Text message fraud grew in Mexico during 2026 and, with it, customers’ distrust of any SMS. For a company that sends legitimate alerts, codes and notifications, that is a business problem: its messages compete with the fraudsters’. These are the figures and the practices that separate a trusted sender from a suspicious one.

The figures: fraud has moved to text messages
In the first half of 2026, 43,871 complaints of possible fraud were filed with Condusef, Mexico’s financial consumer protection agency, 16.7% more than a year earlier. Of those, 14,627 were online fraud, up 14.2%. Four out of every ten complaints the agency receives involve some type of fraud.
In June, Condusef warned that fraudsters have moved from phone calls to messages with links, because more and more people do not answer unknown numbers. Its president, Óscar Rosado, said the fastest-growing loss range is 20,000 to 50,000 pesos per case.
The pretext adapts to the news. In 2026, messages and pages appeared that imitate mobile carriers to exploit the mobile line registration with the CURP, and others offering promotions or cheap streaming services tied to the World Cup.
Nor does fraud target only older adults. In the state of Jalisco, between January and August 2026, Condusef received 11,902 complaints, 5,159 of them (43.3%) over possible fraud; complaints related to digital banking rose 298.3%, and the 30-39 age group saw the largest increase (40.1%). According to the agency, criminals reach their victims through their phones, with SMS and WhatsApp messages that create a sense of urgency.
Anatomy of a fraudulent message
Almost all of them follow the same pattern, and recognizing it helps you design messages that look nothing like it:
- Artificial urgency: an account about to be locked, a deadline that expires today, a charge that must be cancelled within minutes.
- Changing sender: different long numbers in every wave, instead of a stable sender.
- Look-alike link: domains with hyphens, extra words or generic URL shorteners.
- A form that asks for too much: password, PIN, verification code or card details.
- No verifiable context: the message does not match anything the customer has done.
It is worth repeating to your customers: no financial institution asks for passwords, PINs, tokens or codes by text message or by phone.
Ten practices so your SMS is never mistaken for fraud
- Always use the same sender ID for the same type of message. Consistency is what trains the customer.
- Keep transactional and promotional traffic apart, with different senders and schedules.
- Publish on your website which senders you use and what kind of messages you send, so customers can check.
- Use links on your own domain, not generic shorteners. If you need to track clicks, use your own short domain.
- Never ask for passwords, codes, PINs or card details in the message, and say so in the text itself.
- In messages that carry a code, state what it is for, how long it lasts and a warning not to share it. See how to structure them in our guide to SMS OTP authentication.
- Avoid extreme urgency. If the matter is urgent, give a way to verify it: your app or your customer service number.
- Personalize with details only you and the customer know, such as the last digits of an order, never with sensitive data.
- Keep a visible reporting channel so customers can flag suspicious messages that use your name.
- Monitor your brand: alerts for domains similar to yours and a regular review of what customers report.
What to do if your brand is impersonated
- Document the case: capture the message, the sender and the URL, with date and time.
- Warn your customers through your official channels, with a short text that describes the scam and reminds them what your company never asks for.
- Report the fake domain to its hosting provider and request a takedown; report the number or sender to your carrier, and to Condusef if financial services are involved.
- Check whether the attack mirrors one of your campaigns: if the fraud imitates a message you do send, change its format.
- Keep the record. Traceability of your own sends is how you prove which messages came from your platform and which did not.
Related: Mexico’s CNBV now allows authentication codes to be sent by SMS in embedded banking. See what changes for banks and fintechs.
See also: Information security at Grupo Tecnophone · SMS as a critical channel for banking and fintech: OTP, alerts and fallback · SMS for government and institutions
Sources
- “CONDUSEF alerta por fraudes financieros mediante SMS y WhatsApp en Jalisco”, La Crónica de Hoy, September 29, 2026. Read article
- “Reclamaciones por posible fraude crecen 16.7%”, Forbes México, July 9, 2026 (in Spanish). Read article
- “Por posible fraude, 4 de cada 10 reclamos que se registran en la Condusef”, La Jornada, July 10, 2026 (in Spanish). Read article
- “Millones de mexicanos ya no contestan llamadas de desconocidos: Condusef alerta que ahora los fraudes llegan por SMS”, Xataka México, June 2026 (in Spanish). Read article
- “Fraude por SMS crece en México: un clic puede costarte hasta 50 mil pesos”, N+, September 23, 2026 (in Spanish). Read article
- “La prórroga del registro telefónico normaliza los fraudes por SMS”, Expansión, July 10, 2026 (in Spanish). Read article
- “Te ofrecen streaming a precios regalados para ver el Mundial 2026, pero roban tu dinero y datos”, El Informador, June 8, 2026 (in Spanish). Read article
Frequently asked questions
Want your messages to stand apart from fraudulent ones?
Grupo Tecnophone runs enterprise SMS messaging in Mexico with configurable senders, per-message delivery reports and traceability for every send. Request a 30-day pilot or explore our solutions for banking and financial services.


