
Smishing
Smishing is phishing delivered by text message. An attacker sends an SMS impersonating a bank, a courier, a government office or a colleague, and asks the recipient to click a link, call a number, or reply. The name is a contraction of SMS and phishing, coined in 2006.
You already know not to click. That is the odd thing about this subject: smishing may be the best-advised threat in consumer security. Four separate government bodies publish guidance on it, banks text their customers about it, and phone carriers run a free reporting service for it.
And yet almost nothing published about it carries a number. Search the term on either major engine and you will get warning signs, examples, and a list of things to avoid, from pages that mostly agree with each other. What you will not get is the regulator's own data, or an answer to the two questions people actually ask once they have absorbed the advice: does forwarding these to 7726 accomplish anything, and was replying STOP a mistake?
This page answers both, and reports what the numbers show. They are more interesting than "it is getting worse."

Explain it like I'm 10
A text message is a very short letter. Anyone can send one to anyone, and your phone has no reliable way to check that the name at the top is real. It just shows you what the sender typed.
Someone who wants your money can send millions of these for very little cost. They do not need most people to answer. They need a few. So they write something that makes you move quickly: a parcel that needs a fee, an account that is about to close, a payment you do not remember making.
The message is not evidence of anything. It is a guess, sent to a very large number of people, hoping to reach the small number for whom it happens to be plausible today.
Smishing Quiz
Test your knowledge about Smishing - maybe you already know everything about it.
What is smishing?

What the numbers actually say
Here is the figure no page in the captured results carries. In its April 2025 data spotlight, the US Federal Trade Commission reported that consumers lost $470 million to scams that started with a text message in 2024 - five times the amount reported in 2020.
That sentence is usually where the reporting stops. The FTC's own summary does not stop there, and the rest of it changes the meaning.
What was measured | Figure | Direction | Scope |
|---|---|---|---|
Reported losses to text-initiated scams, 2024 | $470 million | Five times the 2020 figure | Reports to the FTC's Consumer Sentinel Network |
Number of text-scam reports | Declined | Down, over the same period | Same dataset |
Share of reports involving a money loss | 5% in 2020 to 11% in 2024 | Up, more than doubled | Same dataset |
Share of text frauds in the top five categories | About half | - | Same dataset |
Read the three rows together and the story stops being about volume. Fewer people reported a text scam, and more of the ones who did had actually lost money. The average encounter got more expensive, not more common. That is a different problem from the one the phrase "smishing is on the rise" describes, and it calls for different attention.
What these numbers do not cover
They are reports to one agency, in one country, from people who chose to report. Nobody reports a text they deleted. A rising loss figure is partly a rising willingness to file, and partly the fact that the categories reaching people in 2024 asked for larger sums.
The categories matter to the reading as well. A dataset in which fake toll notices and job offers are prominent is measuring a different year from one dominated by parcel notifications, and the sums each category asks for are not comparable. A rise in reported losses can come from the same number of people encountering costlier propositions, which is closer to what these three rows describe than any change in how many messages were sent.
The number that circulates instead
There is no count of how many smishing messages are actually sent, and the figures that circulate are not it. The number you will see quoted most often - over 19 billion spam texts in a single month - measures spam, which includes ordinary unwanted marketing, and it comes from a company that sells call and text blocking. Spam volume is not fraud volume, and a vendor metric with no published method is not a substitute for one.

The part the advice does not cover
The FTC also published what the money was lost to. Five categories account for about half of all text frauds reported in 2024: fake package delivery, bogus job offers, fake fraud alerts about a suspicious purchase, fake unpaid tolls, and "wrong number" messages that arrive looking misdirected.
Now read that list with the standard advice in mind. Two of the five do not turn on a malicious link at all.
Task scams are the clearest case. The FTC describes them as promises of online work requiring people to complete a series of online tasks, which end with requests for people to invest their own money. There is no credential harvesting page. There is a sequence of small requests over days or weeks, each one reasonable given the last, ending with the victim sending funds from their own account through channels they chose.
"Wrong number" approaches work the same way structurally. The first message is not an attack. It is a misdirected note to someone else, and the attack is the conversation that follows it, sometimes over weeks.
Why that matters for a careful person
A reader who has optimised entirely around not clicking has done the right thing and still has a gap. Link inspection is a check you run once, on arrival. These two categories present nothing to inspect on arrival, and the harm accumulates through ordinary replies.
The practical shape of the difference: a link-based attack asks for one bad decision, made quickly, and defends itself with urgency. A conversational one asks for many small reasonable decisions, made slowly, and defends itself with rapport. The first is what warning-sign lists were built for. The second passes the warning-sign tests, because by the time money moves there is nothing suspicious in the message that carries it.
One vendor page in the same search results puts the training consequence plainly: a recognition programme focused only on bad URLs misses attacks with no URL to inspect. That is correct, and the regulator's own category list already implied it a year earlier.

Does forwarding to 7726 do anything?
This is the question the sceptical reader arrives with, and no page on either engine's first results answers it. The three digits spell SPAM on most keypads.
The Government of Canada's Get Cyber Safe programme publishes a page devoted to the service. Forwarding a message, it says, "will tell your cellphone provider about the spam messages so they can investigate it and improve their filter for all customers." It is free, and it does not count towards a data or messaging allowance. The automated reply reads: "Thank you for reporting spam. We'll take it from here."
Note what that reply is not. It is not a case number, and nothing is coming back to you.
The same three digits behave differently by country
In the United States, the shortcode is administered by CTIA's Industry Code Administration, a neutral, non-commercial body, and carriers use what consumers submit to calibrate spam filters and blocking tools. The US flow does something the Canadian one does not: it replies asking for the sender's number, so the campaign behind the message can be analysed.
Same three digits, different conversation. If you have forwarded a message and been asked a follow-up question, nothing has gone wrong. That is the American flow working as designed. The arrangement is international rather than a single service, and industry accounts trace it to a GSMA spam-reporting pilot around 2010.
The honest limit
The mechanism is documented. Its effect on you personally is not. No effectiveness measurement was located for this article - nothing establishes that forwarding reduces what arrives on your own handset, and the government page that describes the service does not claim it does.
The accurate mental model is calibration data for a filter that protects everyone, contributed by you. It is not a complaint that gets answered, which is why it feels like nothing happens. Something happens; it just does not happen to you.

Was replying STOP a mistake?
The advice here is blunt and it comes from a government, not a vendor. Get Cyber Safe's guidance on fraudulent text messages says: "Don't reply to suspicious texts, even if asked to text 'STOP' or 'NO'."
What none of the captured pages explains is why the same five letters are both required and dangerous, and the explanation resolves the question properly. Reading the advice against how opt-out keywords ordinarily work, the distinction is this (a derived reading, not a quoted one): STOP is a compliance obligation for a legitimate sender and a liveness signal for a criminal. A real marketer must honour it. A fraudster learns from it that a human being reads this number and responds to prompts.
So the instruction is not "never send STOP to anything." It is "do not send it to a message you already suspect is fraudulent," because the two kinds of sender do opposite things with the same word.
The US regulator words it more bluntly
The Federal Communications Commission publishes its own consumer page on the subject, dated 1 February 2024, which describes the term as a mashup of SMS, for short message service, and phishing. Its instruction is broader than Canada's and admits no exceptions at all: "Never click links, reply to text messages or call numbers" in a suspicious message.
Two governments, the same position, phrased at different widths. Neither is telling you the word STOP is dangerous in general. Both are telling you that a message you already doubt is the wrong place to use it.
If you have replied to one, the practical consequence is more messages, not a compromised phone. A reply is a signal, not an exploit. Delete, block the number, and forward the next one instead.

The word is almost exactly twenty years old
The term was coined by David Rayhawk in a post on the McAfee Avert Labs blog dated 25 August 2006, which trade press reported at the time. This article was written four days short of the twentieth anniversary.
The dictionaries took their time. Merriam-Webster lists the first known use as 2006 and added the entry in April 2023 - a gap of roughly seventeen years between a security researcher naming something and a lexicographer agreeing it had stayed. The Cambridge Dictionary gives the pronunciation as /ˈsmɪʃ.ɪŋ/ and notes "SMS phishing" as the alternative form.
There is a small tell in the search data. Newer coinages attract pronunciation questions; this one does not, and no such cluster appears in what people ask about it. Reference works also tend to file it inside phishing rather than beside it. Both are what a settled word looks like.

What the standard smishing advice is worth
Take the plain answer first: the advice is right. Multiple governments publish it, it is not in dispute, and nothing here overturns it. What this article adds is scope.
- Don't click links in unexpected messages - correct, and now incomplete. It covers three of the FTC's top five categories and does nothing against the other two.
- Don't reply, including STOP - correct, and the reason is specific: a reply confirms a live, responsive recipient to someone who was guessing.
- Verify through a channel you chose - the instruction that survives the gap. Calling the bank on the number from your card, or opening the courier's app yourself, works whether or not the message contained a link.
- Forward it to 7726 - useful, documented, and useful to everyone rather than measurably to you.
Who actually publishes this guidance
Be precise about the sources here, because "experts say" is doing a lot of unearned work across this subject. The Government of Canada's Get Cyber Safe programme defines it as "a type of phishing scam where cybercriminals try to trick you by sending fraudulent text messages", and its pages on the topic and on the reporting shortcode were both revised in January 2026, which is more recent than most of what ranked above them in the results captured for this article.
- The FTC supplies the measurement, from its own consumer-report dataset.
- The FCC supplies the consumer instruction, in the bluntest form of it.
- The reporting shortcode in the United States is run by an industry body, not a government one, which is a distinction to keep straight when you decide how much weight each source carries.
You will notice this page names no app and no product. That is deliberate. A large share of what ranks for this term is published by companies selling blocking or filtering, and the honest answer to "what should I install" is that no independent evaluation was located to support recommending anything in particular.

What this page cannot tell you
Three limits, stated plainly.
No count of smishing messages was located for this article. The available volume figures measure spam, a much larger category, and come from vendors with a product in the market.
No effectiveness measurement for 7726 was located. The mechanism is on the record; the outcome for an individual is not.
Three sources for this article could not be retrieved. The FTC data spotlight, the FCC's consumer pages, and the Merriam-Webster entry all returned HTTP 403 to automated retrieval. Their figures and dates are reported here as established and widely reproduced, they are quoted no further than that, and they are deliberately not linked, because linking a page we could not read would imply a check that did not happen.
One thing that is not this subject
Search engines attach a persistent question to this term about area codes you should supposedly never answer. It belongs to phone calls rather than texts, and the circulating lists contradict each other - one of the numbers commonly listed is not an area code in the relevant sense at all. The FCC's own guidance on the related one-ring scam recommends no such list; it advises not returning calls from numbers you do not recognise, and checking whether a number is international before calling back. Voice fraud is a separate subject with its own mechanics.

The short version
Smishing is phishing over SMS, and it is nearly twenty years old under that name. The advice you have already heard is correct and government-published, and this page does not ask you to drop any of it.
What has changed is the shape of the problem. Reported losses reached $470 million in 2024, five times the 2020 figure, while the number of reports fell and the share involving a loss more than doubled. Fewer encounters, costlier ones. And two of the five categories carrying that money do not involve a link to avoid, which means link inspection alone stopped being a complete defence some time ago.
The one change worth making: stop treating the link as the whole danger. Verify through a channel you chose, not one that arrived in a message. Forward what you get to 7726, understanding it as data for a shared filter rather than a complaint. And treat a conversation that starts by accident with the same care you already give a parcel notification that arrives out of nowhere.