Scams & FraudBeginner5 min read

Phishing and smishing: the scam that keeps evolving

The fake email or text that looks real, and the four-second check that beats 95% of them.

Phishing (email) and smishing (SMS) are attempts to trick you into clicking a malicious link or giving up login credentials. They've gotten dramatically better over the past decade. The classic 'Nigerian prince' grammatical tells are gone — today's phishing emails look exactly like real Amazon order confirmations, real bank alerts, real IRS notices.

Common formats right now

  • Package delivery notifications ('We couldn't deliver your package — click here to reschedule').
  • Fake bank fraud alerts ('Suspicious transaction — verify your account or we'll freeze it').
  • Apple/Microsoft/Google account 'security warnings' asking you to log in.
  • Tax return fake notices ('You're eligible for a $1,200 refund').
  • Subscription renewal alerts ('Your Netflix will be charged $19.99 — click to cancel').
  • Text messages impersonating your CEO or boss asking you to 'handle something quickly.'

Why it works: volume, timing, and AI polish

Phishing is a numbers game played at industrial scale. Sending a million texts costs a criminal operation almost nothing, so a response rate of a fraction of one percent is a profitable day. The messages are timed to coincide with reality: package texts surge in December when everyone actually is expecting deliveries, tax notices arrive in March and April, and 'unusual sign-in' alerts follow every major data breach in the news. And the writing has changed — AI tools now generate flawless, personalized messages in any language, so the old advice to 'look for bad grammar' is obsolete. Assume every message is well-written and judge it on structure instead: who sent it, where the link really goes, and whether you asked for it.

~$470M
Reported US losses to text scams in a recent year
FTC data; most losses go unreported
300K+
Phishing complaints to the FBI per year
Consistently the most-reported cybercrime
4 sec
Time the sender-and-link check takes
Beats the overwhelming majority of attempts

How one click becomes a drained account

The link itself rarely 'hacks' your phone. It takes you to a pixel-perfect clone of a real login page — your bank, Microsoft, your state's toll authority — where you type your username and password straight into the criminal's database. Modern kits relay those credentials to the real site in seconds and prompt you for the two-factor code too, defeating SMS-based 2FA in real time. From there the playbook is fast: change your contact email, add a new payee or Zelle recipient, and move money before you notice anything. A single credential harvested from a fake 'unpaid toll' page has emptied five-figure accounts by dinner.

The four-second check

  1. Look at the sender's actual email address, not the display name. Real bank emails come from the bank's domain. Fakes come from slightly-off domains like 'chase-support.xyz' or 'chasee.com.'
  2. Hover over links (don't click). The actual URL pops up. If it's not going to the real domain, it's a scam.
  3. Ask: did I request this? A random 'package delivery alert' from a service you didn't use is a scam 100% of the time.
  4. When in doubt, don't click the link. Open a new tab and go to the real website directly.
Never give a 'security code'
Real banks and services never call you and ask for a verification code sent to your phone. That code is the last line of defense for your account — handing it over lets the scammer log in as you. This exact scam is running against bank customers every day and it works because it feels legitimate.
SignalLegitimate messagePhishing message
Sender addressExact company domain (chase.com)Lookalike or random domain (chase-alerts.xyz)
Link destinationCompany's real domain on hoverShortened URL or misspelled domain
What it asks forLog in via your own app or bookmarkClick this link, enter credentials or codes NOW
ToneInformational, no deadlineUrgent threat: account frozen, fees, arrest
GreetingYour actual name and partial account numberGeneric 'Dear customer' or your email address
Telling a real alert from a phish (typical patterns)

Smishing's newest costumes

Text-message scams rotate through whatever feels routine at the moment. The 'unpaid toll' text swept the country recently — a few dollars owed to a toll authority, with a link to pay before 'late fees' hit — and works because the amount is too small to trigger suspicion. The 'wrong number' opener ('Hi, are we still on for tomorrow?') isn't after a click at all; it's the first line of a weeks-long pig-butchering recruitment. Fake fraud alerts asking 'Did you spend $847 at Best Buy? Reply YES or NO' use your reply to open a live conversation with a 'fraud agent' who then talks you into moving money. In every case the message itself is harmless — the trap is what you do next. A text can't steal from you; only the link, the reply, or the phone call that follows can.

Build defenses that don't rely on vigilance

  • Bookmark your bank, brokerage, and email login pages, and only ever log in through the bookmarks or official apps. This single habit makes fake login pages irrelevant.
  • Turn on app-based two-factor authentication (or passkeys) for email and financial accounts — codes generated on your device can't be intercepted like SMS.
  • Use a password manager: it won't autofill your bank password on a lookalike domain, which turns it into an automatic phishing detector.
  • Enable transaction alerts so any real problem announces itself through a channel you trust, making 'urgent' texts easy to ignore.
  • Report and delete: forward phishing texts to 7726 (SPAM) and emails to reportphishing@apwg.org, then delete. Never reply, even to say 'STOP' — replies confirm your number is live.

If you already clicked or replied

  1. 1
    Entered a password? Change it now

    Change it on the real site immediately, plus anywhere else that password was reused, and turn on two-factor authentication.

  2. 2
    Entered card or bank details? Call the issuer

    Report the card as compromised and watch for small test charges — criminals verify stolen cards with $1 to $5 transactions before selling them.

  3. 3
    Gave up a 2FA code? Treat the account as taken

    Call the institution's fraud line, lock the account, review recent activity and payees, and check that recovery email and phone weren't changed.

  4. 4
    Report it

    File at reportfraud.ftc.gov, and at identitytheft.gov if personal data was exposed. Speed matters more than embarrassment.

The bottom line

Phishing wins by imitating routine, so the counter is routine too: check the real sender address, never log in through a link, and treat every unexpected message about money or accounts as guilty until verified through your own bookmark or app. The scam evolves constantly; the four-second check hasn't needed an update in a decade.

Check your understanding

1 of 3
You get a text: 'USPS: your package couldn't be delivered, update your address here: usps-redelivery.info.' You never ordered anything shipped by USPS. What's the best move?

Not quite — try again.

The Worth letter

Get smarter about money every week

One email, no spam — practical guides and Worth updates. Unsubscribe anytime.

Put this into practice

Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.

Start free trial