Why texts land in the right thread
Phones group messages by sender name. If a criminal sets the sender ID to match your bank or a carrier, the phone files the scam into the existing conversation alongside real alerts. This is a limitation of the messaging standard, not a sign that your account was compromised.
Treat the thread as meaningless for verification. What matters is where the link goes and what the message asks you to do, never who it claims to be from.
The families of message in circulation
Delivery fees remain the volume leader, followed by bank security alerts asking you to confirm or cancel a transaction, tax refunds and debts, subscription renewals for streaming or antivirus you supposedly bought, and the family-impersonation message that starts 'Hi Mum, this is my new number'.
The 'Hi Mum' variant deserves particular attention because it uses no link at all. The conversation moves to a messaging app, builds sympathy over an hour or a day, and ends with an urgent transfer request because the phone is broken and banking is locked out. The defence is a phone call to the person's old number.
- Delivery or customs fee on a parcel
- Bank alert asking you to confirm or cancel a payment
- Tax refund or overdue tax demand
- Subscription renewal with a 'cancel here' link
- 'Hi Mum / Hi Dad, this is my new number'
- Job offers, prize draws and one-off investment tips
Three checks that settle almost every message
First, does it ask for money, credentials or a code? Genuine notifications inform; scams instruct. Second, where does the link actually go? Press and hold to preview the address and read the part immediately before the first single slash, because that is the real domain. Third, can you verify it somewhere else? Open the bank app, the carrier app or the official account directly.
If a message passes none of these, delete it. If it passes some, still verify independently. The cost of the extra minute is nothing compared with the alternative.
- It instructs rather than informs
- The domain is not the organisation's real one
- There is a deadline measured in hours
- It asks for a code, PIN or full card details
- The same information is not visible in the official app
Blocking and reporting
Forward scam texts to your national reporting shortcode where one exists, then block and delete. Reporting genuinely works: it feeds the lists that carriers and security software use to block the sending numbers and the destination domains, often within hours.
Modern phones and security suites can filter messages from unknown senders and warn on known scam links. Turning both on removes a large share of these messages before you see them, and mobile security apps add domain blocking that works across browsers and messaging apps.
If you clicked or replied
Clicking alone is rarely harmful on an updated phone. If you entered card details, freeze the card. If you entered a password, change it on that service and anywhere else it was reused, starting with email. If you read out a code, recover the affected account immediately.
If you installed an app from the link, especially on Android, restart in safe mode, revoke accessibility and device-administrator permissions from it, uninstall it, then run a full scan and change passwords from a different device.
- Card details entered: freeze and replace the card
- Password entered: change it and every reuse of it
- Code shared: recover that account now
- App installed: safe mode, revoke permissions, uninstall, scan
- Money sent: call the bank and say it is authorised push payment fraud
