Smishing is rising, and AI tools are part of why
Smishing (SMS phishing) uses fraudulent text messages instead of email to trick people into clicking a malicious link or replying with sensitive information. The Canadian Anti-Fraud Centre and cybersecurity researchers have flagged that smishing volume has increased in part because AI tools now make it easier to draft convincing, well-written messages at scale and to mine breached data for fresh targets.
Common smishing messages Canadians see
The specific brand changes, but the structure repeats.
- A fake delivery notice claiming a parcel is held pending a small customs or redelivery fee
- A fake bank alert claiming your account is locked or a suspicious transaction needs confirmation
- A message impersonating a government agency about a benefit, refund, or tax issue
- A message claiming to be from your own phone carrier about an unpaid bill or plan change
- A message in an existing text thread that suddenly asks you to click a link 'to verify your identity'
Warning signs in the message itself
Smishing messages tend to share a few structural tells, even when the wording is polished.
- Urgent claims that an account is locked, suspended, or compromised
- A shortened or slightly altered link that does not match the organization's real domain
- A request to 'confirm' personal or financial information by text
- Pressure to act immediately, discouraging you from verifying independently
The safest response, every time
You do not need to analyze every message individually if you follow one consistent rule.
- Do not click links in unexpected text messages, even if they appear to be in a legitimate thread from your bank or carrier
- Go directly to the organization's official app or website by typing the address yourself, rather than tapping the link
- If a message claims to be from your bank, call the number on the back of your card rather than any number in the text
- Delete the message and block the sender; do not reply, even to text 'STOP', which can confirm your number is active to the scammer
Reporting a smishing attempt
Reporting helps carriers and authorities track and block active campaigns.
- Forward the suspicious text to 7726 (SPAM), a short code supported by major Canadian carriers
- Report the message to the Canadian Anti-Fraud Centre
- If you clicked the link and entered information, follow the same recovery steps as any other phishing incident: change passwords and watch financial accounts closely
Frequently asked questions
Can a text message infect my phone just by receiving it?
In the overwhelming majority of smishing cases, harm comes from clicking a link and entering information or downloading a file afterward, not from the text arriving. The safest approach is still to avoid clicking unexpected links at all.
Why did the scam text appear in the same thread as my real bank?
Some smishing techniques spoof the sender ID so the fraudulent message appears in an existing legitimate conversation thread on the phone. This is a spoofing trick, not evidence that your bank's systems were compromised, but it does make the message look more convincing, which is exactly the point.
Is texting 'STOP' to a suspicious message safe?
No. For a legitimate marketing text, STOP works as intended. For a scam text, replying anything, including STOP, confirms to the scammer that your number is active and monitored, which can increase future targeting.