Atlas record

Fake Text Messages (Smishing)

Fake text messages (smishing) are the short-message form of phishing: messages sent in the name of a courier firm, the e-Devlet public services portal, a bank or a mobile operator steer you towards a fake link or towards sharing information. The small screen of a phone and the reflexive trust people place in text messages make the method especially effective.

In briefSmishing is a fraud that uses short messages sent in the guise of an institution or an acquaintance to steer you towards fake links and towards sharing information.
How it works
  • The attacker sends messages to thousands of numbers through bulk SMS systems on which the sender name can be imitated.
  • The message sets up an everyday and believable scenario such as a delivery, a refund, a fine or a discount.
  • The link leads to a fake page resembling the institution's genuine one, or to the download of a malicious application.
  • The personal and financial details entered, or the device data reached through the installed application, go to the attacker.
  • The information is used for account takeover, card fraud or reaching new victims.
Warning signs
  • A notice of a delivery, refund, fine or prize you were not expecting
  • Odd link addresses that are shortened or do not resemble the institution's domain
  • A request for personal details, card details or the installation of an application
  • Time limits that hurry you ('within 24 hours', 'last day')
  • Messages from an unknown number that nevertheless display an institution's name
  • Messages that pretend to come from a family member and ask for money from a new number
How to protect yourself
  • Make not tapping links in text messages your default behaviour.
  • Follow delivery and banking matters only through the institution's own application.
  • Do not install applications from sources you do not know; keep the device's setting for installing outside the official store switched off.
  • Confirm requests for money from people close to you by calling the person on the number you already know.
  • Use your operator's channels for reporting unwanted messages.
  • Keep your phone's operating system updates regular.
If it happens to you
  • If you tapped the link and entered information, change the passwords of the accounts concerned straight away.
  • If you gave card details, call your bank and have the card cancelled.
  • If you installed an application, disconnect the device from the network and remove the application; have a security scan run if needed.
  • Pass the message and the number on to your operator and to the official reporting channels.
  • Watch your bank account activity closely for several weeks.

The deceptive advantages of a text message

The sender name on a short message can easily be imitated, and a fake message can land in the same conversation thread as an institution's genuine messages. On a small screen it is hard to see a link address in full, and people read a text message with less suspicion than an email. When these three factors come together, the text version of a trap can reach a higher tap rate than the email version.

Common scenarios

The themes seen most often in Turkey are an 'address update' for a parcel that could not be delivered, an unexpected 'refund or payment', a 'bill discount' in an operator's name, an 'application approval' in the name of a public body, and messages pretending to come from a family member: 'my phone is broken, write to me on this number'. The common thread never changes: you are asked to tap a link, or to send information or money.

Even while you are expecting a parcel

Because these messages are sent out at random and in bulk, they sometimes land on a day when you really are waiting for a delivery; that coincidence is what makes the message convincing. The safe way of checking is always the same: open the courier firm's own application or site and look up your tracking number there. The link in the message never takes the place of that route; for the wider picture you can look at the Phishing record.

Related terms: Phishing, Malware, Account Takeover

From the same atlas

First published: 2026-08-12Last reviewed: 2026-08-12Editorial status: working editionReport an error