← Back to blog

Phishing SMS scams

In this article: ► Scam SMS content typically impersonates a bank or a well-known service provider ► The usual aim is to trick users into clicking a link or downloading malware ► The crimes committed include moving money out of your bank account

Phishing is nothing new. It has traditionally appeared in email and on websites, impersonating a well-known official site or announcement so that users lower their guard and give up login credentials and passwords, which are then used illegally elsewhere.

More recently, SMS impersonating banks has appeared. The content tricks the user into clicking a link, entering their banking username and password, and the money is then transferred out.

Common approaches include:

  1. You have added a new payee. If you did not request this, please go to https://xxxxxxxx
  2. A standing transfer instruction has been set up. If this was not you, cancel it at https://xxxxxxxx
  3. Your banking service has been suspended. Log in to reactivate mobile banking at https://xxxxxxxx
  4. An invitation to log in and claim a prize

You will notice these messages generally include a hyperlink. Believe it and click, and you are taken to a phishing site, or asked to download malicious software. Fall for it, fill in the form or install the software, and your personal data has formally been harvested.

The cybercrime that follows may be:

  1. Moving funds out of your account
  2. Attempting to apply for a loan or credit card in your name

How do we avoid it?

  1. Note that banks generally do not send hyperlinks by SMS asking for login credentials, and will not ask you to provide a password
  2. Consider first whether the behaviour described is credible. The scammer’s aim is to make you feel confused, which raises the chance you fall for it
  3. Do not reply to messages of unknown origin. Verify the sender’s identity first — but do not use the contact details in the message itself as the verification route
  4. Do not casually click a link relating to account information. Think twice before tapping a link
  5. Fraudulent sites and URLs usually contain unusual letters, digits or Latin characters faking an official identity
  6. Do not disclose personal data casually — protect your own interests