Smishing is phishing by text message. Scammers send an SMS or chat message that looks like it comes from your bank, phone company, courier or a government office, and push you to tap a link or call a number. Newer smishing hides the scam inside convincing web addresses, such as a domain that starts with a real brand name and ends with today’s date.
That trick surfaced in January 2020 and it is a good lesson in how scam texts keep improving. This post walks through it, the other tactics scammers use in text messages today, how to read a link before you tap it, and what to do if you or your customers are targeted.
The date-based domain trick
On January 2, 2020, UK technologist Terence Eden’s wife received a billing alert that appeared to be from the mobile network EE. She wasn’t an EE customer, so no harm was done, but Eden looked closely at the link and wrote up what he found. The address began with ee.co.uk, then a dot, then the day’s date, and it ended in .info.
Three things made it convincing:
- It started with https://. Many people still read that as “safe”. The certificate had been issued free of charge by Let’s Encrypt, which checks only that the requester controls the domain, not who they are.
- The real brand came first. “ee.co.uk” at the start of the address looked like EE’s own site. In fact it was only a subdomain of a scam domain. Eden’s point: on a cracked phone screen on a crowded train, would you notice a dot where a slash should be?
- The date looked like a billing reference. A link containing “jan02” in a message about a January bill feels routine.
The domain was also meant to be disposable. Scammers know that phishing domains get blocked quickly, so they register a cheap new one for each day’s campaign. By the time Eden had set up a virtual machine to inspect the site, major browsers were already flagging it. It had probably done its job by then.
How smishing has developed since
The date trick was one step in a long line. Text scams have only grown since. The US Federal Trade Commission reported that people lost $470 million to scams that started with a text message in 2024, more than five times the 2020 figure, in its Data Spotlight on top text scams of 2024.
The lures you are most likely to see:
- Delivery problems. “Your parcel is on hold, pay a small redelivery fee.”
- KYC and account blocks. “Your bank account or SIM will be suspended today, update your KYC.”
- Utility disconnection. “Your electricity will be cut tonight, call this officer.”
- Fake refunds and rewards. Tax refunds, reward points about to expire, cashback offers.
- Unpaid tolls and fines. Small amounts, so people pay without thinking.
- “Hi Mum” and wrong number chats. A stranger strikes up a conversation that turns into a job, investment or romance scam.
- Job offers. Paid “tasks” such as liking videos, which end with requests for deposits.
The technique has also moved beyond SMS into WhatsApp, Telegram and iMessage, where sender filtering is weaker. Many campaigns now use URL shorteners, free hosting or newly registered lookalike domains that change every few hours.
How to read a link before you tap it
The part of a web address that tells you who owns the site is the registered domain: the name directly in front of the ending (.com, .in, .info and so on), before the first single slash.
- In www.examplebank.in/login, the owner is examplebank.in.
- In examplebank.in.secure-update.info/login, the owner is secure-update.info. Everything to the left of it is decoration that anyone can add.
- In examplebank-in.com, the owner is examplebank-in.com, a different domain from examplebank.in.
If you can’t tell, don’t tap. Open the company’s app or type its address yourself. A padlock or https:// only means the connection is encrypted. It says nothing about whether the site is honest. For more checks, see how to identify a phishing website.
What to do: for individuals
- Don’t tap links in unexpected texts about payments, deliveries, KYC or blocked accounts. Go to the app or website directly.
- Never share an OTP, PIN or CVV, and never install a “support” app because someone asked you to.
- Call back on the number printed on your card or the official website, never the number in the message.
- In India, report suspected fraud calls, SMS and WhatsApp messages through Chakshu on the Sanchar Saathi portal. If money has already gone, call 1930 or file a complaint on cybercrime.gov.in at once.
- Block the sender and delete the message after reporting it.
What to do: for brands being impersonated
When scammers use your brand in text messages, your customers lose the money but your support team takes the calls and your reputation takes the damage. Organisations can act:
- Watch new domain registrations that contain your brand name, including ones that pair it with dates, “verify”, “kyc” or “refund”. Automated domain monitoring makes this practical.
- Take down the sites fast. Each domain may only live for a day, so removal speed matters more than anything else. A takedown service works with registrars, hosts and messaging platforms to get them removed. TIKAJ and its platform Hunto handle more than 100,000 takedowns a year for over 150 enterprise customers.
- Tell customers what you never send. Publish a short, consistent message: “We will never text you a link to update KYC or ask for your OTP.”
- Send your own texts from registered sender IDs and keep their format consistent, so anything different stands out.
We cover the different kinds of smishing in more depth in what is smishing and what are its types.
FAQ
What is smishing?
Smishing is phishing carried out through SMS or chat messages. The message pretends to come from a trusted organisation such as a bank, courier, phone company or government office and asks you to tap a link, call a number or reply with details. The aim is to steal login details, OTPs, card data or money, or to install malware.
Why do smishing links use https?
Because https is free and easy to get. Certificate authorities such as Let’s Encrypt issue certificates to anyone who controls a domain, including scammers. Https only means the connection is encrypted between you and that site. It doesn’t prove who runs the site, so a padlock on a link in a text message tells you nothing about whether it is safe.
How can I report a scam SMS in India?
Report suspected fraud calls, SMS and WhatsApp messages through the Chakshu facility on the Sanchar Saathi portal run by the Department of Telecommunications. If you have already lost money, call the national cyber crime helpline 1930 immediately or file a complaint at cybercrime.gov.in. Keep a screenshot of the message and the sender number.
