Smishing is phishing by SMS or chat message. A text pretends to come from a bank, courier, power company, toll operator, employer or government office and pushes you to tap a link, call a number or reply with details. Most smishing falls into a few repeating types, and each type has a tell you can check in a few seconds.
The name joins SMS and phishing. The goal is the same as any phishing attack: passwords, card numbers, OTPs, money, or malware on your phone. Text messages work well for scammers because people read them quickly, links are short and hard to inspect, and a message seems more personal than an email.
The volume keeps climbing. The Anti-Phishing Working Group’s Phishing Activity Trends Report for Q2 2026 cites Crane Authentication, which saw smishing increase by 40% from the first to the second quarter of 2026.
The 7 most common types of smishing
1. The KYC or account block message
“Your bank account will be blocked today. Update your KYC here.” The link opens a copy of a bank login page that asks for your customer ID, password and then the OTP. The Reserve Bank of India cautioned the public again in February 2024 against frauds in the name of KYC updates. The tell: banks don’t ask you to update KYC through a link in an SMS.
2. The parcel or delivery message
A courier or postal service says a parcel is on hold because the address is incomplete or a small fee is unpaid. The page asks for your card details to pay a few rupees, and the card is then used for much larger amounts. The tell: you weren’t expecting a parcel, or the courier name doesn’t match the one the seller used.
3. The unpaid bill or disconnection notice
“Your electricity will be disconnected tonight at 9.30 pm. Call this officer.” Some versions ask you to install an app to pay. Chakshu, the reporting tool on Sanchar Saathi, lists bank, wallet, SIM, gas, electricity and KYC update messages among the frauds it accepts reports for. The tell: a real utility doesn’t give you a few hours’ notice from a personal mobile number.
4. The fine or toll message
A text claims you owe a traffic fine, an e-challan or a road toll, and that a late fee follows if you don’t pay now. The FBI’s IC3 published a warning about toll payment smishing in April 2024 after receiving more than 2,000 complaints in about a month, with texts asking for a $12.51 toll to avoid a $50 late fee. The tell: official fines are checked on the official portal, never through a link in a text.
5. The job or part-time task offer
“Earn ₹5,000 a day by liking videos.” The first tasks pay small amounts to build trust, then the victim is asked to deposit money before bigger tasks open up. The tell: a real employer doesn’t recruit by SMS or WhatsApp and doesn’t ask you to pay to work.
6. The reward, refund or prize message
Reward points that expire today, an income tax refund waiting to be claimed, a lottery you never entered. The link asks for card details “to credit” the amount. The tell: money that is owed to you never needs your card’s CVV or OTP.
7. The wrong number conversation
“Hi, is this Riya? We met at the conference.” The sender apologises for the mistake and keeps chatting. Days or weeks later the conversation moves to an investment app or a cryptocurrency platform. The tell: a stranger who keeps a “wrong number” chat going is rarely an accident.
How to read the sender before you read the message
In India, businesses send SMS through registered sender headers, the short names such as XX-BANKNM you see in place of a phone number. Under the Telecom Commercial Communications Customer Preference (Second Amendment) Regulations, 2025, TRAI told access providers to add a suffix to each header: -P for promotional, -S for service, -T for transactional and -G for government messages.
That gives you two quick checks. A message claiming to be from your bank that arrives from an ordinary ten digit mobile number deserves suspicion. And a “bank alert” with a -P suffix is advertising, not an account warning. A correct header is not proof of safety, though, because scammers also send links through chat apps, email to SMS gateways and compromised accounts.
The link itself needs reading too. Scammers hide fake sites inside believable web addresses, including addresses that begin with a date, as we explain in the date-based domain trick.
What to do with a smishing text
- Don’t tap the link and don’t reply, not even with STOP.
- If the message mentions your bank, a bill or a fine, open the official app or website yourself and check there.
- Never call a number given in the message. Some smishing texts exist only to start a phone scam, which is called vishing.
- Report the message on Chakshu on Sanchar Saathi, which takes reports of fraud calls, SMS and WhatsApp messages.
- If you lost money, call 1930 or report at cybercrime.gov.in straight away.
TRAI’s 2025 amendment also gives you seven days, up from three, to complain about spam to your operator, according to a Lok Sabha reply published by PIB.
What brands can do
When your brand’s name is in the text, your customers are the target. Register your official sender headers and publish them, tell customers which channels you never use, and find the landing pages fast. A smishing link usually points to a lookalike domain that can be reported to the registrar and host and taken down, which stops the campaign even while the texts keep arriving. TIKAJ’s takedown service handles that end to end.
FAQ
Does a registered sender header mean a text is safe?
It helps, but it is not proof. A registered header with the right -S or -T suffix shows the message came through a business route. Scammers still reach people through chat apps, international routes and hacked business accounts. Treat any message that asks for an OTP, a password or a payment through a link as suspicious, whatever the sender shows.
Why do smishing texts use such small amounts?
A small amount such as a ₹25 redelivery fee or a $12.51 toll feels harmless, so people pay without thinking. The payment is not the goal. The fake page collects the full card number, expiry date, CVV and the OTP, and the criminals then use that card for much larger transactions or add it to a wallet on their own phone.
What should I do if I tapped a smishing link?
If you only opened the page, close it and don’t enter anything. If you typed a password, change it from the official app and turn on two-step verification. If you entered card or bank details, call your bank to block the card, then report on 1930. If the link installed an app, uninstall it and check which permissions it had.
