Can someone hack my phone by sending a text message?
In rare cases yes — through zero-click exploits targeting unpatched OS vulnerabilities — but the far more common risk is phishing links within texts.
Last reviewed: 1 August 2026
Explanation
Highly sophisticated attacks known as zero-click exploits can compromise certain phones when a specially crafted message is received, without the user clicking anything. These attacks generally target specific individuals using expensive commercial spyware and are not used in typical mass fraud. For most people, the real risk from text messages is smishing: a text that contains a link leading to a phishing site or malware download, requiring the user to take an action. Keeping your phone's operating system and apps fully updated is the best protection against both categories of attack, as updates patch known vulnerabilities. Be cautious about any link in an unexpected text, even from a number you recognise.
Separating the two threat levels prevents both panic and complacency. Zero-click spyware is expensive, targeted at journalists, activists, executives, and officials, and burning such a capability on ordinary fraud makes no economic sense — so for most people it belongs off the worry list. Smishing, by contrast, is industrial: sent in millions, cheap to run, and profitable even at tiny response rates. Your defences should match the real threat, which means link discipline and updates rather than fear of the message itself.
A middle category is worth knowing: texts that try to talk you into installing something. A message urging you to download an app from outside the official store — a 'tracking app', a 'security update', a 'video player' — is attempting to bypass the strongest protection your phone has. Sideloaded malware delivered this way can read messages and capture banking sessions. Simply reading a text remains essentially safe on an updated phone; installing what a text asks for is where compromise actually happens.
Common red flags
- Unexpected text with a link from an unknown or spoofed number
- Text claims to be from your bank, a parcel company, or a government agency
- Unusual battery drain or data usage after receiving a strange message
- Apps opening or closing on their own
- Receiving unexpected one-time passcodes you didn't request
What to do now
- Keep your phone OS and all apps updated at all times
- Never click links in unexpected texts
- If you suspect compromise, run a security scan and consider a factory reset
- Report smishing texts to your carrier's spam number (7726 in the UK and US)
Frequently asked questions
Should I be worried about spyware on my phone?
For most people, the main risk is phishing rather than spyware. If you are concerned about targeted surveillance, organisations such as Access Now's Digital Security Helpline offer free assistance.
Can just opening a text message infect my phone?
On an up-to-date phone, opening and reading a message is essentially safe. The practical risks require an action from you — tapping a link, entering credentials, or installing an app from outside the official store. Keep the OS updated and those actions disciplined.