Scams & Spam

AI-Generated SMS Scams: The New Technology Threatening Everyone

AI has made scams several times more convincing — here's how to spot a message written by artificial intelligence

By Traceback Editorial Team
10 min read
Young man reading suspicious AI-generated SMS message on smartphone

AI-Generated SMS Scams: The New Technology Threatening Everyone

An SMS from your bank. Perfect language. Precise politeness. Gentle but urgent pressure.

Except the bank didn't send it. ChatGPT did.

Artificial intelligence has transformed SMS scams from typo-riddled messages into perfectly crafted personal letters, and your chances of spotting the fraud have dropped to nearly zero. We've examined dozens of cases in recent months: even people who consider themselves "tech-savvy" are falling into the trap.

This is a new reality where technology writes better than you, understands you better than you, and knows exactly how to make you click.

How Artificial Intelligence Changed the SMS Scam Game

Until two years ago, spotting an SMS scam was relatively simple. Messages with blatant spelling errors ("Dear valued costumer"), poor Google Translate from English, and fake domains that were obvious from a mile away. Your brain would automatically pick up on the forgery.

2025 brought a dramatic shift. Artificial intelligence like ChatGPT or Claude now writes in fluent Hebrew, adapts tone to age and context, and precisely mimics the writing style of a specific bank or company. It doesn't just copy — it learns.

A real comparison:

Classic message (2022):
"Hello! Your account has been blocked due to security issue. Enter link immediately to update details: bit.ly/xyz123"

AI-written message (2025):
"Hi Ronit, we've detected unusual activity on your card ending in 4523. Please confirm this was you within 24 hours to prevent temporary blocking. Thanks, Leumi Card team."

The difference? The second message uses your first name, mentions the last digits of a card (possibly leaked in an old breach), and writes in a "caring" tone instead of threatening. It doesn't ask to "update details" — it asks you to "confirm this was you." It sounds reasonable. It sounds real.

Why does this work so well? Because AI learns from real content. It reads thousands of legitimate SMS messages from Israeli banks, analyzes the structure, format, and exact phrases they use. It knows that Bank Leumi writes "Leumi Card team" and not "Credit Department." It knows they don't use unnecessary exclamation marks. It adapts itself to local culture, language, and expectations.

Cyber authorities in Israel report a sharp increase in complaints about sophisticated SMS scams since the beginning of 2025. Conversations with investigators from the Israel Police and bank call center representatives point to a clear trend: scams are becoming harder to detect.

Why AI Messages Are So Convincing — The Techniques Artificial Intelligence Uses

Perfect human language
No spelling errors. Hebrew flows naturally, grammar is correct, sentences are constructed organically. You can no longer rely on "if it's written badly, it's a scam."

Personalization
AI can read a public profile on Facebook, LinkedIn, or Instagram, and tailor the content. If you posted last week that you bought a new car, the message will mention "vehicle details update." If you live in Tel Aviv, it'll write "Dizengoff branch." This isn't random — it's intentional.

Sophisticated emotional pressure
Forget crude threats. AI uses a "caring" tone that "wants to help." "We've detected unusual activity" sounds like the bank is looking out for you. "Please confirm within 24 hours" gives you time, doesn't push you to panic, but creates moderate urgency that makes you act.

Brand mimicry
Artificial intelligence analyzes hundreds of real SMS messages from Israeli banks. It learns how Bank Hapoalim signs off on messages, how Leumi phrases security alerts, and how Mizrahi Tefahot writes service messages. It copies the style exactly, including format and sentence structure.

Natural conversation pace
In cases where the scam moves to WhatsApp or Telegram, AI knows how to respond immediately but with simulated "typing." It answers in real-time, uses emojis moderately, and knows when to add "one moment, I'm checking" to feel human.

Comparison between a real message and one written by AI:

Real SMS from Bank Leumi:
"Bank Leumi: A transaction of 450 NIS was made on your card at Super-Pharm. Details: *6522 or in the app."

Fake SMS written by AI:
"Bank Leumi: We've detected a charge of 1,240 NIS on your card at Aliexpress. If you didn't make this transaction, please confirm here within 12 hours: [fake link]. Leumi Card team."

Almost no differences. The tone is similar, the format identical, the language correct. The only difference is the link — and the real bank won't ask you to "confirm" via SMS. But if you don't know this in advance, you'll click.

How to Spot an SMS Message Written by Artificial Intelligence

Here's the truth: there's no way to distinguish with absolute certainty between a message written by AI and one written by a human. The technology is too good. But there are red flags that AI still can't hide.

Shortened link or strange domain
A real bank won't use shortening services (bit.ly, tinyurl). It also won't send you to "Ieumi.co.il" (I instead of L) or "bank-hapoalim-secure.com." If the domain doesn't end with the bank's official .co.il, it's a fake.

Request for immediate action via link
Israeli banks don't send a link to update details via SMS. If the message says "click here to confirm," "update password," or "verify identity," it's a fake. The bank will ask you to log into the app, the official website, or call the call center.

No way to verify the sender
If the number isn't identified or it's a regular mobile number (050, 052), it's suspicious. Banks send from short codes (*6522) or registered landline numbers. If the number pretends to be a call center but isn't listed on the bank's website, it's a fake.

Request for sensitive information
This is the golden rule: No legitimate organization will ask you for a password, CVV, or one-time code via SMS. If the message asks you to "enter a verification code in a link," it's 100% a scam.

Three-step verification:

  1. Don't click the link — ever.
  2. Call the official call center of the organization (number from the official website, not from the SMS).
  3. Ask: "Did you send me an SMS at X time?" If the answer is no, report the message.

If the answer is yes, request instructions from the real representative — don't act based on the SMS itself.

Why We're All Vulnerable — Even If You're "Tech-Savvy"

There's a common illusion: young people, people who work in high-tech, think they're immune. They're not.

We examined a case of a 35-year-old software developer who transferred 800 shekels to scammers after an email that looked completely authentic. He told us: "I teach information security in an online course. I thought I was above this. But I got the message right after ordering a package on Amazon, and it mentioned the correct tracking number. I didn't think twice."

AI targets emotion, not logic. And we all have emotions.

You can be a cyber expert, but if you're tired after a 12-hour workday, you get a message that looks like it's from the bank, and your brain wants to solve the problem quickly, your alertness plummets. AI knows this. It times messages for peak hours (17:00-20:00, when people are with family).

Once technology writes better than you, you can't rely on intuition. You need rules that you apply automatically, even when you're stressed.

What to Do Now — A Practical Defense Plan (3 Layers)

Layer 1: Preventive preparation

  • Save all official numbers of your bank, insurance, Israel Post, and delivery services with a clear identifying name. When a message arrives, you have the correct number ready.
  • Enable two-factor authentication (2FA) on your bank account, email, and social networks.
  • Update your phone to the latest version. Operating systems constantly improve spam filters.

Layer 2: Real-time

  • Got an SMS? Stop 30 seconds before clicking. This is the most important rule. Ask yourself:

    • Was I expecting this message?
    • Did I perform an action that requires confirmation?
    • Is the number identified?
  • Check the sender's number. If it's unidentified or a regular mobile number, don't click any link.

Layer 3: After suspicion

  • If you clicked a suspicious link: Don't enter anything. Close the page.
  • Change passwords immediately from another device.
  • Call the bank and explain what happened. They can temporarily block the account.
  • Check account activity through the official app.
  • Report: Call the police (110) or file an online complaint on the Israel Police website.

Comparison Table: "Classic" SMS Scam vs. AI Scam (2026)

Criterion Pre-AI Scam (until 2023) AI-Based Scam (2025+)
Language Spelling errors, poor translation Perfect Hebrew, natural phrasing
Personalization Generic message for everyone Text tailored to age, location, context
Tone Pressuring, threatening Polite, "caring," professional
Response time Slow (human operator) Immediate, 24/7
Brand mimicry ability Weak, easy to spot Very high, precise imitation
Success rate About 5-10% of recipients fall for it About 25-40% (according to reported cases)

FAQ: AI SMS Scams

How does artificial intelligence write SMS messages? Does it require a programmer?

No. Tools like ChatGPT, Claude, or Google Gemini are available to everyone for free or at low cost. A scammer writes: "Write me an SMS from Bank Leumi asking to update details," and gets a ready answer in Hebrew within seconds. No technical knowledge needed. It's as simple as sending a WhatsApp message.

Is there a technical way to detect text written by AI?

Currently very difficult. Tools like GPTZero or Copyleaks aren't always accurate in Hebrew and are better suited for longer texts. The best way is default skepticism: don't trust the message itself, trust the process. Call the call center, check in the app, don't act based on an SMS.

I received an SMS from the bank with a verification code — is this AI?

Not necessarily. Verification codes are sent all the time when you log into the app or perform a secure action. But if you received a code without requesting it (didn't log in, didn't try to connect), that's a warning sign. Call the bank immediately and ask to temporarily block the account.

What should I do if I already entered a password on a fake link?

  1. Change the password immediately from another device.
  2. Call the bank and explain what happened.
  3. Check account activity through the official app.
  4. Consider replacing your credit card if you entered card details.
  5. Report to the police (110) and the Privacy Protection Authority.

Can security apps on phones block AI scams?

Partially. Apps like Truecaller or the built-in filters in Android and iOS block numbers known to be malicious. But if the scam is new, the app won't detect it. It's a game of chase: scammers are always one step ahead. Use these apps as an additional layer, but don't rely on them completely.

What's the difference between regular phishing and AI phishing?

Regular phishing: A human scammer composes a message, sometimes using templates. It has small errors and a tone that doesn't quite fit.

AI phishing: Artificial intelligence generates personalized text in perfect language with a tone that feels "right." The difference is in execution quality — it's like the difference between crude manual forgery and sophisticated forgery that's been carefully tested.


⚠️ Disclaimer: This article is general information only and does not constitute legal advice. For any specific legal situation, consult a qualified attorney. Traceback is not responsible for legal outcomes.

Related reading
Get the app

See who's calling. Every time. One tap.

Join 34,000+ people who finally know the real number behind every No Caller ID call, unknown number, and private caller. 30,000+ revealed and counting.