How to Report Phishing Text Messages: What to Do, Where to Report, and How to Protect Yourself

Written by: Abigail Ivy
Published on:

What phishing text messages are and why reporting matters

Phishing text messages, also called smishing, are fraudulent SMS or MMS messages designed to trick you into revealing personal information, clicking malicious links, or sending money.

Knowing how to report phishing text messages helps protect your accounts, supports fraud investigations, and can reduce the chance that the same scam reaches other people.

These messages often imitate banks, delivery services, toll agencies, employers, or government offices.

The faster you report them, the easier it is to preserve evidence and limit damage if you accidentally interacted with the scam.

How to report phishing text messages

The best reporting path depends on who your carrier is, what the message claimed, and whether any financial loss or identity theft is involved.

In most cases, you should report the message to your mobile carrier, your message app, and the appropriate government fraud reporting channel.

Report the text to your mobile carrier

Most U.S. carriers support forwarding suspicious texts to a short code for spam review.

This is often the fastest first step.

  • AT&T, Verizon, and T-Mobile: Forward the suspicious text to 7726 (which spells SPAM).
  • Do not click links, call numbers in the message, or reply with “STOP” if you suspect fraud.
  • If your carrier offers a spam or phishing report option in its app, use that as well.

Forwarding the message helps carrier fraud teams identify sending patterns, block malicious numbers, and improve spam filtering.

Report the message in your texting app

Many smartphones let you report junk or spam directly inside the messaging app.

This is useful because it sends platform-level abuse signals to Apple, Google, or your carrier-backed messaging service.

  • iPhone: Open the message, tap the sender, and use the “Report Junk” option if available.
  • Android: Open the message and select the spam reporting or blocking option in Google Messages or your device’s messaging app.

Reporting in-app is especially important when the sender uses a spoofed phone number or a mass texting service.

Report phishing texts to the government

If the text is clearly fraudulent or involves an attempt to steal money or identity information, report it to the proper government agency.

  • FTC: File a report at ReportFraud.ftc.gov for scams, phishing, and identity theft attempts.
  • IC3: If the message is tied to online fraud, file with the FBI Internet Crime Complaint Center at ic3.gov.
  • SSA, IRS, USPS, or other agency impersonation: Use the official fraud reporting page of the impersonated agency when available.

Government reports do not always result in immediate updates to your case, but they build intelligence that helps investigators identify scam networks.

Report phishing texts to your bank or service provider

If the message pretends to be from your bank, credit union, payment app, online marketplace, shipping company, or utility provider, contact the organization through its official customer support channel.

Give them the sender number, the message content, and any link or callback number included in the text.

  • If the text mentions a transaction you do not recognize, ask the institution to review account activity.
  • If you clicked a link, ask whether they recommend a password reset or account lock.
  • If the scam targeted a business account, notify your IT or security team immediately.

What information to save before reporting

Before deleting anything, preserve the evidence.

Good documentation can help if you need to dispute charges, file an insurance claim, or report identity theft.

  • A screenshot of the text message
  • The phone number or sender ID
  • The date and time the message arrived
  • Any link, file, or callback number included in the text
  • Notes about whether you opened the link, replied, or shared information

If possible, keep the original message thread intact until you finish reporting.

If the scam used a short link, save the full URL if your phone displays it.

What to do if you clicked the link

Clicking a phishing link does not always mean your device is compromised, but it does raise the risk of credential theft, malicious downloads, and account takeover.

Act quickly.

  • Do not enter passwords or payment information unless you are certain the site is legitimate.
  • Close the page immediately if it asked for sensitive information.
  • Run a security scan using trusted mobile security software if available.
  • Change passwords for any account you may have exposed, starting with email and banking.
  • Enable multifactor authentication on important accounts.

If you entered a password, update it anywhere else you reused the same password.

If you shared financial details, contact your bank or card issuer immediately.

How to tell whether a text is phishing

Phishing texts often use urgency, fear, or rewards to get a fast response.

Learning the most common warning signs makes reporting easier because you can act before damage occurs.

  • Unexpected delivery alerts, toll violations, tax notices, or package holds
  • Requests to verify an account, reset a password, or confirm a purchase
  • Messages containing shortened links or misspelled web addresses
  • Pressure to respond immediately or risk suspension, fines, or loss of access
  • Requests for OTP codes, passwords, Social Security numbers, or payment card details

Legitimate organizations rarely ask for sensitive information through a text message link.

When in doubt, visit the organization’s official website by typing the address yourself or use a verified mobile app.

How to block future phishing texts

Reporting one message helps, but reducing future exposure is just as important.

A few settings and habits can significantly lower your risk.

  • Turn on spam filtering in your phone’s messaging app.
  • Block suspicious numbers after reporting them.
  • Silence messages from unknown senders if your device supports it.
  • Avoid posting your phone number publicly when possible.
  • Use unique passwords and a password manager for important accounts.

For businesses, use mobile device management, secure messaging policies, and employee awareness training to reduce the chance of one phishing text leading to a larger breach.

When to escalate the report

Some phishing texts deserve more than a simple spam report.

Escalate immediately if the message involves money loss, identity theft, credential compromise, or harassment.

  • Financial loss: Contact your bank, credit card issuer, or payment platform right away.
  • Identity theft: File an identity theft report and consider placing a fraud alert on your credit file.
  • Compromised business account: Notify security, legal, and IT teams.
  • Ongoing campaign: Save multiple examples and include them in your complaint.

In severe cases, law enforcement may ask for screenshots, phone logs, and transaction records.

Keep copies organized and accessible.

Why your report helps others

Phishing operations often rely on automation, spoofed numbers, and recycled message templates.

One report can help carriers, consumer protection agencies, and financial institutions identify broader campaigns, block infrastructure, and warn other potential victims.

Reporting also creates a record that may support reimbursement or dispute resolution later.

If you receive a suspicious text again, treat it the same way: preserve evidence, report it to the carrier, escalate to the proper agency when needed, and protect any accounts that may be at risk.