How to Report SMS Phishing?
SMS phishing is rising. Here’s how to report it effectively, no matter your country or device. Learn how to forward smishing attempts and protect your data, whether you're in the UK, US, or elsewhere.
Ozan Ucar, Founder and CEO of Keepnet
SMS phishing or smishing is on the rise, and scammers are constantly adapting their methods. Whether it's an alarming message about your bank account or a fake delivery notification, smishing attacks try to trick you into clicking on malicious links or sharing sensitive information. But don’t worry. There are clear steps to take when you receive one of these fraudulent messages.
Here’s a breakdown of how to report SMS phishing, split by country and device to help you stay secure, wherever you are and whichever device you use.
What to Do When You Receive a Smishing Attempt
Before diving into country and device-specific guidelines, let’s quickly cover what everyone should do when they receive a suspicious SMS:
- Do not click any links or respond to the message.
- Do not provide any personal or financial information.
- Take a screenshot of the SMS for future reference.
- Report the message to your mobile carrier, relevant authorities, or your company’s security team.
- Delete the SMS once it has been reported.
How to Report SMS Phishing: Country Breakdown
United Kingdom (UK)
In the UK, reporting phishing SMS is quite straightforward:
- Forward the message to 7726 (SPAM), which is a free service provided by most UK mobile networks (EE, Vodafone, O2, Three).
- Alternatively, report the phishing attempt to the National Cyber Security Centre (NCSC) by emailing a screenshot of the message to report@phishing.gov.uk.
- If the message is pretending to be from your bank or a well-known company, contact them directly to inform them of the phishing attempt.
For more detailed information about combating SMS phishing, read our comprehensive Smishing guide.
United States (US)
In the US, you can report smishing attempts in several ways:
- Forward the message to 7726 (SPAM) for major mobile carriers like AT&T, Verizon, and T-Mobile.
- Report the phishing attempt to the Federal Trade Commission (FTC) via their website, which collects data on scams for broader consumer protection.
- Some phishing attempts may involve financial fraud. If so, report the incident to the FBI's Internet Crime Complaint Center (IC3).
Editor's Note: This article was updated on March 12, 2026.
Canada
For Canadian users:
- Forward the message to 7726 (SPAM) for all major Canadian carriers.
- Report the incident to the Canadian Anti-Fraud Centre via their website or by phone.
Many scams in Canada are also reported through provincial law enforcement, so check with your local police service.
Australia
In Australia, here's what to do if you encounter a phishing SMS:
- Forward the message to 0429 999 888 provided by the Australian Communications and Media Authority (ACMA).
- Report it to Scamwatch, run by the National Anti-Scam Centre at the ACCC.
In Australia, large-scale smishing campaigns may also be reported directly to your bank or company.
European Union (EU)
Different EU countries may have specific reporting mechanisms, but in most cases:
The reporting route is not the same in every country. In Spain and several other EU member states you forward the message to 7726 (SPAM). In France the short code is 33700. In Germany there is no short code: reports are submitted through the Bundesnetzagentur online form, and the authority can order the sending number to be deactivated.
Use official national cyber security resources, such as Cybersecurity Incident Response Teams (CSIRTs), to report more advanced or harmful phishing campaigns.
Your local mobile provider can often help in redirecting reports to the appropriate authorities.
Reporting SMS Phishing Based on Devices
iOS Devices (iPhone and iPad)
If you're using an iPhone or iPad, Apple makes it easy to report phishing messages:
- Screenshot the message to keep a record of it.
- Forward the message to 7726 (SPAM).
- Block the number that sent the message: go to the SMS, tap the contact at the top, then select "Block this Caller."
- Tap Report Junk under the message to report it to Apple. If the message pretends to come from Apple, also email a screenshot to reportphishing@apple.com.
- Use Apple’s support page for further steps if you suspect a data breach or security issue.
Android Devices
On Android devices, reporting SMS phishing is just as straightforward:
- Screenshot the message.
- Forward the message to 7726 (SPAM).
- Use Android’s built-in tools: open the SMS app, tap and hold the message, and select "Report Spam" or "Block." This sends the report to Google and helps block further phishing attempts.
- If the phishing attempt is linked to a well-known app or company, report it to the Google Play Protect team via the Play Store.
Report SMS Phishing to Communities
Keepnet
One of the most effective ways to combat phishing and smishing is through community-driven threat intelligence. Keepnet Human Risk Management provides a unique Threat Sharing Platform that allows organizations to collaborate on identifying and stopping phishing attacks. By contributing to a shared database of phishing threats, businesses can quickly detect new phishing tactics and apply preventive measures.
Keepnet offers an SMS phishing simulator and security awareness training product to help companies train employees to recognize smishing attempts. These tools also gather data on phishing trends and help inform the larger community about emerging threats, making it easier to defend against phishing collectively.
Other Cybersecurity Communities
In addition to Keepnet Labs, there are several cybersecurity communities and platforms where you can report SMS phishing to help spread awareness and prevent further attacks:
- Anti-Phishing Working Group (APWG): A global coalition of institutions, corporations, and government entities working to combat phishing, smishing, and other cybercrimes. You can report phishing attacks and participate in discussions on the latest threats.
- Scamwatch (Australia): Managed by the Australian Competition and Consumer Commission (ACCC), Scamwatch collects information on phishing attacks, fraud, and smishing campaigns and shares them with the public.
- National Cyber Security Centre (NCSC) (UK): The NCSC encourages businesses and individuals to report phishing attempts, including smishing. It also provides resources on how to handle such attacks and protect your devices.
- Fraud.org (US): A project of the National Consumers League, Fraud.org allows users to report various fraud attempts, including SMS phishing. These reports help identify large-scale phishing campaigns.
By reporting phishing to these communities, you contribute to a collective defense strategy that helps everyone stay secure. Communities like these gather threat intelligence, share insights across organizations, and foster a more collaborative approach to cybersecurity.
Why Reporting SMS Phishing is Important
Reporting SMS phishing is not just about protecting yourself. It's about helping to create a safer digital environment for everyone. When you report a phishing attempt, you contribute valuable data that allows authorities, telecom companies, and cybersecurity teams to track, analyze, and shut down phishing operations more effectively. These reports help identify trends, discover new tactics, and prevent other people from falling victim to the same scams.
In the UK, 43% of businesses reported a breach or attack in the past year and 38% of them were phished, which makes phishing the most disruptive attack type for 69% of the businesses affected (UK Cyber Security Breaches Survey 2025/26). The same pressure shows up across smishing (SMS phishing), quishing (QR code phishing), and voice phishing. This increase highlights the urgency of regular reporting. With phishing tactics evolving constantly, timely reports give organizations the insight they need to stay ahead of attackers. Moreover, your reports can trigger public alerts and help strengthen network filters, reducing the spread of malicious links and fake messages.
By taking the time to report a phishing attempt, you’re actively contributing to the fight against cybercrime, helping both individuals and organizations avoid costly breaches, data theft, and financial loss. The more reports authorities receive, the better equipped they are to dismantle phishing networks and protect the broader community from future attacks.
Get Smishing Awareness Training with Keepnet
For businesses, cybersecurity awareness training helps employees recognize and report attacks before they spread. Incorporating smishing simulations and ongoing security awareness programs are great ways to minimize human error, a key entry point for attackers.
Get a free trial of our phishing simulation tool or request a personalized demo today to protect your company from smishing and other threats. Empower your employees to identify and report SMS phishing attempts like a pro!
Check a Suspicious Text Before You Report It
Reporting a message protects the next person who receives it, but most people want an answer first: is this actually a scam? You can get one in seconds with the free Keepnet Reporter app.
Open the message in Messages, select it, and report it through the app. You never have to copy or forward anything by hand. You can report an unknown call the same way, from your recent calls list. The first check runs on your own device, so clear cases come back immediately. If the case is not clear, the report is checked against more than ten threat intelligence sources before you get an answer.
Every report comes back as one of four verdicts, each with the reason behind it: no threat detected, suspicious, spam, or malicious. These results are for guidance and do not constitute a security guarantee. If money has already left your account, contact your bank first.
The app does not read or scan your SMS inbox. Data only leaves your phone at the moment you tap Report, and only for the item you chose. Reports are deleted automatically after 90 days. The app is free: no subscription, no in app purchase, and no account required.