Text messages feel personal and urgent. They arrive on a phone people check constantly, often in the middle of a busy shift. That is exactly why scammers use them. A fake text claiming to be from a scheduling app or the payroll department can trick a busy employee into handing over a password or banking details in seconds.
This kind of attack is called smishing, short for SMS phishing. Healthcare and senior-living staff are frequent targets because they rely on scheduling and pay tools, work irregular hours and may be using personal phones for work. This post explains how these scams look and what to do about them.
Scammers do not need to know which app your facility uses. They guess, or they use generic wording that sounds right to anyone. Common themes include:
Shift swap or open shift messages. "A shift is available. Confirm now to claim it." The link leads to a fake sign-in page.
Schedule change notices. "Your schedule has been updated. Review immediately."
Payroll problems. "There is an issue with your direct deposit. Verify your details to avoid a delay."
Pay raise or bonus offers. "You are eligible for a bonus. Log in to claim it."
Benefits or HR enrollment deadlines. "Action required to keep your benefits."
Messages from a supposed manager. "Hi, it is the administrator. Are you available? I need a favor." followed by a request for gift cards or a code.
The link in the text typically opens a page designed to look like a real login. Anything you type goes straight to the attacker.
Urgency or a deadline. Scammers want you to act before you think.
An unexpected message about money or your schedule. Your real employer's process is usually familiar.
A link in a text from an unknown number. Official systems often send notifications through their own apps or through a known number.
A strange or shortened web address. The domain may look close to the real one but be slightly different.
Requests for a password, a verification code, your Social Security number or bank details. Legitimate systems do not ask you to share a code by text.
Poor grammar or odd phrasing. Not always present, but worth noting.
Do not tap the link. Instead, open the scheduling or payroll app directly, or type the address you normally use.
Do not reply, even with "stop." A response confirms your number is active.
Check with a person. Ask your supervisor or HR using a phone number you already know.
Report it. Forward a screenshot to your IT contact or designated reporting address. On many phones you can also report the text as junk, and you can forward it to 7726 (SPAM), which wireless carriers use to collect scam reports.
If you already clicked or entered information, tell IT immediately, change your password, and contact your bank if financial details were involved. Speed matters, and nobody should be punished for reporting honestly.
Be explicit about how your scheduling and payroll systems communicate. If shift offers only come through a specific app, say so. If HR will never ask for banking details by text, say that. When staff know what normal looks like, fake messages stand out.
Give staff one easy way to report a suspicious text, such as a dedicated email address or a phone number. Thank people who report, even if the message turns out to be harmless.
Even if a password is stolen, multi-factor authentication on scheduling, payroll and email accounts makes it harder for an attacker to use it. Prefer methods that cannot be easily intercepted or shared.
Require extra verification before direct deposit information can be changed. A payroll diversion scam works by quietly rerouting a paycheck, so a callback or in-person confirmation step is a valuable control.
If staff use personal devices for work, publish simple guidance and consider whether work apps can be protected without taking over the phone. Respect privacy while protecting the organization.
Many programs focus on email. Add examples of fake texts, ideally using realistic but fictional samples that mirror the apps your staff actually use.
A quick message in a staff meeting or a break room poster with three rules works better than a long policy: do not tap links in unexpected texts, open the app yourself, and report anything odd.
UnityCare IT helps healthcare employers build practical awareness materials, set up multi-factor authentication and create simple reporting routines. A supportive culture where staff ask first and report quickly does more to stop smishing than any filter.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172