AI Scam Text Messages: How to Spot Them Now That They Read Like Real Texts

Safety & scams Tutorial7 min read·Updated July 23, 2026
The short answer

AI tools now write scam text messages that are grammatically perfect and personalized with real details scraped from data breaches, so 'bad spelling' no longer works as a warning sign. Instead, check the sender's number, don't tap the link, notice if the message creates urgency or asks you to reply, and verify anything real through the company's official app or website — never through the text itself.

A few years ago, spotting a scam text was easy: bad grammar, a weirdly formatted link, a sender who clearly didn't speak English as a first language. AI writing tools have quietly ended that era. Today's scam texts — called "smishing," short for SMS phishing — can be grammatically perfect, personalized with your actual name or a real recent order, and tuned to sound exactly like your bank, delivery company, or even a family member.

The good news: the underlying tricks haven't changed, even if the writing has gotten better. These six checks catch most AI-polished scam texts in under a minute.

Look at who actually sent it

A text claiming to be from your bank, a delivery company, or a government agency should come from a short code or a number you recognize from past legitimate messages — not a long, random phone number, an international number, or an email-address-looking sender.

Tap on the sender to see the full number if your phone doesn't already show it. If a message claiming to be "USPS" or "your bank" arrives from a personal-looking 10-digit number instead of the company's usual short code, that's a strong warning sign on its own.

Don't tap the link — go to the source yourself

This is the single most effective habit against smishing. Instead of tapping any link in a text, open a new browser tab (or the company's own app) and type the address yourself, or use a bookmark you already trust.

If the text claims there's a package waiting, a toll unpaid, or account activity to review, the same information — if it's real — will be sitting there when you log in directly. If nothing shows up, the text was fake.

Recognize AI-perfected pretexts

AI has made scam texts sound natural, but the setups themselves are familiar once you know to look for them: an undelivered package needing a small "customs fee," an unpaid toll with a threat of licence penalties, a bank fraud alert asking you to "verify" your card, a missed jury summons, or a job offer that starts by text out of nowhere.

What's changed is the personalization — AI tools can pull your name, city, or even a real recent purchase from data leaked in past breaches and drop it into the message, making it feel far more targeted and credible than a generic blast.

Notice urgency, and any request to reply or pay

Scam texts are built to make you act before you think: "final notice," "your account will be suspended today," "reply within 2 hours." Real notifications from banks, delivery services, and government agencies almost never demand action within hours over text.

Also treat any request to reply with a word (even something like "Y" or "C"), click through to "confirm," or pay a small fee by card as a red flag. Replying at all — even to opt out — can confirm to a scammer that your number is active.

Verify independently, the same way every time

If a text claims something urgent about your bank, delivery, or a government matter, don't use any link, phone number, or QR code from the text. Open the company's official app, or a website address you type yourself, and check your account there. For anything claiming to be a government notice, use the agency's official .gov (or your country's equivalent) website directly.

Calling the number printed on your bank card or a past bill also works — never a number provided inside the suspicious text itself.

Turn on your phone's built-in scam-text detection

Recent phones can help catch these automatically. Google Messages now includes an on-device AI scam-detection feature for Android that flags suspicious message patterns in real time — it launched in the US, UK, and Canada and has since expanded to more than 20 countries, supporting several languages including English, Arabic, French, German, Portuguese, and Spanish, and all the analysis happens on your phone rather than being sent anywhere. iPhone users can filter messages from unknown senders into a separate list under Settings, so unrecognized senders don't land straight in your main inbox.

After checking a message, forward it to 7726 (spells "SPAM") to report it to your carrier — this works in both the US and the UK — then block the sender and delete it.

What to Watch Out For

AI has also learned to imitate people you know. Scammers increasingly use AI to write a text or voice message that sounds like your adult child, grandchild, or a coworker asking for urgent help — often money sent quickly. If a text from a "known" number feels off, or asks for money or gift cards, call that person back on a number you already have saved, not one provided in the message.

Don't trust caller ID or sender names on their own. Both can be faked (called "spoofing") to display a real company name or even a real contact's name. Treat the sender name as a hint, not proof.

What to Try Next

Scam texts are often just one piece of a bigger playbook that also uses AI-written emails and cloned voices. How to spot AI phishing emails covers the same tactics applied to your inbox, and how to detect an AI voice on a phone call is worth reading if a "text from a relative" turns into a phone call that doesn't quite sound right.

Sources

Published July 23, 2026 · Updated July 23, 2026How we test →

Frequently asked questions

What is 'smishing'?
Smishing is phishing done by SMS or text message instead of email — the name blends 'SMS' and 'phishing.' The goal is the same: get you to click a bad link, reply with personal information, or call a fake number. AI has made these texts far more convincing than the misspelled ones you may remember from a few years ago.
Why don't typos or bad grammar give away scam texts anymore?
Scammers now use the same AI writing tools everyone else uses, so their texts read like they were written by a native speaker with no spelling mistakes. Grammar is no longer a reliable signal — you need to check the sender, the link, and what the message is asking you to do instead.
Is it safe to reply 'STOP' to a text I think is a scam?
Only reply 'STOP' to messages from a company or service you actually signed up with. For a text from an unknown sender or one you suspect is a scam, don't reply at all — even 'STOP' confirms to the scammer that your number is active and being read, which can lead to more messages. Block and delete instead.
Will AI-written scam texts eventually be labeled or blocked automatically?
The FCC has proposed rules that would require companies sending AI-generated texts and robocalls to clearly disclose that AI was used, but as of mid-2026 it's still just a proposal, and there's no confirmed date for a final rule. In the meantime, Google Messages now offers on-device AI scam detection for text conversations. It launched in the US, UK, and Canada and has since expanded to more than 20 countries and several languages, with more on the way.
What should I do if I already clicked a link in a scam text?
Don't enter any information on the page that opens. If you did enter a password or card number, change that password immediately and contact your bank or card issuer to watch for or block fraudulent charges. Also check your phone for anything unexpectedly installed, and run a security scan if you're not sure.
Where do I report a scam text?
Forward the message to 7726 (spells 'SPAM' on your keypad) — this works with most major carriers in both the US and the UK and helps them block similar messages. You can also report it to the FTC at reportfraud.ftc.gov (US) or, in England, Wales and Northern Ireland, to Report Fraud at reportfraud.police.uk — the service that used to be called Action Fraud; in Scotland, report to Police Scotland on 101. Then block the sender and delete the message.
Radim S.
Founder & editor

Radim is a software developer who spends his days building with AI and his evenings explaining it to family members who don’t care how it works — only what it can do for them. The safety guides are checked claim by claim against primary sources before they go out.