Skip to main content
Find a DoctorGet Care Now
Skip to main content
Search icon magnifying glass

Contrast

Contact

Share

Give Now

MyChart

Help

Yale New Haven Health System

Security awareness monthly tip: Don’t take the text message bait

Hands holding a phone

Texting is quick and convenient, but text messages are also a growing target for cybercriminals.

SMShing (SMS phishing) occurs when attackers send malicious text messages designed to trick you into clicking a link, calling a number or sharing sensitive information. These messages often look urgent and may appear to come from a trusted source, such as an IT department, bank, delivery service or even a coworker.

Yale New Haven Health’s Office of Information Security (OIS) reminds employees about common signs of SMShing messages, which might:

  • Claim your account has been locked or compromised
  • Ask you to verify credentials, reset passwords or make payments
  • Contain unexpected links or phone numbers
  • Use urgent language like “Act Now” or “Immediate Action Required” 
  • Come from unknown or slightly altered phone numbers

How to protect yourself

  • Don’t click links in unexpected or suspicious text messages.
  • Don’t reply to messages requesting passwords, codes or personal information.
  • Verify requests by contacting the sender through a trusted method (not the number in the text).
  • Check links carefully if you choose to preview them and look for misspellings or unusual domains.
  • Block suspicious senders to prevent further attempts.
  • Delete suspicious messages after reporting them.

Remember, text messages are just as risky as email when it comes to phishing. If a message seems urgent, unexpected or “off,” pause and verify before acting.

For more tips or training, or if you have questions on this topic, email the Office of Information Security at [email protected].