Smishing Analyzer
Check a messageDownload
Appearance

What happens after you click

Not a list of warning signs. What the person on the other end is actually doing, minute by minute.

Last reviewed 28 August 2026

Most advice tells you what not to do. It works badly, because a rule you do not understand is a rule you will break under pressure. So here is the other side of it: what happens once someone acts on one of these messages.

The ninety seconds after an OTP

  1. They are already logged in, waiting

    Before they call, they have your phone number and enough details to reach the login screen. They are sitting on the last step, the one that needs the code. That is the only thing they are missing.

  2. The code arrives on your phone because THEY asked for it

    This is the part people miss. The OTP is real, from your real bank, and it arrived because the person on the phone just pressed a button. Its arrival feels like proof they are genuine. It is proof of the opposite.

  3. You read it out. They type it in.

    The whole conversation up to that point exists to get through those six digits before the code expires. That is why they hurry you, and why they keep talking so you do not read the warning in the message itself.

  4. They move the money immediately, in small pieces

    Usually into several accounts at once, often to buy things that can be resold. Small amounts attract fewer automatic checks. This takes seconds, not hours.

  5. They keep you on the call

    Because while you are talking, you are not opening your banking app. The conversation after the code has been used is doing work too.

  6. It is withdrawn or moved on before you report it

    This is why reporting inside the hour matters. A bank can sometimes freeze a receiving account. It cannot get back cash that has already left one.

What happens after a link

The page you land on is usually a copy of the real login screen, sometimes pixel for pixel. Some of them pass what you type straight through to the real bank in real time, so the site behaves exactly as it should, right down to asking for the OTP that genuinely arrives.

Nothing on the page will look wrong, because it is not meant to. This is why the advice is to open your own app rather than to look carefully at the page: careful looking is not a defence against a perfect copy.

What happens after an install

A screen-sharing app lets someone watch you type, including the password you are changing because you have become suspicious. An APK installed from a link can read the messages arriving on the phone, which means it can read the OTPs without needing to ask you for them at all.

In both cases the fix is the same and it is urgent: turn off Wi-Fi and mobile data, uninstall it, then change passwords from a different device.

If money has already gone · The five rules