The smishing that needs no link: when fraud asks you to reply
For years, the advice has been the same: don't click the link. And for years, it worked reasonably well as a first line of defence. The problem is that attackers read the same advice as their victims.
The variant growing in Spain in 2026 carries no link. No phone number. No URL shortener. It's a clean SMS, formatted exactly like your bank's real messages, asking for just one thing: reply with the code.
🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
The pattern
The message arrives in the same SMS thread where your bank's real notifications already live. Same sender name, same format, same tone. The text reads something like:
"BBVA: We have detected unauthorised access to your account. To cancel it, reply to this message with the code you just received."
At that moment, the attacker has already attempted to log into your online banking with your credentials — obtained previously from a data breach or an earlier attack. The bank sent a real OTP to your phone to authorise the operation. The only thing the attacker is missing is that code. So they just asked you for it directly, impersonating your own bank.
The victim, believing they are cancelling an unauthorised access attempt, sends the code. The attacker completes authentication. They're in — without forcing anything, without a fake page, without a suspicious link.
Why this is different
Smishing detection filters — including the ORTSLAB engine — are built on solid logic: bank + external link, official body + URL shortener, courier + URL. These patterns work because fraud has always needed to take the victim somewhere.
This attack goes nowhere. There is no URL to analyse, no recently registered domain, no hidden redirect. The attack vector is the victim's own SMS reply.
It follows exactly the same principle that ESET documented in EvilTokens for Microsoft 365 accounts — we published the analysis on 18 June — but translated to the SMS channel and requiring no sophisticated technical infrastructure. The attacker only needs you to reply.
What we have updated
This week we added a new detection rule to the ORTSLAB engine for this pattern: messages that actively request a reply with a verification code, with no URL and no phone number, in a banking or official body context.
The rule detects variants such as:
- "Reply with the code"
- "Send the code to cancel"
- "Respond with your PIN"
- "To cancel, reply with your verification code"
If the message also mentions a financial brand or a government body, the detection weight increases because the impersonation is explicit.
This is not a cosmetic patch. It is a structural extension of the analysis logic to cover the vector that until now fell outside the detection scope: fraud with no link.
The one rule that never fails
Regardless of what the SMS says, there is one rule no Spanish bank ever breaks: banks do not ask for OTP codes via SMS reply.
The OTP arrives on your phone so that you enter it yourself — in the bank's app or website — for an operation you initiated. Never to send it to anyone. If an SMS asks you to forward a code — for any reason, urgent or not — it is fraud.
That does not change. What changes is that the ORTSLAB engine now knows it too.
Have you received a suspicious SMS or think your account may have been compromised? Oscar Orts — court-certified IT expert — can forensically analyse the incident and produce an expert report with full legal validity for judicial proceedings or insurance claims.