Common Social Engineering Indicators
Smishing messages tend to share the same red flags. Watch for any of these in texts you receive:
- Unknown or spoofed sender. Real institutions identify themselves clearly and use consistent numbers or short codes.
- Urgency or fear. Phrases like "your account is locked" or "act now" pressure you to click before you think.
- Partial account info. A few visible digits is easy to fake and doesn't prove the sender is legitimate.
- Look-alike URLs. Attackers swap letters for similar characters (for example, a Greek "α" that looks like "a") or use unusual domains.
- Unexpected login links. If you didn't initiate the interaction, be wary — legitimate services typically direct you to their app or official site, not a link in a text.
- Generic greetings. Real notifications usually address you by name and reference the actual service you use.
Example: spot the red flags
Tap each to see why it's suspicious. This is an illustration — real attempts may look different, but the patterns are the same.
4:08
Unknown Sender
You recently used a
toll road. A balance of $6.75 remains unpaid. Pay here to
avoid late fees:
[LINK]
Now