Awareness

What Is Smishing? How to Stop Scam Texts

The hook: the two seconds that change everything#

A friend texted me two words: "Got caught." Minutes earlier, a message had landed on their phone claiming to be from the tax office, warning of a "mandatory verification," with a link to gov-taxrefund.help.

Obvious, right? The real tax authority's domain doesn't end in .help. The scam name stitches two familiar words together to manufacture a feeling of trust. But this article isn't about "how to spot a fake link" - thousands of those exist already. It's about something more uncomfortable: why the same people who read those articles still click.


The attacker's view: why smishing is the cheapest effective attack#

For an attacker, SMS phishing - smishing - is a gift, for three reasons.

  • The channel is trusted by default. People have been trained for decades to distrust links in email. SMS still feels personal and safe: your bank, your courier, your doctor all text you. That inherited trust is exactly what gets exploited.
  • The screen is small and attention is short. Mobile browsers routinely hide the full URL, and notification previews show only the link text, never the actual domain. The signals you'd use on a desktop simply aren't visible.
  • The cost is near zero. Bulk SMS tools and leaked phone-number lists cost pennies. Even a 0.1% response rate is profitable, so attackers send millions and don't care about the 99.9% who ignore it.

In my friend's case the attacker combined authority (a government body) with urgency ("verification is mandatory, now"). That's a textbook pressure combination, and it works regardless of someone's IQ or IT knowledge, because it targets instinct, not logic.


The defender's view: why repeating "be careful" has limits#

That reply - "got caught" - isn't random. In security we call it the awareness-behaviour gap: people know the rule, but in a specific, emotionally charged moment the rule doesn't fire. Three things drive it.

  • Cognitive fatigue. The average person gets dozens of notifications a day. The brain leans on shortcuts ("looks like it's from the bank" = real), because fully analysing every message is exhausting and unsustainable.
  • Context collision. If you genuinely are waiting on a parcel, or you do have an unpaid bill, a scam message that mentions exactly that lands directly on a real worry. Timing does most of the work.
  • The mobile environment strips away signals. On a desktop you see the full URL in the address bar. On a phone you often see only a button that says "Verify here."

The lesson for anyone doing training: telling people "be careful" for the tenth time doesn't work better than the first. You need two layers - the human (awareness) and the technology (a system that stops the threat before the human has to make a decision at all). For teams, that human layer is best built with realistic practice, not lectures - which is the case for phishing simulations.


Practical defence: the 5-point check#

If a link has already arrived and nothing has flagged it, run these five checks before you tap.

  1. The domain ending. A real .gov site is not gov-refund.help; mybank.com is not mybank.account-verify.info. Read the ending right before the first single slash, not the reassuring words in front of it.
  2. The sender. Institutions rarely text from a random personal mobile number.
  3. The urgency language. "Mandatory," "immediately," "your account will be blocked" are markers of emotional pressure, not how official notices actually read.
  4. Were you expecting this? If your bank, the tax office, or a courier reaches out unprompted, treat that as a signal, not a coincidence.
  5. Verify on another channel. Open a browser yourself and type the known address by hand, or call the number on your card. Never use the link you were sent - and don't assume a number you found via a Google or AI search is genuine either; scammers plant fake support numbers there too.

Technical defence: settings that protect you even when you don't notice#

This is the most important part. A checklist depends on you being alert every single time. Settings work when you're tired, distracted, or in a hurry - which is exactly when you get caught. Turn these on once. (These pair well with the broader steps in our Android and iOS hardening guides.)

Android (Google Messages)#

Google Messages has built-in protection that warns about dangerous links and can block access to malicious sites when a message is flagged as suspicious.

How to turn it on:

  1. Open the Google Messages app.
  2. Tap your profile icon (top right) → Messages settings.
  3. Choose Spam protection (on some phones: "Protection & Safety" → "Spam Protection").
  4. Turn on Enable spam protection.

With it on, the system checks links in your messages against Google's safety database and, if a link is judged dangerous, blocks it until you mark the message as "Not spam" yourself.

Worth knowing: Android doesn't have a single switch for "block all links from unknown numbers." Protection works through threat analysis, not a contact list, so pair Spam protection with the 5-point check above.

iOS (iPhone Messages)#

iPhone has a feature that comes closest to what people actually want: it stops you opening a link from a sender who isn't in your contacts until you approve them.

iOS 26 and newer:

  1. Open the Messages app and tap the filter icon (top left) → Manage Filtering.
  2. Turn on Screen Unknown Senders. (The matching notification controls also appear under Settings → Apps → Messages → Unknown Senders, but the toggle itself lives in the Messages app.)
  3. Optionally turn on Filter Spam so suspicious messages are sorted automatically.

iOS 18 and older:

  1. Settings → Messages.
  2. Find Message Filtering.
  3. Turn on Filter Unknown Senders.

With this on, messages from unknown numbers go to a separate "Unknown Senders" list and - crucially - the links in them can't be tapped until you either mark the sender as known or reply to the message. That's effectively "links from strangers are off by default."

One trap: if you ever reply to the message - even once, even just to mock the scammer - the sender can get treated as "known" for future messages. So never reply to a suspicious text, full stop.


Quick wins vs long-term strategy#

Quick win (5 min) Long-term
Android Turn on Spam protection Check the "Spam & blocked" folder regularly; teach family to read domain endings
iOS Turn on Screen Unknown Senders Never reply to unknown messages; periodically review the "Unknown Senders" list
Both Add your bank's / tax office's real number to contacts from an official source Run a short family or team drill with a real smishing example

Last word#

The friend who wrote "got caught" isn't an exception - they're a statistic. Phishing and smishing success rates don't fall because people magically get smarter in a vacuum. They fall when technology starts doing the work instead of memory.

Your job - as a manager, an educator, or just a family member - isn't only to remind people to "be careful." It's to help them turn on the settings, once, that will protect them every time after that.


Summary#

  1. Smishing works on urgency, not ignorance. The lure is a two-second window - a delivery, a fine, a refund - not a test of how much you know.
  2. Read the end of the domain, not the start. gov-taxrefund.help is the .help domain, not the tax office. Everything before the final dot is decoration.
  3. Turn on the filter. Android: Google Messages → Messages settings → Spam protection. iPhone (iOS 26+): Messages → filter icon → Manage Filtering → Screen Unknown Senders, which also stops you opening links from strangers.
  4. Never reply, not even once. On iOS a reply can promote the sender to "known" and re-enable their links.
  5. Save real numbers yourself. Add your bank's and tax office's contact details from a statement or official site, so you never have to trust a number that arrived in a text.
  6. Get to the account another way. Open the bank's own app or type the address by hand. If the message was real, the same notice is waiting there.
  7. Extend it to the phone and the browser too - the same reflex covers scam numbers surfaced by AI assistants.

Want to test whether your team would actually catch a real one? Get in touch about a phishing and smishing simulation built around your organisation.

Subscribe

Get new posts as we publish them

We publish hardening guides, threat notes and a weekly cybersecurity roundup. Add our feed to your reader and new posts turn up on their own - no email address, no account, no tracking.

Subscribe via RSS

New to feeds? A reader such as NetNewsWire, Feedly or Thunderbird watches this URL for you: https://bluwarden.com/feed.xml