The scam arriving by text message this summer looks nothing like sextortion โ€” and that’s exactly why it matters to our readers. Reports of IRS impersonation text messages are up roughly 40% in 2025, part of a smishing (SMS phishing) wave that harvests exactly the personal data โ€” names, phones, employers, financial details โ€” that later fuels targeted extortion. The two crime families are converging on the same supply chain.

The Scale and the Pattern

~40% โ€” increase in IRS impersonation text reports in 2025
0 โ€” legitimate IRS first-contacts by text message demanding payment
Refunds, unpaid tolls, delivery fees โ€” the dominant lures

The IRS has stated it plainly and repeatedly: it does not initiate contact by text message demanding payment or personal information. Every “your tax refund is pending verification” text is a fraud โ€” every one. The lures rotate with the season: refund claims during filing season, “unpaid toll” notices in summer, parcel-delivery fees around holidays. The mechanics never change: urgency, a link, a credential-harvesting page.

How SMS Spoofing Works โ€” for Detection Purposes

Understanding the trick defuses it. The SMS system allows the sender of a message to declare its own originating identifier, and carriers historically trusted that declaration. The result, conceptually: a scammer can make a text display as coming from a legitimate short code, a real agency label, or even a number that matches your area code. The “from” field on a text is a costume, not an address.

Caller ID on SMS is a self-reported name badge. That’s the entire foundation of every impersonation text you’ve ever received โ€” and the reason “but it said IRS right there” means nothing.

Anatomy of the Lure

What Gets Stolen โ€” and What It Feeds

Here is the sextortion connection. Smishing pages harvest names, birthdates, addresses, phone numbers, employer details, and card data. That corpus is exactly what organized crews use to build credible targeted extortion: a victim who receives a threat containing their real employer name and city believes the perpetrator “has files” on them. Often, the perpetrator has nothing but a smishing database. When we run footprint analyses for clients โ€” part of the methodology in our service tiers โ€” we routinely trace the “impossibly personal” details in threats back to breached or phished data rather than genuine compromise.

How to Identify and Report

The Unified Defensive Posture

Smishing, sextortion, and the hybrid schemes we covered in May’s pig-butchering analysis share a single vulnerability: they all depend on the victim reacting instead of verifying. The sequence that defeats all of them is identical โ€” pause, verify through an independent channel, document, report. If a “too personal to be fake” message has you worried, the FAQ addresses how to assess real versus manufactured leverage, and confidential help is available via our intake around the clock.

If you or someone you know is being sextorted:

Don’t pay. Don’t panic. Document everything. A senior OSINT specialist reviews every confidential intake within 4 hours โ€” and the consultation is free.

help@smishguard.bond