Text message scams and how to read them correctly

    Text remains the most effective channel for fraud because it is short, trusted and arrives on the device people use for banking. There is no sender verification in SMS, so a message can display any name at all, and a scam message will often appear in the same conversation thread as genuine ones from your bank.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    Why texts land in the right thread

    Phones group messages by sender name. If a criminal sets the sender ID to match your bank or a carrier, the phone files the scam into the existing conversation alongside real alerts. This is a limitation of the messaging standard, not a sign that your account was compromised.

    Treat the thread as meaningless for verification. What matters is where the link goes and what the message asks you to do, never who it claims to be from.

    The families of message in circulation

    Delivery fees remain the volume leader, followed by bank security alerts asking you to confirm or cancel a transaction, tax refunds and debts, subscription renewals for streaming or antivirus you supposedly bought, and the family-impersonation message that starts 'Hi Mum, this is my new number'.

    The 'Hi Mum' variant deserves particular attention because it uses no link at all. The conversation moves to a messaging app, builds sympathy over an hour or a day, and ends with an urgent transfer request because the phone is broken and banking is locked out. The defence is a phone call to the person's old number.

    • Delivery or customs fee on a parcel
    • Bank alert asking you to confirm or cancel a payment
    • Tax refund or overdue tax demand
    • Subscription renewal with a 'cancel here' link
    • 'Hi Mum / Hi Dad, this is my new number'
    • Job offers, prize draws and one-off investment tips

    Three checks that settle almost every message

    First, does it ask for money, credentials or a code? Genuine notifications inform; scams instruct. Second, where does the link actually go? Press and hold to preview the address and read the part immediately before the first single slash, because that is the real domain. Third, can you verify it somewhere else? Open the bank app, the carrier app or the official account directly.

    If a message passes none of these, delete it. If it passes some, still verify independently. The cost of the extra minute is nothing compared with the alternative.

    • It instructs rather than informs
    • The domain is not the organisation's real one
    • There is a deadline measured in hours
    • It asks for a code, PIN or full card details
    • The same information is not visible in the official app

    Blocking and reporting

    Forward scam texts to your national reporting shortcode where one exists, then block and delete. Reporting genuinely works: it feeds the lists that carriers and security software use to block the sending numbers and the destination domains, often within hours.

    Modern phones and security suites can filter messages from unknown senders and warn on known scam links. Turning both on removes a large share of these messages before you see them, and mobile security apps add domain blocking that works across browsers and messaging apps.

    If you clicked or replied

    Clicking alone is rarely harmful on an updated phone. If you entered card details, freeze the card. If you entered a password, change it on that service and anywhere else it was reused, starting with email. If you read out a code, recover the affected account immediately.

    If you installed an app from the link, especially on Android, restart in safe mode, revoke accessibility and device-administrator permissions from it, uninstall it, then run a full scan and change passwords from a different device.

    • Card details entered: freeze and replace the card
    • Password entered: change it and every reuse of it
    • Code shared: recover that account now
    • App installed: safe mode, revoke permissions, uninstall, scan
    • Money sent: call the bank and say it is authorised push payment fraud

    Frequently asked questions

    How did a scam text end up in my bank's message thread?

    Sender names in SMS are not verified, so a scam can display your bank's name and be grouped with real messages. It does not mean your account was breached.

    Should I reply STOP?

    No. Replying confirms the number is live and usually increases the volume. Block and report instead.

    Is clicking a link enough to be hacked?

    On a current, patched phone, rarely. The risk is what you type or install afterwards.

    How do scammers get my number?

    Data breaches, leaked marketing lists and sequential dialling. Nothing about receiving a scam text implies a specific leak.

    Does a mobile security app help?

    Yes, mainly through scam-message filtering and blocking known malicious domains, which stops the phishing page before it loads.