Smishing Scams in 2026: How to Spot Fake Text Messages Before They Cost You Money
A text message arrives on your phone.
It says your Royal Mail parcel cannot be delivered until you pay a small fee.
Another claims HMRC owes you a tax refund.
Your bank supposedly needs you to verify a suspicious payment.
Or perhaps the strangest one of all appears:
A text message that seems to have come from your own number.
Welcome to smishing — phishing carried out through SMS and other mobile messages.
In 2026, scam messages remain a major problem in the UK. Ofcom reported in July that 40% of UK mobile users said they had received at least one suspicious mobile message during the previous three months.
The messages are also becoming harder to recognise. Criminals can imitate trusted organisations, disguise where messages originate and create professional-looking websites designed to capture passwords, card details and personal information.
So what should you look out for — and what should you do if you've already clicked?
What Is Smishing?
Smishing is essentially phishing delivered through a text message.
The criminal sends a message designed to persuade you to do something, usually urgently.
That might mean:
Clicking a link.
Entering Microsoft 365 credentials.
Providing banking information.
Paying a small delivery charge.
Calling a fraudulent telephone number.
Installing an application.
Providing personal information.
The message itself isn't necessarily the attack.
Its job is usually to get you to take the next step.
The NCSC defines phishing as criminals using emails, texts or calls to trick victims, often sending them to websites designed to steal passwords, banking information or other sensitive data.
Why Smishing Works So Well
We tend to treat text messages differently from email.
Most people already expect their email inbox to contain spam.
A text message can feel more immediate and personal.
There's also much less screen space available to inspect where something came from. On a smartphone, a message saying:
Royal Mail: We were unable to deliver your parcel
might initially look completely believable.
Add urgency:
A £1.49 redelivery charge must be paid today.
Now the victim is encouraged to act before thinking.
The amount may deliberately be small because the real objective isn't necessarily the £1.49.
It may be your card number, expiry date, security code, address and other personal details.
Scam #1: Fake Parcel Delivery Messages
Parcel-delivery scams remain one of the classic forms of smishing.
A message might impersonate:
Royal Mail
Evri
DPD
Amazon
DHL
or another delivery company.
It may claim:
> Your parcel couldn't be delivered. Choose another delivery date.
The link then takes you to a convincing imitation website.
The NCSC specifically warns about missed-parcel SMS scams and advises users not to click suspicious links or install applications promoted by them.
If you genuinely are expecting a parcel, don't use the link in the message.
Open the delivery company's official application or enter its website yourself and check the tracking number there.
Scam #2: Fake Bank Fraud Alerts
This one is particularly effective because it uses fear.
You receive:
“£749.99 payment attempted from your account. If this wasn't you, click here immediately.”
Your natural reaction is:
WHAT £749 PAYMENT?
And that's exactly what the criminal wants.
The link may lead to a fake online banking page designed to steal credentials.
Other versions encourage you to telephone a number where the criminal impersonates the bank's fraud department.
Never authenticate yourself to a bank using contact information supplied inside an unexpected message.
Open the banking app yourself or telephone the number printed on your bank card.
Scam #3: HMRC Tax Refunds and Tax Demands
HMRC remains an obvious impersonation target.
Scammers may claim:
You have a tax refund waiting.
or take the opposite approach:
You owe tax and must pay immediately to avoid penalties.
HMRC maintains specific guidance for checking suspicious texts and other communications. Suspicious HMRC texts can also be forwarded to 60599 for investigation.
The important thing is not to rely on how professional the message looks.
If you're uncertain, access your HMRC account independently through GOV.UK rather than following a link from the message.
Scam #4: Fake Parking, Toll and Penalty Messages
Another common technique is to claim that you owe a relatively small amount.
You might receive a message about:
An unpaid parking charge.
A toll payment.
A penalty notice.
An outstanding travel charge.
Again, urgency is usually involved:
Pay today or the charge increases to £100.
The objective is to stop you checking whether the payment is genuine.
Before paying anything, independently identify the organisation supposedly requesting payment and verify it using official contact details.
Scam #5: Fake Microsoft and Security Messages
For businesses, this can be particularly dangerous.
An employee receives:
“Microsoft: Suspicious access detected on your account. Verify immediately.”
The link leads to a fake Microsoft 365 login page.
The employee enters their email address and password.
They may even be asked to approve MFA.
Suddenly the attacker may have access to business email.
From there, they may search for invoices, customers and suppliers or attempt business email compromise.
This is why protecting Microsoft 365 with strong MFA, Conditional Access and increasingly phishing-resistant authentication such as passkeys or FIDO2 matters.
Your employees also need to understand one basic rule:
Microsoft does not need you to use a random link in an unexpected SMS to secure your Microsoft account.
Go directly to the service instead.
Scam #6: Messages From Your Own Number
Yes, it can happen.
A text can appear to come from a familiar organisation or apparently even from your own telephone number because sender information can be manipulated.
This falls under the broader problem of spoofing.
Ofcom explains that criminals can manipulate caller identification so communications appear to come from trusted organisations such as banks, HMRC, delivery companies or government bodies.
So don't assume:
“My phone says it's from X, therefore it must be X.”
Sender information is useful.
It isn't proof of identity.
Ofcom Is Tightening the Rules in 2026
There is some good news.
On 15 July 2026, Ofcom announced new rules and guidance designed to make it harder for scammers to abuse UK mobile messaging services.
The measures include stronger controls around suspicious senders, malicious links and business-message sender IDs, alongside requirements intended to help networks identify and block scam activity.
That should make life more difficult for criminals.
But no filtering system will stop every fraudulent message.
Users still need to recognise suspicious behaviour.
Warning Signs of a Smishing Message
Don't rely purely on spelling mistakes.
Modern scams can be professionally written.
Instead, consider the behaviour the message is asking from you.
Be suspicious when an unexpected message:
Creates extreme urgency.
Threatens financial consequences.
Promises unexpected money or refunds.
Requests login credentials.
Asks you to approve an MFA request.
Claims payment details have changed.
Requests card information.
Pushes you towards an unfamiliar website.
Asks you to install an application.
A message doesn't need to contain every warning sign to be malicious.
Sometimes the only unusual thing is:
You weren't expecting it.
Don't Trust the Link — Verify Independently
This is probably the most useful habit to develop.
If Royal Mail apparently sends you a message:
Don't use the link.
Open Royal Mail independently.
If your bank contacts you:
Use the banking app or number you already know.
If Microsoft apparently reports suspicious activity:
Access Microsoft 365 directly.
If a supplier asks you to change payment details:
Telephone a known contact using a number already on file.
The NCSC similarly recommends using official channels rather than contact information supplied inside suspicious communications.
That simple habit breaks a huge number of social-engineering attacks.
Report Suspicious Texts to 7726
In the UK, most mobile providers participate in the 7726 reporting service.
Forward suspicious texts to:
7726
The service is free with participating providers.
Your mobile operator can investigate where the message originated and potentially block or ban malicious senders.
The number is easy to remember because 7726 spells SPAM on a telephone keypad.
Reporting scam messages also helps protect other people rather than simply deleting the message and moving on.
What If You've Already Clicked the Link?
Don't panic.
Clicking a link doesn't automatically mean your accounts have been compromised.
What matters is what happened afterwards.
If you only opened the website, close it and don't enter anything.
If you were prompted to install software, don't do so.
If you have already installed something suspicious, have the device investigated.
The NCSC recommends running security software when users have followed instructions to install suspicious software. For a work-owned device, it specifically advises contacting your IT department.
For business devices, contact IT quickly rather than trying to hide the mistake.
Early reporting can make a significant difference.
What If You Entered Your Password?
Change it immediately.
If the same password has been reused elsewhere, change those accounts too.
Also consider whether active login sessions need revoking and whether MFA settings have been altered.
For a Microsoft 365 business account, contact whoever manages your Microsoft environment immediately.
Simply changing the password may not be enough if the attacker has already authenticated or created persistence elsewhere.
The NCSC also now recommends considering passkeys where available after credential compromise because they remove reliance on reusable passwords and provide stronger resistance to phishing.
What If You Entered Banking Details?
Contact your bank immediately using its genuine telephone number or application.
Do not wait to see whether money disappears.
Explain exactly what information you provided.
If money has already been stolen, report the fraud through the appropriate official route. The NCSC currently directs victims in England, Wales and Northern Ireland to Report Fraud, while people in Scotland should contact Police Scotland.
Speed matters.
The sooner the bank knows, the sooner it can take appropriate protective action.
Businesses Need More Than Employee Awareness
Your cyber-security strategy should not depend on every employee recognising every scam.
People make mistakes.
And modern scams can be extremely convincing.
The NCSC explicitly recommends organisations use layered technical controls against phishing rather than relying solely on users avoiding malicious links.
For businesses, those layers may include:
Phishing-resistant MFA and passkeys.
Microsoft Entra Conditional Access.
Managed smartphones and laptops.
Endpoint Detection and Response.
DNS and web filtering.
Email security.
Security awareness training.
Rapid reporting procedures.
Least-privilege access.
If one employee makes one mistake, another control should ideally prevent that mistake becoming a serious breach.
Make Reporting Easy for Employees
One of the worst security cultures a business can create is one where people are frightened to admit they clicked something.
Someone clicks a suspicious link.
They realise what they've done.
They're embarrassed.
So they say nothing.
Now the IT team doesn't know there may be a problem.
A much better response is:
“I clicked something and I'm not sure whether it was genuine.”
Great.
Now it can be investigated.
Employees should know exactly who to contact and should feel comfortable reporting suspicious messages quickly.
The goal isn't to prove employees never make mistakes.
It is to detect and contain mistakes before criminals can exploit them.
Smishing in 2026: The Key Message
Smishing has evolved considerably from the badly written text messages of the past.
Modern scam texts can look convincing, appear to come from familiar organisations and use current events or genuine services to make the story believable.
The safest approach is therefore not trying to become a forensic expert in SMS messages.
Instead:
Slow down.
Don't use unexpected links.
Verify requests independently.
Never approve authentication requests you didn't initiate.
Report suspicious texts to 7726.
And if you've already provided information, act quickly.
A convincing message is still only a message.
Verify before you trust it.
Protect Your Business From Phishing and Smishing
Hamilton Group can help businesses strengthen protection against phishing, smishing, credential theft and account compromise.
We can help with Microsoft 365 security, Microsoft Entra ID, phishing-resistant MFA and passkeys, Conditional Access, endpoint protection and EDR, managed devices, DNS and web filtering, security awareness training, and wider managed cyber security.
Technology cannot stop every employee from ever receiving a convincing scam.
But good security can make one accidental click much less likely to become a major business incident.
And if one of your employees receives something suspicious or thinks they may have clicked a scam, our aim is to make first contact on IT support requests within 15 minutes.
Call Hamilton Group on 0330 043 0069 or visit hgmssp.com to speak with one of our IT and cyber-security experts.