A deceptive text may ask the recipient to follow a link, call a number, disclose information, approve a transaction, install software, or continue the conversation elsewhere. The term identifies the delivery channel, not the attacker’s objective, degree of targeting, or technical method used after the message.
Texts can appear within a familiar conversation or display a recognizable sender name or number. Campaigns often imitate delivery companies, banks, government services, employers, or personal contacts, then move the recipient to a website, phone call, or messaging application.
Key points
VerificationOpen the organization’s known application or website, or contact it using independently obtained details; do not rely on a link, number, or callback instruction supplied in the text.
Layered controlsMobile filtering and reporting, managed-device policies, restricted application installation, phishing-resistant multi-factor authentication, and transaction checks can limit different stages of an attack.
If someone respondedPreserve the message, report it through the relevant service or workplace channel, review account activity, and change exposed credentials from a trusted device where appropriate.
Important limitationSender identifiers and conversation placement can be manipulated, while legitimate organizations also send unexpected texts; neither appearance nor urgency alone establishes whether a message is authentic.