Text message fraud, or smishing, is a growing risk for women founders and women-led businesses running a UK company from a mobile phone. Ofcom research published in 2024 found that 82% of UK adults received a suspicious text, call, or message in the previous three months (Ofcom, 2024). UK Finance reported that total fraud losses in 2023 reached £1.17 billion (UK Finance, 2024). A single convincing message can lead to stolen bank credentials, malware on your device, or a compromised business account. Learning how to protect your phone against text smishing is now part of running a secure small business.
Smishing explained
Smishing is phishing delivered by SMS, WhatsApp, or similar messaging apps. The sender pretends to be a trusted organisation, such as your bank, HMRC, the DVLA, a delivery firm, or the NHS, and tries to make you click a link, call a number, or share personal information. The name combines “SMS” and “phishing”.
Unlike email, text messages feel immediate and personal. Most people check their phones within minutes of receiving a message, which is why criminals use smishing to bypass the caution they might apply to a suspicious email.
Common UK smishing tactics
Knowing the typical disguises makes them easier to spot.
Fake bank alerts
You receive a text claiming to be from your bank, warning of suspicious activity and asking you to click a link or call a number. The link leads to a fake login page designed to capture your credentials. Genuine UK banks will never ask you to click a link to confirm your details or share passwords.
HMRC tax rebate or penalty texts
Messages promising a tax refund, or threatening a fine for unpaid tax, are common around self assessment deadlines. HMRC does send some text messages, but it will never ask for personal or financial information by text, and it does not include clickable links to claim refunds.
DVLA vehicle tax scams
Texts claiming your vehicle tax is overdue or that you are due a refund are a frequent smishing theme. The DVLA does not send texts with links asking for payment details or bank account information.
Delivery and parcel scams
Texts claiming a parcel missed delivery and asking for a redelivery fee are widespread. They often impersonate Royal Mail, Evri, DPD, or other couriers. The link may steal payment details or install malware.
NHS and health-related messages
Scammers send texts about missed appointments, prescriptions, or health rebates. The NHS may send appointment reminders, but it will not ask for payment or bank details by text.
Warning signs of smishing
Most smishing texts share warning signs:
- Urgent or threatening language, such as “your account will be closed” or “you face a fine”
- Requests to click a link or call an unfamiliar number
- Spelling mistakes, odd phrasing, or sender IDs that do not match the real organisation
- Offers that seem too good to be true, such as unexpected tax rebates or prizes
- Requests for passwords, PINs, or one-time passcodes
Steps to protect your phone against text smishing
These steps reduce the chance of becoming a victim.
Unexpected links in texts
If a message asks you to act, pause. Open your browser separately and log into the service the usual way, or call the organisation using the number on its official website or your card. Do not use the number or link in the text.
The 7726 reporting service
In the UK, you can forward suspicious text messages to 7726, which spells “SPAM” on a keypad. This free shortcode is supported by the National Cyber Security Centre and major mobile networks, and it helps identify and block scam campaigns. Forward the message, then forward the sender’s number if requested.
Phone and app updates
Security updates fix vulnerabilities that malware can exploit. Enable automatic updates for your operating system and apps, and only install apps from official stores such as the Apple App Store or Google Play Store.
Strong authentication
Protect business accounts with multi-factor authentication where available. Avoid using SMS-based two-factor authentication for high-value accounts if app-based or hardware-key options exist, because SIM-swapping attacks can intercept text codes.
Business data backups
Regular backups protect you if malware locks or wipes your device. Use a cloud service or external drive, and test that you can restore files.
If you respond to a smishing text
If you have clicked a link, entered details, or made a payment, act quickly:
- Contact your bank immediately using the number on the back of your card
- Report the incident to Action Fraud online or by calling 0300 123 2040
- Change passwords for any compromised accounts
- Run a security scan on your device
- Notify your insurer if you have cyber insurance cover
Protecting your business, not just your phone
If you employ staff or use personal devices for work, smishing becomes a business risk for women-led businesses. Women in business often handle client data, invoicing, and banking from one phone, so a single compromised message can affect both personal and company accounts. The National Cyber Security Centre offers free guidance for small businesses, and the government-backed Cyber Essentials scheme provides a framework for basic cyber hygiene. For businesses handling personal data, the Information Commissioner’s Office can take action if inadequate security leads to a data breach. Under UK GDPR, the ICO can issue fines of up to £17.5 million or 4% of global annual turnover for the most serious data breaches (ICO, 2024).
If you are a company director, identity theft can also put your business filings at risk. The Companies House identity verification requirements, introduced under the Economic Crime and Corporate Transparency Act 2023, are designed to reduce this risk, but you still need to guard the personal details that criminals could use to impersonate you.
The Take Five to Stop Fraud campaign, led by UK Finance, encourages everyone to stop and challenge requests for money or information. Making this a habit across your team is one of the cheapest and most effective security controls.
Action steps for women-led businesses
- Forward any suspicious text to 7726 before deleting it.
- Verify unexpected messages by contacting the organisation through official channels.
- Enable automatic updates and multi-factor authentication on business accounts.
- Report fraud to Action Fraud and your bank if you lose money or data.
- Review your business cyber defences through the NCSC and Cyber Essentials.
Knowing how to protect your phone against text smishing gives you time to pause, check the source, and keep your women-led business safe.






