A text message arrives from your bank. It alerts you to a purchase you don't recognise — a specific amount, a named shop, an exact time. At the end of the message, an instruction: if you did not make this purchase, reply CANCEL. No link. No suspicious phone number. It looks legitimate.

It isn't. It's a scam. And it's one of the hardest types of smishing to spot precisely because it has none of the warning signs we've been taught to look for.

Imagen del artículo

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

Why this text message looks real

Most advice about smishing focuses on links: don't click, check the domain, distrust URL shorteners. That advice is correct, but incomplete. Scammers know this and have adapted their techniques. An increasing number of bank fraud campaigns by SMS drop the link entirely.

Instead, the message includes details that generate immediate credibility: the exact name of the bank, an amount with decimal figures, a well-known retailer, a recent date and time. The brain processes those details and concludes the message is genuine — because a scammer couldn't know all that, right?

In reality, they can. That data comes from database breaches, public information, or is simply invented with enough detail to seem real. The amount and the shop name are not verified facts — they are hooks designed to trigger an immediate emotional reaction.

What happens when you reply

When the victim replies "CANCEL" — or "NO", or "STOP", or any variant — several things can happen depending on the sophistication of the attack.

In the simplest case, the attacker confirms that the number is active and belongs to someone who reacts to messages from their bank. That number moves to a priority list for more elaborate attacks.

In more advanced versions, the reply triggers an almost immediate phone call from someone presenting themselves as the bank's fraud department. That person already knows you just received the text — because they sent it — and uses that context to gain your trust and ask for banking details, a one-time code, or authorisation for a "verification" transfer.

This is called vishing — voice phishing — and combined with the preceding SMS it is one of the most effective techniques because the victim arrives at the call already primed to believe there is a real problem with their account.

The signals to look for when there is no link

Without a URL to analyse, the warning signs are more subtle — but they are still there.

The sender's number is the first. A legitimate bank sends its SMS from a short code or a recognisable alphanumeric alias — not from a long mobile number, and certainly not from a number with an international prefix different from the country where it operates. A text from "your bank" arriving from an unexpected international number is not from your bank.

The instruction to reply is the second. No bank manages charge cancellations by asking you to reply to an SMS. The real process always goes through the official app, the bank's website, or a call to the number on the back of your card — never by replying to a text message.

The absence of a verifiable reference is the third. Legitimate bank SMS messages include references you can cross-check in your app or statement: a transaction number, the last four digits of the card, an operation code. If the message only has an amount and a shop name but nothing you can verify against your own records, it is suspicious.

Implied urgency is the fourth. "If you did not make this purchase" appeals directly to the fear of losing money. That emotional pressure is designed to make you act before you think.

What to do if you receive a text like this

Do not reply to the SMS. Not "CANCEL", not "NO", not anything. Any reply confirms that the number is active.

Do not call any number that appears in the message. If you receive a call shortly after the SMS from someone claiming to be from your bank's fraud team, do not provide any information — however convincing they sound.

If you are unsure whether there is a real charge on your account, check directly through your bank's official app or by calling the number you already had saved before receiving the text. Do not use any contact details that appear in the suspicious message.

If you have already replied or provided details, contact your bank immediately to block any potential transactions, and report the case to your country's relevant cybersecurity authority.

Why the scanner does not detect this type of SMS

ORTSLAB automatically analyses the technical patterns of messages: sender authentication, domain reputation, URL shorteners, Unicode homoglyphs in links, malicious QR codes. When an SMS contains no link, many of those technical signals simply are not present.

This is a real limitation of any automatic analysis tool. Reply-based vishing patterns — SMS without a URL designed to provoke a reaction or trigger a follow-up call — are harder to detect automatically than link-based smishing, precisely because they avoid the usual technical vectors.

If you receive a link-free SMS that raises doubts, you can paste it into ORTSLAB to analyse what can be analysed — the sender number, the alphanumeric alias, social engineering patterns in the text. But with this type of message, human judgement remains the best defence: if something feels off, don't reply and verify through a channel you already knew.