Textly
TextlyBlogSecurity
Security

Smishing: the anatomy of a bank fraud text

Bank impersonation is the most expensive SMS fraud there is. Taking one apart line by line shows why it works on careful people.

Parcel scams take small amounts from many people. Bank fraud texts take large amounts from fewer, and they are considerably better made. Anyone can lose money to one. The defence is recognising the machinery, not being clever.

A real pattern, reconstructed

Here is a composite of a campaign that has run in several countries, reassembled from reports. The wording changes; the structure does not.

Message 1, 21:14. "[BANK]: A payment of €890.00 to LUXTRADE LTD was authorised. If this was not you, visit [link] immediately."

Note what it does. It arrives in the evening when you are unlikely to call a branch. The amount is large enough to alarm but not so large it seems absurd. The merchant name is unfamiliar, so you cannot dismiss it from memory. And it offers you an action that feels defensive rather than acquisitive: you are not being asked to send money, you are being invited to stop a payment.

That inversion is the core of the technique. Every instinct that normally protects you, urgency and protectiveness about your money, is turned into the thing driving you forward.

Message 2, 21:16. It arrives in the same thread as your bank's real messages.

This is the detail that defeats careful people. SMS sender IDs are alphanumeric strings, not authenticated identities. A fraudster can set the sender to your bank's name, and your phone will group it with genuine messages from that bank, because grouping is done by sender ID.

So the fake message appears directly beneath a real one-time code your bank sent last week. There is no visual difference. The thread itself has become the credential.

Message 3, 21:19. A phone call from someone identifying themselves as the fraud team.

Now the message becomes a setup rather than the attack. The caller is calm, professional, and already knows details: the amount, the merchant, your name. Those came from their own script, but the effect is that they appear to be inside your bank's systems.

They ask you to move your money to a "safe account" while they investigate. That is the whole point of the operation, and everything before it existed to make this request sound like a rescue.

The three signals that hold up

You cannot rely on the sender name, and you cannot rely on the thread. Three things still work.

1. No real bank asks you to move money

This is close to absolute. A bank freezes an account, blocks a card and reverses a transaction from its own side. It never needs your cooperation to move funds somewhere safe, because it does not need somewhere safe.

Any instruction to transfer money is fraud. There is no legitimate version of that request.

2. Hang up and call back on a number you found yourself

Fraudsters rely on you staying in a channel they control. Take the number from the back of your card or your bank's official app. Never from the message, never from the caller, and never by returning the call, which can be held open on some networks.

A genuine fraud team will be entirely comfortable with you calling back. Pressure not to is itself the answer.

3. Slow down deliberately

Every element is engineered to compress your decision time: the hour, the amount, the countdown, the calm voice explaining that each minute matters. Nothing real is lost by taking five minutes. Everything fraudulent depends on you not taking them.

If you have already transferred money: call your bank immediately on a number you looked up yourself, then report it to your national fraud reporting body, or to the police where no such body exists. Speed materially affects whether funds can be recalled. Do this before anything else, including telling us.

What detection can and cannot do

Textly's on-device classifier looks at intent and structure rather than a blocklist, so it catches new campaigns rather than only known ones. Messages claiming a payment problem, creating urgency and pointing at a domain that does not belong to the bank get flagged and their links disabled.

But be clear about the limit. The most dangerous part of this attack is a phone call, and no messaging app sees phone calls. Detection buys you a warning on the opening move. The rule that actually protects you is the one that needs no technology at all: nobody legitimate will ever ask you to move your money to keep it safe.

Textly brings WhatsApp, Telegram, Discord, Slack and Android SMS into one inbox, and understands it on your device rather than ours.

Get Textly