An older woman's hands holding an iPhone with an unlit screen โ€” text message scams targeting seniors.

Text Message Scams Targeting Seniors: How Smishing Works

The Chase text wasn't from Chase. The USPS text wasn't from USPS. The 10-second check that catches nearly all of them.

Listen · Tiina reads this
The short version, in Tiina's actual voice.
0:42
In one paragraph

Text-message scams ('smishing') are among the fastest-growing scam categories against older adults. The patterns are predictable: fake bank fraud alerts, fake package-delivery problems, fake Apple ID locks. Every one of them asks for a click or a code. The 10-second check that catches nearly all of them: don't tap the link. Open the actual app (Chase, USPS, Apple) and check there. If the alert is real, it'll show in the app. If it's not, the link was going to steal credentials. We've also seen the rise of AI-voice phone scams using texted callback numbers โ€” same principle: don't call the number in the text.

The text said it was Chase Bank. It wasn't Chase Bank. It used Margaret's name. It said there were fraudulent charges in Texas โ€” three hundred and forty dollars at a gas station outside Houston โ€” and that her account had been frozen for her protection. Under that, a link: tap to verify your PIN and unlock the account.

It looked so official. A case number, tidy bank language, even a "reply STOP to opt out" line at the bottom. Margaret didn't tap. She opened Tiina on her iPhone and read the text out loud, word for word.

The voice on the other end calmly said: "Banks never text you a link to verify a PIN. This is a smishing scam. Don't tap it. If you want to be sure, call the number on the back of your card."

She forwarded the text to 7726, the way Tiina walked her through it. Deleted it. Called Chase from the back of her card. No charges. No frozen account. The link died on her screen.

The three smishing patterns running right now

Recognize these
  • Bank fraud alert. "We detected a $X charge in [distant city]. Reply YES to confirm or NO to cancel. To speak with fraud team, call [number]." The number is the scammer. Reply "STOP" if you want, but never tap the link or call the number.
  • USPS / FedEx / UPS undeliverable package. "Your package can't be delivered. Update your address: [link]." The link harvests credentials or installs a keylogger.
  • Apple ID lock / Microsoft account compromise. "Your Apple ID has been locked. Sign in to verify: [link]." Apple never texts you links to sign in. Microsoft doesn't either.

Newer patterns we're tracking: fake Medicare-card-replacement texts (often paired with a phone call), fake state-DMV "unpaid toll" notices (especially common in late 2025), and fake IRS refund texts.

The 10-second check

Three steps. Memorize this:

Over-the-shoulder view of a senior man holding his iPhone.
The text comes in. He sets the phone down. He calls Tiina first.
  1. Don't tap the link. Ever. If action is really needed, it will be waiting in the organization's own app or website โ€” you never need the link in the text.
  2. Open the actual app. Open Chase. Open USPS. Open Apple's Find My. If the alert is real, it's in the app.
  3. If unsure, call the official number on the back of your card (or the company's official website โ€” typed by hand, not searched). Not the number in the text.

Run this check every time. The 10-second cost prevents the 6-month consequence.

What to do with a suspected smishing text

Clicking the link in a smishing text usually does one of three things: takes you to a fake login page that steals your username and password the moment you type them, downloads malware in the background (more common on Android than iPhone), or opens a fake form that captures your Social Security number, bank info, or credit card. On iPhone, just opening the link rarely installs anything โ€” but if you typed any information on the page that loaded, assume it is compromised. Change the password for that account immediately, turn on two-factor authentication, and watch the account for the next 30 days. Do not click "unsubscribe" โ€” that confirms your number is live.
Common smishing texts in 2026: fake USPS or FedEx delivery notices ("Your package is delayed, click here to update your address"); fake bank fraud alerts ("Did you authorize a $487 charge? Reply YES or NO"); fake toll violations ("You have an unpaid E-ZPass toll, pay now to avoid suspension"); fake IRS or Social Security threats; fake Amazon order confirmations for things you did not buy; and fake "hi mom" texts from a new number claiming the kid's phone broke. The toll scam exploded in 2024 and 2025 โ€” the FBI's IC3 logged over 60,000 complaints in 2024 alone. The tell is always urgency plus a link plus a request to act now.
Forward the spam text to 7726 (which spells SPAM) โ€” this reports it to your carrier and helps them block the sender for everyone. Then delete and block the number. On iPhone, turn on Settings > Messages > Filter Unknown Senders, which routes texts from unknown numbers to a separate tab. Add the carrier's free spam protection (Verizon Call Filter, AT&T ActiveArmor, T-Mobile Scam Shield) โ€” all three filter texts too. Do not reply, do not click, do not unsubscribe. For a parent who clicks everything, add a third-party scam-blocker app with text filtering.
Replying to a smishing text โ€” even just "STOP" or "NO" โ€” confirms to the scammer that your phone number is active and that a real person reads the messages. Your number then gets flagged as high-value and sold to other scam operations, so you will get more spam, not less. The reply itself does not give them your bank account or password, but it escalates the volume of attacks. If you replied and did not click a link or share information, you are mostly fine โ€” just expect more smishing for the next few months. If you did share anything, treat it as compromised and start changing passwords.
Tiina helps them stop before they act.

A scammer counts on no one being there to ask. Tiina is โ€” a companion on the phone who'll talk through any "urgent" call, calmly, before your parent does anything they can't undo.

7 days free · Cancel anytime
Try Tiina free →

The newer smishing patterns running in 2026

Smishing evolves fast. Federal agencies and carriers play whack-a-mole. The current 2026 patterns we're tracking โ€” none of which existed two years ago:

Active patterns this quarter
  • Fake Medicare card replacement. "Your new Medicare card is pending. Verify your number to receive it: [link]." Medicare doesn't text. Real card replacements come by mail. See our pillar guide for the longer treatment of Medicare scams.
  • Fake state-DMV unpaid toll. "You owe $4.75 in unpaid tolls. Pay now to avoid fees: [link]." Spreading rapidly through Texas, California, Florida. State DMVs do not text; tolls go by mail.
  • Fake IRS refund. "Your IRS refund of $1,402 is ready. Verify your details to receive it: [link]." The IRS does NOT text refund notifications. Refunds come via the original payment method on the return.
  • Fake utility shutoff threat. "Your power will be shut off in 30 minutes for non-payment. Pay immediately: [link]." Real utilities send written notice before a shutoff. Anyone threatening same-day shutoff by text is a scammer.
  • Fake bank login alert with callback number. "Suspicious sign-in detected. If this wasn't you, call [number]." The callback number connects to a scammer who walks your parent through "verification" that drains their account. The text-then-call pattern is harder to spot than text-with-link.

When in doubt: forward to 7726 (SPAM) from the text thread. Standard cross-carrier reporting number. The carriers track these and block patterns at scale.

If your parent already tapped the link โ€” the 30-minute checklist

Tapping a link alone usually doesn't compromise the phone โ€” modern browsers sandbox most attacks. The risk is what your parent did NEXT. If they tapped and:

  1. Only viewed the page (no taps, no info entered): clear browser history and cache, update iOS to the latest version, watch the affected account for a week. Most likely safe.
  2. Entered a password: change that password EVERYWHERE that password is used. Then enable two-factor auth on the real account. Then call the bank/Apple/Amazon to confirm no suspicious activity.
  3. Entered a credit/debit card: call the card's fraud line on the back of the card. Replace the card. Watch for charges over 60 days.
  4. Entered SSN or Medicare number: freeze credit at all three bureaus (Equifax, Experian, TransUnion โ€” all free). File at identitytheft.gov. See our recovery guide for the full timeline.
  5. Sent money via gift cards, wire, or Zelle: call the receiving institution within the hour. Recovery is partial-at-best but speed matters. File an IC3 complaint at ic3.gov same-day.

Speed matters more than perfection. Better to overreact in the first hour than to optimize the response in week three.

An iPhone resting on a table beside reading glasses and a mug.
The right move, ninety-nine times out of a hundred. Set it down. Delete it later.

What this sounds like with Tiina in the room

11:42 AM. Your mom's phone buzzed five minutes ago โ€” a text saying her Chase account was locked, with a link to verify her PIN. She doesn't have a Chase account. But she's seen the news about scammers and isn't sure. She opens Tiina, screenshots the text, and asks, "Is this a scam?" Tiina answers. Yes โ€” banks never text you links to verify a PIN. Walks her through what to do: don't tap, forward to 7726, delete. Doesn't make her feel paranoid for asking. Your mom forwards it. Deletes it. Goes back to her crossword.

11:47โ€ขโ€ขโ€ข
M
Mom
Tuesday 11:42 AM
Got a text saying my Chase account was locked. I don't have a Chase account.
Showed it to Tiina. She said it was a scam โ€” banks never text you links like that.
Deleted it. Forwarded the other one to 7726 like she said. Felt smart.
Read 11:51 AM
A text from a mom to her daughter. The Tuesday she stopped forwarding scam texts asking what they meant.

Mom reads the text to Tiina before she taps the link.

"USPS package held" โ€” "Chase account locked" โ€” "Your grandson needs bail." She reads it out loud, Tiina answers, and the link dies on her screen instead of in her checking account.

7 days free ยท Then $24.99/month ยท Cancel anytime
Listen ยท Real Tiina voice
This is what Tiina actually sounds like.
A scripted scenario: an 84-year-old widow reads Tiina a USPS text about a 'rescheduling fee.'
A Tiina conversation
Margaret: "Tiina, USPS just texted me about a package fee."
0:33

Methodology & editorial policy

Reviewed and updated May 10, 2026 by the Tiina Editorial Team. Patterns sourced from FTC Consumer Sentinel monthly reports and CTIA carrier-side smishing data. Re-checked monthly as new templates emerge.

About composite scenarios. Margaret is a composite character, and the scenes and sample conversations in this article are illustrative. The three current patterns and the 10-second check are sourced from active federal advisories.

About Tiina. Tiina is a voice-first AI companion for older adults โ€” an app for iPhone and iPad that your parent opens to talk through a moment that doesn't feel right.

Sharing. Quote freely with a link back to this page. For full reprints, email hello@tiina.ai.

Sources. 6 references โ€” FTC, FBI IC3, FCC, CTIA, AARP Fraud Watch, Apple Support.View all
  1. FTC Consumer Alert โ€” Smishing โ€” scam texts and how to stop them. consumer.ftc.gov
  2. FBI Internet Crime Complaint Center โ€” Smishing Scam Regarding Debt for Road Toll Services (PSA240412, Apr 2024; toll-text complaint volume). ic3.gov
  3. FCC โ€” Stop Unwanted Robocalls and Texts. fcc.gov
  4. CTIA โ€” Spam Text Reporting (forward to 7726). ctia.org
  5. Apple Support โ€” Filter and Report iMessage Spam. support.apple.com/HT202300
  6. AARP Fraud Watch โ€” Text Message Scam Alerts. aarp.org/money/scams-fraud