Text Scams
What to Do If You Replied to a Suspicious Text
Replying to a suspicious text does not automatically mean your accounts are compromised, but it can confirm your number is active or expose information. This guide explains what to do based on what you shared.
What matters is what you shared
If you replied to a suspicious text, the risk depends on what you sent. A simple reply may confirm your number is active. Sharing a password, one-time code, card number, banking detail, Social Security number, or account information is more serious and needs immediate action.
Do not keep chatting with the sender. Do not click follow-up links. Do not send verification codes, screenshots, documents, or money. Move to official channels for any account or company mentioned in the message.
Replying once does not prove you were hacked. Treat it as a signal to stop interaction, review what was shared, and secure affected accounts.
Why scammers want replies
A reply can tell a scammer that the number is active and that a real person is reading. It may lead to more messages, calls, or attempts to move you into a longer conversation.
The FTC warns that scammers use texts, calls, and emails to impersonate companies, agencies, banks, delivery services, and support teams. Their goal is usually to get money, account access, or sensitive information.
Some scams start with harmless-looking questions. The danger increases when the conversation turns urgent or asks you to verify identity.
- Confirming your number is active.
- Building trust through conversation.
- Asking for one-time codes.
- Sending fake links.
- Requesting payment.
- Collecting personal details.
Check exposure as context
If your phone number or email appears in known exposure data, scammers may have more context to target you. A match does not prove the suspicious text came from a specific breach, but it can explain why the message felt personal.
Only check identifiers you own or are authorized to manage. Never enter passwords, one-time codes, SSNs, card numbers, passport numbers, or bank details into an exposure checker.
If you only replied with words
Stop responding, block or report the sender, and watch for more spam. A simple reply such as yes, no, or who is this is usually less serious than sharing account details.
Still, be cautious with follow-up messages. Scammers may try a second approach after confirming the number is active.
If you shared a code or password
Secure the named account immediately through its official app or website. Change the password, sign out unknown sessions, review recovery settings, and enable MFA.
If the password was reused, change it everywhere it was used.
- Change affected passwords.
- Sign out unknown sessions.
- Review recovery email and phone.
- Enable MFA.
- Check connected apps.
- Monitor alerts.
If you shared financial information
Contact your bank or card issuer through official channels. Review transactions and ask about card replacement, disputes, account locks, or fraud monitoring if needed.
Do not use phone numbers sent by the suspicious text.
Protect your phone number
Set a carrier PIN and ask about SIM swap or port-out protection. The FCC warns that phone-number takeover can support account attacks.
Move important accounts away from SMS-only authentication where stronger options exist.
Report harm if it occurred
If you lost money, shared identity information, or experienced account takeover, keep records and use official reporting channels such as the FTC or FBI IC3.
Save texts, dates, transaction details, and support case numbers.
Frequently asked questions
Can replying to a scam text hack my phone?
A text reply alone usually does not hack your phone, but it can confirm your number is active and lead to more targeting.
What if I shared a one-time code?
Secure the related account immediately, sign out unknown sessions, and contact the provider through official support.
Should I block the number?
Yes, after preserving records if you need them for a bank, provider, or official report.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
