That text message from Royal Mail, your bank or HMRC might look completely legitimate. It probably isn’t. Smishing, also known as SMS phishing, is one of the fastest-growing forms of cybercrime, using fraudulent text messages to trick people into handing over personal information.
Here’s how to spot a scam text message, avoid becoming a victim, and what to do if you’ve already clicked.
Most people have now heard of phishing – the fraudulent emails designed to steal your personal details or hijack your accounts. Fewer people are familiar with smishing (SMS phishing), which is essentially the same scam delivered by text message. Rather than sending a fraudulent email, criminals send a malicious text message that appears to come from a trusted organisation.
The reason smishing has grown so rapidly is straightforward: it works. We have become conditioned to trust text messages in a way we no longer trust emails. We expect texts to be direct, urgent and real. Fraudsters know this, and they exploit it expertly.
How Smishing Works
A smishing attack follows a well-worn formula. You receive a text message that appears to come from a trusted organisation – your bank, HMRC, Royal Mail, a delivery company, or a government body such as the NHS or DVLA. The message creates a sense of urgency. There is a problem with your delivery. Your account has been suspended. You owe a small customs fee. Your package is waiting. You must act now.
The message contains a link. That link takes you to a website that looks convincingly like the real thing – the correct logo, the right colour scheme, familiar layout. You are asked to enter personal details: your name, address, date of birth, account number, card details, or password. The moment you do, those details are in the hands of criminals.
Some smishing attacks go further. Rather than simply stealing your login details, they attempt to trick you into installing malicious software or exploit security vulnerabilities on your device. If successful, this malware may allow criminals to monitor activity, steal stored passwords or intercept authentication codes.
Common Smishing Examples in the UK
You may well have seen some of these yourself:
Royal Mail and Parcel Delivery Text Scams – Perhaps the most common parcel delivery text scam claims your parcel couldn’t be delivered because a small fee is outstanding. The text directs you to what appears to be the Royal Mail website, but it’s actually a fake Royal Mail text designed to steal your payment details.
Bank Text Scams – Bank text scams often warn of suspicious activity on your account and ask you to verify your details or call a fraudulent number.
HMRC Tax Refund Scams – A text claiming you are owed a tax refund and directing you to a government-lookalike website to claim it. No personal details, no refund; just your information handed to criminals.
NHS / GP Appointment Scams – Messages claiming to be from the NHS asking you to confirm or book an appointment. These often appear particularly convincing because we are accustomed to genuine NHS text messages.
Competition Win Notifications – You have won a prize. Click here to claim. You haven’t won anything.
Why Smishing is So Effective
Several factors make smishing particularly difficult to detect and resist:
Phone numbers are easy to spoof. Criminals can make a text message appear to come from a recognised name or number – even one that appears in an existing conversation thread on your phone. You might see a message that appears to continue a legitimate conversation with your bank, when in fact it has been inserted by a fraudster.
We act on texts more quickly. Research consistently shows that text message scams are more likely to catch people off guard than fraudulent emails because text messages feel more personal and immediate. As a result, we are often less likely to pause and scrutinise them carefully. The combination of a trusted-looking sender and a sense of urgency is designed to override our natural caution.
The links are hard to inspect. Unlike on a desktop computer, it is often much harder to inspect where a link really leads before opening it.
We receive genuine texts from these organisations. Banks, delivery companies and government bodies really do send texts. That familiarity makes the fraudulent versions harder to distinguish.
How to Spot a Smishing Message
No single indicator makes a text message definitively fraudulent, but these warning signs should immediately raise your suspicion:
Urgency. Any message telling you that you must act immediately, within 24 hours, or risk losing access to something, is designed to stop you thinking clearly. Pause.
Unexpected contact. If you were not expecting a text from your bank, HMRC, or a delivery company, treat it with scepticism. Genuine organisations rarely send unsolicited texts asking for personal information or payment.
Links that don’t match. One of the easiest ways to identify a fraudulent SMS is by examining the web address. Criminals often register domains that look almost identical to the genuine organisation, but are subtly wrong – gov-uk-hmrc.com instead of gov.uk, for example.
Requests for personal or financial information. Organisations such as your bank, HMRC, Royal Mail or the NHS may send genuine text messages, but they will not ask you to provide sensitive financial information, passwords or security credentials by text.
Poor spelling or grammar. Not all smishing messages contain errors – some are extremely polished – but mistakes remain a useful warning sign.
Generic greetings. “Dear Customer” rather than your name could suggest a mass-sent fraudulent message. Generic greetings aren’t proof of fraud, but when combined with other warning signs they should raise suspicion.
What to Do if You Receive a Smishing Text
If you receive a suspicious text, the safest course of action is straightforward:
Do not click any links. Even if you are genuinely expecting a delivery or owe money to HMRC, do not use the link in the message. Instead, type the company’s web address directly into your browser.
Go directly to the official website. If there is a genuine issue with your account or delivery, you will be able to find it by visiting the organisation’s website directly via your browser, or calling the number on the back of your bank card.
Report it. In the UK, you can forward suspicious texts to 7726 (which spells SPAM on a phone keypad). This is a free service run by mobile network operators and helps identify and shut down smishing operations.
Delete the message. Once reported, delete it so you are not tempted to click the link later.
What to Do if You’ve Already Clicked
If you have already tapped a link in a suspicious text, do not panic – but do act quickly.
Do not enter any information. If you have clicked the link but not submitted any details, you may have avoided the worst of it. Close the browser immediately.
Change your passwords. If the message was impersonating a service you use, change your password for that service immediately, and for any other account that shares the same password.
Contact your bank. If you entered any financial details, call your bank immediately using the number on the back of your card. Explain what happened. They can monitor your account, block compromised cards, reverse unauthorised payments where possible and advise on the next steps.
Check for malware. If your phone has behaved unusually since you tapped the link, such as unexpected activity, battery drain, unfamiliar apps, it may have been compromised. We can assess the device, remove known malware where possible and advise whether a factory reset or further security measures are necessary.
Report it to Action Fraud. The UK’s national fraud reporting centre can be reached at actionfraud.police.uk or by calling 0300 123 2040.
Protecting Yourself Going Forward
A few straightforward habits significantly reduce your exposure to smishing:
Never click links in unexpected texts. This single habit eliminates the vast majority of smishing risk. Always navigate to websites directly.
Enable two-factor authentication, or passkeys where supported, on important accounts. Even if criminals obtain your password, 2FA means they still cannot get in without the second code. Enable it on your banking, email, and any account that holds financial or personal data.
Keep your phone’s operating system updated. Updates patch security vulnerabilities that malware can exploit.
Be suspicious of urgency. Legitimate organisations give you time to act. Artificial urgency is a manipulation tactic.
Talk to the people around you. Older relatives and less technically confident friends and family members are disproportionately targeted by these scams. A straightforward conversation about what to look for can make a real difference.
How PC Man Can Help
If you are concerned that your phone may have been compromised following a smishing attack, or if you would like help securing your devices and accounts against this kind of threat, we are here to help.
At PC Man, we offer cyber security services for home users and businesses throughout London and the surrounding areas, including security audits, malware removal, and practical advice on keeping your devices and data safe. We also offer remote IT support if you would prefer to speak to us without us needing to visit in person.
We have been serving London since 2005, and we have seen every variant of these scams. If something has gone wrong, or if you simply want to make sure it won’t, we are here.
Call us on 020 3369 0669, email info@ilovepcman.com, or book online. A conversation costs nothing. A security incident can cost a great deal more.
Photo by Victor Larracuente on Unsplash





