Derek was wrapping up Friday afternoon when his phone buzzed. A text message. It looked official. "FedEx: Your package could not be delivered. Click here to reschedule." There was even a tracking number.
Derek had ordered something online the week before. The timing felt right. He tapped the link. A page loaded asking him to confirm his address and pay a $2.35 redelivery fee. He typed in his debit card number and hit submit.
No confirmation page appeared. The site just went blank. Derek figured it was a glitch and moved on with his weekend.
Monday morning, his bank app showed three charges he did not make.
Derek received a smishing message. Smishing is phishing done through text messages. The fake FedEx text used a real-looking link to send him to a fraudulent page. When he entered his card number, attackers captured it instantly. The $2.35 fee was bait. His full card details were the real target.
Smishing works because texts feel personal and immediate. We read them quickly and act without thinking. Attackers use trusted brand names like FedEx, UPS, USPS, your bank or your phone carrier to build false confidence. The same tactic works against work accounts too. A text claiming to be from IT asking you to verify your login can hand over your work credentials just as easily.
Never tap a link in an unexpected text about a package, payment or account issue. Go directly to the company's official website instead.
Check the sender's number. Legitimate carriers and banks rarely send texts from random mobile numbers or short codes you do not recognize.
If a text asks for payment, even a small amount, treat it as a red flag. Delivery companies do not charge redelivery fees by text.
If the text claims to be from IT or your employer, contact IT directly using your internal directory. Do not use any contact information provided in the text.
Report suspicious texts to your carrier by forwarding them to 7726. In the US, this is the standard spam-reporting shortcode for most carriers.
✔ Go to your phone's messaging app and delete any unread texts from unknown numbers asking you to click a link or make a payment.
✔ If you use online banking, confirm your bank's official text alert number is saved in your contacts so you can spot fakes.
✔ If you received a suspicious text that looks work-related, report it to IT now.
I do not tap links in unexpected texts about packages or deliveries.
I go directly to the official website to track orders or resolve delivery issues.
I never enter payment details on a page I reached through a text link.
I know how to report spam texts (forward to 7726 in the US).
I report any work-related suspicious text to IT immediately
When a text asks you to click, pay or log in, go directly to the source instead. Open the company's official app or website on your own. Do not use the link in the message.