How to spot phishing texts and fake links on your phone

Most phone phishing is not sophisticated. It relies on urgency, fear, and links that look almost right. Slow down and verify before you tap.

Classic warning signs

Suspicious text phone settings illustration
Urgency + odd links are classic phone phishing patterns. UI varies by brand and OS version.

What to do instead of tapping

  1. Do not open the link from the message.
  2. Open the official app or type the official site yourself.
  3. Call the number on the back of your card or in the official app, not the number in the text.
  4. Delete the message after you verify it is fake.
Suspicious text phone settings illustration
Verify in the official app — never via the text link. UI varies by brand and OS version.

Preview links carefully

On many phones you can long-press a link to preview the real URL. Look at the domain itself, not the bold marketing words in front of it.

One-time codes are keys

If someone calls or texts asking you to read a verification code, stop. Those codes are designed to prove that you are signing in—handing them over hands them your account.

Report and block

If you already tapped

  1. Do not enter credentials on the page.
  2. Leave the site and run OS updates.
  3. Change passwords for the account from a known-good device/app.
  4. Turn on 2FA if it was missing.
  5. Watch banking accounts for strange charges.

Real-world examples of risky messages

When in doubt, use a channel you already trust: the official app, a bookmark you typed yourself, or a phone number from the institution’s official site.

Protect family members

Teach one rule that sticks: never read a verification code to anyone who calls you. Offer to help relatives set official banking apps with notifications so fake SMS has less room to invent urgency.

After a close call

If you almost entered a password, change it anyway from the official app. Enable 2FA. Review account recovery email/phone fields so an attacker cannot reroute resets. Then delete the phishing message so you do not tap it later by mistake.

Email on phones deserves the same caution

Phishing is not only SMS. Mobile email clients hide full URLs. Long-press links, ignore urgency language, and navigate via bookmarks for finance sites. Turn on spam filtering and report phishing in Gmail/Outlook when the button exists.

Phishing FAQ

Do banks ever ask for passwords by SMS?
Real institutions do not need your password via a random text link.
What about short links?
Preview destinations carefully; type known sites manually when money is involved.
Is caller ID spoofing real?
Yes. Callback numbers in a text can be fake too—use official channels.
Should I reply STOP?
For marketing, yes. For obvious scams, blocking/reporting is enough; do not engage.

Related guides