Briefing 02 · Smishing

That “suspicious activity” text is probably not your bank.

“ALERT: a payment of $487 was attempted from your account. If this was not you, verify immediately: [link].” It arrives at dinner, it looks exactly like the real thing, and the fake login page behind that link empties accounts in minutes. This is smishing — SMS phishing — and it works because it borrows your bank's own voice.

How it runs

Fear in, credentials out.

1. The alert

Mass-sent texts spoof a bank's name or short code. The amount is specific, the tone is official, and “if this was not you” makes ignoring it feel dangerous.

2. The page

The link opens a pixel-perfect copy of the bank's login. Everything you type — username, password, even the one-time code — goes straight to the attacker, who is logging into the real bank as you type.

3. The follow-up call

Minutes later, “bank security” calls to help with the fraud they invented. Now they have your trust, and they talk you through approving transfers or reading out codes.

Why it beats smart people

Every element is borrowed from real fraud alerts you have actually received. The scam does not look suspicious — it looks familiar.

The tells

Three things the fake cannot survive.

Never do this:

Never log in through a link that arrived by text or email, and never read a one-time code to anyone who calls — including “bank security.” The code is the key to your money; the caller is the reason it is being requested.

The defense

One habit: the app is the only door.

Decide it once, tell your family once: money alerts are only ever checked by opening the bank's app or typing the bank's address yourself. Alert texts can be read — never obeyed. Pair it with a saved official number for callbacks and this entire scam category dies in your household.