Have you received any weird text messages lately – from yourself?
Don’t worry, you are not alone and you are probably not having an out of body experience. The latest trend in spam involves cell phone users receiving text messages from what appears to be their own phone number.
The messages usually claim to be from the user’s wireless carrier, referencing the recipient’s wireless bill and including a link to a “free gift”. Spoiler alert: the link instead leads to potentially malicious websites, according to users on Reddit and Twitter.
This is all potentially very confusing. Here’s what you need to know about these spam emails and what you can do about them:
Why am I getting these text messages?
“As part of a recent fraud scheme, bad actors sent text messages to some Verizon customers that appear to come from the customers’ own number,” Verizon spokesman Rich Young said. “Since the discovery of the scheme, our company has made a significant effort to limit the current activity.”
Young noted a recent increase in spam text messages across all mobile carriers, and said Verizon is “actively working with others in our industry and with U.S. law enforcement as part of an investigation.” aimed at identifying and arresting these fraudsters and their illegal actions”.
Robokiller, a company that makes a mobile app to block spam calls and texts, said it tracked more than 5,000 incidents of spam text messages with the same number over the past week, as of Thursday.
According to Robokiller, typical versions of spam texts include messages that say, “Free msg: Your bill is paid for March,” along with a dodgy link that claims to offer a free gift. In other cases, the spam message includes a link that claims to take the recipient to a Verizon survey, according to CNET.
A writer from The Verge noted that clicking the link in a particular post took the writer to the website of Channel One Russia, a Russian government-run television network. “We have no indication of any Russian involvement” in the spam, Young said.
An AT&T spokesperson told CNBC Make It, “We are monitoring this situation closely and have not seen anything similar on our network.” A T-Mobile spokesperson did not immediately respond to CNBC Make It’s request for comment.
What about other types of spam?
The recent surge in spam messages with the same number comes amid an increase in the total number of spam messages received by US wireless customers in recent years.
Last year, the Federal Communications Commission (FCC) warned that spam messages have increased during the Covid-19 pandemic, with scammers more likely to prey on desperate Americans suffering from health or financial difficulties. Robokiller said Americans received a total of 87.8 billion spam text messages in 2021, a 58% increase from the previous year.
Spam messages are often referred to as SMS phishing or “smishing” attacks, where scammers attempt to trick wireless users into sharing personal information or clicking on malware-infested links. In some cases, spammers trick your phone’s caller ID to make it look like a text or call is coming from a local or government-associated number, a practice called “identity spoofing.”
In the case of spam texts with the same number, it seems that “bad actors” are even able to spoof recipients’ own numbers, which adds another layer to the process.
What can I do about this?
Security experts suggest that you should always be wary of phone calls or text messages from unidentified or unknown numbers.
The FCC adds that you should “never share your personal or financial information via email, text, or phone.” The agency also advises against clicking on links or attachments you receive in a text message, and calling your friend who is texting you a link before clicking, to make sure they haven’t been hacked.
Verizon offers similar guidance for dealing with potential phishing attacks involving suspicious text. The company says you shouldn’t respond to suspicious messages at all. Instead, Verizon advises customers to forward spam texts, especially those claiming to be from Verizon, to SPAM (7726).
You can also report potential spam text messages and emails to government agencies and law enforcement, including by completing the Federal Trade Commission’s Online Fraud Complaint Form and the Crime Complaint Center on the Internet from the Federal Bureau of Investigation.
If you click on a malicious link, experts say your best bet is to avoid entering any information and disconnecting your device from the internet as soon as possible. Then go to your device settings, find the apps you don’t remember downloading and delete them.
You can also use an antivirus app to scan your device for malware and change passwords for any accounts you think may have been compromised. If you believe any of your personal or financial information may have been compromised, you can also freeze your credit for free to prevent potential identity theft.
Register now: Be smarter about your money and your career with our weekly newsletter
If your passwords are less than 8 characters, change them immediately, according to a new study
These are the 20 most common leaked passwords on the dark web – make sure none of them are yours