Phishing has moved beyond email. Text-message scams (smishing) and phone-call scams (vishing) now account for a large share of fraud reports, partly because caller ID and sender names are trivial to fake. The good news: the underlying tactics repeat across almost every version of these scams, so recognizing the pattern matters more than memorizing specific examples.
Common scam formats you'll actually encounter
- Missed delivery texts claiming a package couldn't be delivered, with a link to "reschedule" that leads to a fake payment or login page.
- Bank fraud alerts — a text or call claiming suspicious activity on your account, asking you to "verify" by providing your card number, PIN, or a one-time code.
- Government agency impersonation — calls claiming to be the tax authority, threatening legal action or arrest unless you pay immediately, often via gift cards or wire transfer.
- One-ring scams — a call that rings once and disconnects, hoping you'll call back a number that charges premium rates.
- Family emergency scams — a call claiming to be a relative in trouble (sometimes using AI voice cloning from a few seconds of audio) asking for urgent money.
- Job or prize scams — a text about a job offer or a prize you didn't enter, requiring an upfront "fee" or personal details to claim it.
The tells that hold up across all of them
- Manufactured urgency. Scammers want you to act before you have time to think or verify. "Act now," "your account will be locked in 24 hours," and "final notice" are all pressure tactics.
- A request for payment in gift cards, wire transfer, or cryptocurrency. No legitimate bank, government agency, or company asks for these as a payment method — ever.
- A request for a one-time verification code. Banks and services don't call or text asking you to read back a code they just sent — that code exists specifically to prove a login attempt was you, and reading it out loud hands that proof to the scammer.
- A link in an unexpected text. Even if the sender name looks right, sender names in texts are not verified and can be spoofed by anyone.
- A caller who already seems to know some of your information. Scammers often have partial data from a previous breach and use it to sound credible — a name, last four digits, or old address doesn't confirm they're legitimate.
The single habit that defeats nearly all of these: verify independently
Never use the phone number, link, or callback number provided in the suspicious message itself. Instead, go to the official number or website through a source you already trust — the number on the back of your card, the bank's app, or a site you typed in yourself rather than clicked to. If it's a real alert, it'll show up there too. If someone calls claiming to be a relative in distress, hang up and call that relative directly on the number you already have for them.
What to do after you spot one
- Don't click, don't call back, don't reply — even replying "STOP" confirms your number is active to some scam operations.
- Forward suspicious texts to 7726 (SPAM), a reporting short code supported by most US carriers, which helps carriers identify and block scam campaigns.
- Block the number after reporting, though be aware scammers frequently rotate numbers.
- Turn on your phone's built-in spam filtering — both iOS and Android offer settings to silence or filter calls from unknown numbers, and most carriers offer a free scam-call filtering service.
- If you already provided information or made a payment, contact your bank or card issuer immediately to flag the transaction, and consider checking whether your data appears in a known breach (see our guide on checking for leaked passwords and emails).
Quick recognition checklist
- Urgent deadline or threat → treat with suspicion.
- Asked to pay by gift card, wire, or crypto → it's a scam.
- Asked to read back a one-time code → it's a scam.
- Unexpected link in a text → don't click; go to the official site or app directly.
- Unsure about a call or text → hang up, look up the official number yourself, and call that instead.