Dealing with a smishing attack

A smiling woman in a tan knit jumper looks at her phone while seated in a rustic café setting.

Navigation

Your generosity can provide a lifeline to victims of cybercrime

You receive a text message, commonly claiming to be from your bank, telling you there is a problem with your account, an issue with a payment, or suspicious activity that needs your urgent attention. The message may also arrive through a messaging or social media platform such as WhatsApp, Facebook Messenger or Telegram. It will usually contain a link to click, a QR code to scan, or a phone number to call.

This is known as a smishing attack.

If you click the link, you may be taken to a fake website designed to steal your banking or account login details. If you call the number, you may speak to a scammer who will try to convince you to reveal passwords, PINs, one-time passwords (OTPs), card details or other sensitive information.

Fraudsters do not only impersonate banks. They may also pretend to be organisations such as:

  • SARS

  • Courier companies

  • Mobile network providers

  • Municipalities

  • Government departments

  • Online shopping platforms

  • Streaming services such as Netflix

  • Payment services such as PayPal

We want to better understand the impact of you experiencing this issue, can you share your experience by filling in this online form? This will help us better protect future victims.


How to spot smishing (text message scam)

  1. You receive an unexpected text message - Banks, SARS and other organisations may send SMS notifications, but they should never ask you to provide passwords, PINs, OTPs, card details or full login credentials by SMS.

    Treat unexpected messages containing links, QR codes, urgent payment requests or requests for personal information as suspicious. Instead, open the organisation's official app, type their website address into your browser, or call them using a number you already know is genuine.

  2. A strange phone number or sender - Smishing messages often come from unfamiliar numbers. However, scammers can also use spoofing techniques to make messages appear to come from a legitimate sender name or trusted number.

    Do not rely on the sender name, short code or phone number as proof that a message is genuine. Verify contact details using the organisation's official website.

  3. A sense of urgency -Smishing messages often create pressure by claiming:

    • Your bank account has suspicious activity.

    • A payment has failed.

    • Your parcel cannot be delivered.

    • Your account will be suspended.

    • Someone you know urgently needs money.

    Scammers want you to act before thinking. If you are unsure, contact the organisation using contact details you already trust. Never use the contact details provided in the suspicious message.

  4. Links or QR Codes- Unexpected messages may encourage you to click a link or scan a QR code.

    Website addresses may be slightly misspelled or completely different from the legitimate website.

    Never click links or scan QR codes in unexpected text messages. If you receive a message claiming to be from an organisation, open their official app or type their website address into your browser instead.

  5. Poor spelling and grammar - Poor spelling or grammar can sometimes indicate a scam. However, many modern scam messages are professionally written and may even include accurate personal information.

    Do not assume a message is genuine simply because it looks professional or uses official branding.

A close-up of hands holding a smartphone with a marble-effect case, wearing a pink shirt.

What to do if you have fallen for a smishing scam

It is easy to fall for a smishing scam—even cybersecurity professionals sometimes do. The most important thing is to act quickly.

  1. Disconnect the affected device

    If you downloaded a file, installed software or suspect that the device may have been infected with malware, disconnect it from Wi-Fi, mobile data and any wired network connections if possible. This may help limit further malicious activity.

    If you only clicked a link and there is no indication that malware was downloaded or the device has been compromised, do not assume that the device is infected. Continue with the appropriate account and reporting steps below.

  2. Change exposed passwords

    If you entered a password into a suspicious website or otherwise shared your password with the scammer, change that password immediately.

    If the same password is used for other accounts, change it on those accounts too.

    Where possible, use a different trusted device to change passwords if you suspect that the affected device may be compromised.

    If you entered banking credentials, PINs or OTPs, contact your bank immediately using trusted contact details rather than attempting to resolve the issue yourself.

  3. Contact the organisation being impersonated

    If the message claimed to come from your bank, contact your bank's fraud department immediately using the number in your banking app, on the back of your bank card or from the bank's official website.

    If the message impersonated the South African Revenue Service (SARS), report the phishing attempt to phishing@sars.gov.za or contact the SARS Fraud and Anti-Corruption Hotline on 0800 00 2870. SARS currently provides these channels for reporting phishing and scams.

    If your South African ID number or identity information was exposed, consider contacting the Southern African Fraud Prevention Service (SAFPS) for advice about protective registration.

    Follow any additional instructions provided by the legitimate organisation to help secure your account.

  4. Scan your device for malware

    If you downloaded a file, installed software or suspect that your device may have been compromised, use reputable security software to scan the device.

  5. Watch for signs of identity theft

    If you shared any of the following:

    • South African ID number

    • Banking information

    • Proof of address

    • Payslips

    • Identity documents

    contact SAFPS for advice and monitor your:

    • Bank accounts

    • Credit profile

    • Financial statements

    Report any unauthorised transactions or suspicious activity immediately to the relevant financial institution.

  6. Preserve evidence

    Keep evidence of the incident before deleting messages or other material.

    This may include:

    • Screenshots of the message

    • Sender details

    • Links or URLs

    • Payment information

    • Transaction records

    • Emails or messages

    • Communication with the scammer

    • Any relevant case or reference numbers

    Do not destroy evidence.



Report the crime

Where money has been stolen, a bank account has been accessed without permission, or identity information has been misused:

  • Contact the relevant bank or financial institution immediately where financial information or funds are involved. If you are dissatisfied with how your bank or financial services provider handles your complaint, you may be able to escalate it to the National Financial Ombud Scheme.

  • Report the incident to the South African Police Service (SAPS) where a crime has occurred, to do this you should contact your local police station.

  • Report SMS spam or scam messages through WASPA.

  • If the message you have received is impersonating SARS, if the message impersonated SARS, report the phishing attempt to phishing@sars.gov.za or contact the SARS Fraud and Anti-Corruption Hotline on 0800 00 2870. SARS currently provides these channels for reporting phishing and scams.

The Cyber Helpline can explain these options and signpost you to the appropriate organisation. You will need to report the incident yourself; the Cyber Helpline cannot report the incident on your behalf.


How to avoid falling for a smishing scam

  1. Be cautious of unexpected text messages - Anyone who has your phone number can send you a message. Treat unexpected texts with caution, especially those asking you to act urgently.

  2. Trust your instincts - If something feels unusual or suspicious, stop before responding. Delete the message and contact the organisation directly using trusted contact details.

  3. Never provide personal information by text message - Legitimate organisations will not ask you to provide passwords, PINs, OTPs or banking credentials by SMS or messaging platforms.

  4. Do not click links or scan QR codes - Never click links or scan QR codes in unexpected text messages. If you receive a message claiming to be from an organisation, open their official app or type their website address into your browser instead.

  5. Verify phone numbers independently - If a message provides a phone number to call, do not use it.

    Instead, find the official contact number on the organisation's website or official app.

  6. Stay informed about scams - Learning about common scams can help you recognise them more quickly.

    Follow trusted organisations such as your bank, SAFPS, the Cyber Helpline and relevant government agencies for scam awareness updates.


Donate

Your generosity makes our free support possible. Please consider giving today.

Without donations, we cannot keep our service free or provide help to the most vulnerable victims of cybercrime when they need it most. As a not-for-profit organisation, every donation goes directly towards keeping The Cyber Helpline up and running. Donate now and help us support victims of cybercrime.