quick Verification Checklist Before You Click, Reply, or Pay
Run these checks in the order below, and most fake texts fall apart in under thirty seconds.
- Was I expecting this? If you didn’t order a package, don’t bank with that institution, or never entered a sweepstakes, treat the text as fraudulent by default.
- Is there pressure to act right now? Urgency, deadlines, and threats of penalties are manufactured to shut down your critical thinking, and the Better Business Bureau lists urgency as one of the clearest markers of a phony text.
- Does the link or number look off? Misspelled domains, random strings of characters, or a link shortener hiding the real destination are all warning signs worth stopping for.
- Am I being asked for a password or a code? Never share a password, PIN, or two-factor code in reply to a text. Legitimate companies and government agencies don’t request them this way, and the IRS explicitly states it never asks for sensitive account data over text.
- Can I verify this independently? Open the company’s official app, or call a number pulled from their website, not the one in the text itself.
- Use your phone’s built-in reporting. Most phones let you mark a message as junk directly from the thread, which helps carriers flag repeat offenders.
Pro Tip: Screenshot the message before you delete it. If you need to report the fraud or file a police report later, having the exact sender number, timestamp, and message text makes the process much faster.
What to Do Immediately After You Click or Share Information
Speed matters here. The longer stolen data or malware sits unaddressed, the more damage it can do.
- If you clicked a link but entered nothing: Close the browser tab immediately, clear your browsing data, and check your device for any app you don’t remember installing.
- If you entered a password or a 2FA code: Change that password right away, sign out of all active sessions, and switch to an authenticator app or hardware security key instead of SMS codes going forward.
- If you sent money or gift card codes: Call your bank or payment provider immediately to request a fraud investigation or transaction recall; gift cards are harder to recover, but the issuer may be able to freeze the balance if you act fast.
- Report it: Forward the message to 7726, then file a full report at ReportFraud.ftc.gov. For losses involving real money, file a report with local police as well.
- Contact your carrier if the messages continue, so they can block the sending number or trace the campaign.
- Preserve your evidence. Keep screenshots and timestamps, and consider a credit freeze with the major bureaus if you shared your Social Security number.
Why Smishing Works: The Techniques Behind Every Fake Text
Attackers don’t need to hack your phone. They just need you to believe the message for five seconds.
- Number spoofing lets a scammer’s outgoing text display a bank’s real short code or even your own number, borrowing trust that was never earned.
- Domain lookalikes and link shorteners disguise a malicious URL behind a familiar-looking brand name or a compressed link that hides the true destination until you’re already on the page.
- Urgency, authority, and scarcity are the three social engineering levers behind almost every template above, from tax deadlines to “final notice” utility shutoffs.
- Pig-butchering and executive impersonation trade speed for patience, building weeks of trust before the actual ask.
- AI-generated text now smooths out the grammar mistakes that used to give scam texts away, and personal details pulled from data breaches let attackers reference your real bank, employer, or recent purchase.
Roughly 4.5 billion robotexts were sent every week in late 2024, a volume that means nearly every phone user will encounter a smishing attempt sooner or later, not just once in a while.
How Organizations Detect and Stop SMS Fraud Campaigns
Individual vigilance stops one text. Organizations need visibility into patterns across hundreds or thousands of employees, because a single successful smishing message aimed at a payroll admin or an executive assistant can cost far more than one person’s stolen gift card balance.
- Security teams rely on user-reported messages, campaign correlation, and mobile telemetry to spot when the same lure is hitting multiple employees at once, often before it’s flagged by any single carrier.
- Once a pattern is confirmed, typical response includes blocking the sending number or domain, pushing an internal alert, and logging the incident for audit and compliance purposes.
- Employees should expect fast, specific guidance rather than generic “be careful” reminders, and should know exactly which internal channel to use to report a suspicious text, without ever forwarding a 2FA code to anyone, including someone claiming to be IT.
- Platforms like Smishalert give security teams the correlation and reporting layer that turns individual smishing reports into an early warning system for the whole organization.
For a deeper look at what that detection and response workflow looks like in practice, see how security teams build phishing prevention programs.
The Scale of the Problem: What the Numbers Show
The volume of smishing attempts has outpaced most people’s awareness of the threat. Weekly robotext volume in the billions, combined with the ease of spoofing a trusted number, means the average phone user now receives fraudulent texts as routinely as spam email arrived a decade ago. Financial impact varies widely by scam type: gift card scams tend to cost victims smaller amounts per incident but hit a huge number of people, while pig-butchering investment scams and executive impersonation fraud can drain tens of thousands of dollars from a single victim or business in one incident.
What makes the scale genuinely concerning isn’t just the number of messages sent. It’s the hit rate. Even a fraction of a percent response rate across billions of weekly texts translates into a steady stream of successful thefts, which is exactly why scammers keep recycling the same delivery, bank, and prize-win templates rather than inventing new ones. The templates that work don’t need to change.
Emerging Trends and New Tactics to Watch
The playbook is shifting in three directions worth watching closely. First, AI-generated text has eliminated the broken English and awkward phrasing that used to be the easiest tell in a scam message, making fakes harder to distinguish from real customer service texts on sight alone. Second, breach-informed personalization means a text might reference your actual bank, your real employer’s name, or a purchase you genuinely made recently, pulled from leaked data rather than guessed at random. Third, multi-channel escalation is becoming standard: a smishing text often now leads to a follow-up phone call or a WhatsApp message from the same “support agent,” layering channels to build false credibility. Business-targeted variants, especially gift card scam texts impersonating a CEO or manager, have grown more convincing as attackers scrape company org charts and executive travel schedules from public sources like LinkedIn and press releases.

Legal Consequences for SMS Fraud Perpetrators
SMS fraud isn’t a gray area under U.S. law. Sending fraudulent text messages to obtain money or personal information can trigger charges under federal wire fraud statutes, identity theft laws, and the CAN-SPAM Act’s provisions on deceptive commercial messaging, each carrying separate penalties that can include years in federal prison and substantial fines. The Federal Communications Commission also pursues civil penalties against illegal robotexting operations, sometimes in the millions of dollars per case, when it can trace the campaign to a specific operator. The practical challenge is jurisdiction: many smishing campaigns originate overseas, routed through spoofed numbers and disposable SIM cards, which makes prosecution far harder than the underlying law would suggest. That’s part of why reporting matters even when you weren’t victimized. Reports to the FTC and FCC feed the intelligence that eventually leads to takedowns.
What Mobile Carriers Do to Fight SMS Fraud
Carriers sit in a unique position: they can see patterns across millions of numbers that no single recipient ever could. Major U.S. carriers now run automated filtering systems that flag messages matching known scam templates before they ever reach your inbox, similar to spam filtering in email. When you forward a message to 7726, you’re feeding that detection system directly, helping it recognize and block the same message being sent to thousands of other numbers. Carriers also participate in industry-wide initiatives to authenticate legitimate business texts, making it easier to eventually distinguish a real bank alert from a spoofed one. None of this is foolproof. Spoofing techniques evolve as fast as detection does, which is why carrier-level filtering works best as one layer alongside your own verification habits, not a replacement for them.
Tools and Apps That Help Block Fraudulent Texts
Your phone’s built-in spam filtering is the first line of defense, and both major mobile operating systems now include native reporting tools that feed carrier detection systems. Beyond that baseline, dedicated call and text-blocking apps can catch patterns your carrier’s filter misses, particularly for newer scam templates that haven’t been flagged yet. For a closer look at how iOS and Android handle this filtering natively, see this breakdown of mobile OS message filtering. Security-focused guides also break down the specific red flags to check in a scam text before you ever tap a link, and general mobile app security practices help reduce the odds that a malicious link installs something harmful even if you do click by mistake. For organizations managing this risk across an entire workforce rather than one device at a time, platforms built specifically for messaging-based threats, like Smishalert’s solutions, correlate reports across employees to catch coordinated campaigns that individual spam filters were never designed to see.
Why the Twenty-Example Approach Beats Generic Warnings

Most advice on this topic stops at “be suspicious of unexpected texts,” which is technically true and practically useless. The reader who just received a gift card scam text from their “boss” doesn’t need a philosophy of skepticism. They need to know, in the next ten seconds, whether this specific message matches a known pattern.
That’s the gap this list is built to close. Pattern recognition works faster than abstract caution, and it works better under the exact kind of pressure scammers manufacture. The conventional advice also underestimates how much individual vigilance and organizational detection depend on each other. One employee spotting a fake CEO text is useful. That same employee reporting it into a system that correlates it against similar reports across the company is what actually stops a campaign before it reaches the next ten targets. If there’s one priority to take from all of this, it’s building the habit of verifying through a second channel before reacting, every single time, regardless of how urgent the message claims to be.
— Sophie
Sources
- Text message scams: how to identify, report and help protect yourself
- How to recognize and report spam text messages
- How to spot a phony text message
- Spoofing and phishing — FBI