arrow_backBack
Techartificial-intelligencecybersecurityfraud

AI built at Brazil's Unicamp blocks SMS scam texts before they arrive

bookmark_borderSave
LCBy Luiza Campos•September 26, 2026•Sources: Jornal da Unicamp, G1

An artificial intelligence model created at the Institute of Computing of Unicamp, the State University of Campinas in São Paulo state, is already blocking fraudulent text messages before they reach users' phones. The tool, named Smish-Checker, was built by computer scientist Stephane Schwarz during her PhD at the Recod.ai lab, led by professor Anderson Rocha. According to a report by news site G1 published on Saturday (26), the project began as a request from a cloud communications company and now runs in a production environment.

The target is smishing, SMS plus phishing: a message that poses as a bank, retailer or known service, pushes for urgency and carries a link to a fake page that harvests personal data. Criminals like the channel because SMS is cheap, works without internet and can be blasted in bulk. Generative AI made it worse, as Schwarz told Jornal da Unicamp, the university's own newspaper:

"The technical barrier that used to limit fraudsters has practically disappeared. Today, anyone can generate smishing messages nearly indistinguishable from legitimate communication, with no Portuguese mistakes, natural tone and even personalization."

How the system spots the scam

The model stacks several layers of evidence, like a bank guard who checks ID, signature and account history before opening the door. It first inspects the link itself: letters swapped for lookalike characters (an uppercase "I", a lowercase "l" and a lowercase "i" can look almost identical on screen, while the computer reads them as different symbols), URL shorteners that hide the destination, and public domain records such as a site's age, owner and creation date. It then weighs the content: the text, the message's intent (an alert, a bill, a promotion) and the title of the landing page. A built-in technique also shows which piece of evidence mattered most in each decision, which helps audits. Finally, it measures the round-trip time of the connection to catch man in the middle scams, in which the fake page relays what the victim types to the real site, like a criminal who intercepts a letter, copies it and sends it on: the extra stop on the fraudster's servers leaves a mark on the clock. "We don't cling to a single point of advantage. We look at multiple layers and multiple pieces of information," Schwarz summarized to G1. According to Jornal da Unicamp, the model scored above 90% accuracy in tests with messages about a suspended credit card, and the methodology also applies to channels such as WhatsApp and Facebook Messenger.

The project's origin explains that design. The demand came from a company that makes money delivering bulk SMS to banks, retailers and services, carrying alerts, bills and one-time codes. Scams flooding the channel mean clients lose trust in it, which erodes the business. Hence the fixation on never blocking honest messages: "blocking legitimate content is really bad in a real business context," Schwarz said. Jornal da Unicamp reports that the work left the university and was integrated into the systems of an international company.

What we still don't know

Neither report names the company using the technology, and the published numbers come from tests; real-world metrics, such as how many messages get blocked or the false-blocking rate, remain private. Jornal da Unicamp itself notes that the timing analysis performs differently depending on how the fraudster's server is configured. And the race goes on: the development started by studying how criminals dodge filters, and new tricks tend to follow.

No AI replaces suspicion. Banks and retailers do not ask for passwords or card re-registration over SMS links. Faced with an urgent bill or a prize, the safe route is to skip the link, open the official app or type the site address into the browser, and contact the company through official channels if in doubt. Unicamp's filter acts before delivery; users only notice it exists when an unwanted message fails to arrive.

Comments

No comments yet. Be the first to comment!

Log in to leave a comment. Sign in