Helping an elderly parent deal with scam texts: a guide that doesn't talk down to them

Back to the blog
22 August 202612 min read

There's a sentence you often hear on the phone, on a Sunday afternoon, with a note of embarrassment in the voice: "I got a strange message from the bank, I think I clicked." Then a silence. Then, almost always, an apology: "I'm so stupid, I shouldn't have."

That shame is the real problem. It delays reporting by several hours, sometimes several days, when the useful window for blocking a payment or a card is measured in minutes. And it rests on a misunderstanding: older people don't get caught because they're "hopeless with computers." They get caught because the fraudulent messages of 2026 are designed to work on everyone, and because they have slightly fewer reference points for cross-checking information — not slightly less intelligence.

Supporting a parent in this area is a balancing act: you have to protect without dispossessing. Here's how to go about it in practice — settings, vocabulary, and the procedure once the damage is done.

Close-up of a smartphone lying on a black surface, showing the Google, phone and messaging icons

Why text messages remain the preferred angle of attack

We tend to picture the modern scam as a matter of sophisticated fake websites. In practice, the way in is still the message, and for a structural reason: a text message has no friends list. There's no contact request, no moderation, no sorting algorithm. Any number in the world can send a message to any other number.

Add three characteristics specific to the channel:

  • The message lands in a legitimate thread. On iOS as on Android, a text sent with a spoofed sender name can slot straight into the existing conversation with your bank or your mobile operator. The fraudulent message then appears right below genuine ones. No amount of visual vigilance survives that.
  • The screen is small. A truncated URL on a six-inch display, in a medium-sized font, read with age-related long-sightedness, simply isn't legible. The deceptive subdomain goes unnoticed.
  • The channel still inspires trust. An entire generation learned that texting was the "serious" channel: the doctor, the lab, the bank, the pharmacy. That reputation, earned over twenty years, is now being exploited.

For several years now, the French platform Cybermalveillance.gouv.fr has ranked phishing — including smishing, its text-message variant — at the top of the assistance requests it receives from individuals. This is not a niche phenomenon; it is the bread and butter of mass cybercrime.

What has changed over the past two or three years

The cliché of the scam text riddled with spelling mistakes belongs to the past. Text-generation tools have removed the main warning sign: clumsy language. Messages are now grammatically flawless, correctly punctuated, written in a credible administrative register.

Three developments are particularly relevant to older people:

  1. Personalisation. Repeated database leaks make it possible to quote a name, a town, sometimes a health insurer or a phone provider. A message that opens with "Good morning Mrs Duval" instantly disarms suspicion.
  2. The switch to a phone call. The text is now just a trigger: it invites you to call a number back, where a human being — the "fake bank adviser" — takes over. This is the costliest scenario, with losses running into tens of thousands of euros.
  3. The emotional lever. The so-called "fake child" scam ("Mum, I broke my phone, here's my new number") explicitly targets parents and grandparents. It asks for nothing technical: just a transfer, to someone you believe you love.

A useful rule to pass on: an emergency that forbids you from hanging up and calling back yourself is, by definition, a scam. No legitimate institution has ever required anyone to stay on the line.

The five scenarios to know by heart

Rather than learning an endless list of variants, it's better to memorise the five families. They cover the overwhelming majority of cases.

ScenarioThe pretextThe unmistakable sign
Fake parcel"Customs fee of €1.80 to be paid"A trivial sum used to capture a bank card
Fake bank"Suspicious payment attempt, please confirm"A request for a code received by text, or to call a number back
Fake public bodyFine, tax office, health insurance, benefits agencyA direct link instead of the official site you know
Fake relative"It's me, I've changed my number"Rapid shift to a messaging app, then a request for money
Fake tech support"Your account will be closed within 24 hours"An artificial countdown

What these five scenarios have in common isn't technical, it's emotional: fear, urgency, curiosity or affection. That's what needs to be spotted, not the fine detail of a URL's spelling.

The single instinct that replaces all the others

If you pass on only one thing to a parent, make it this: you never click inside a message; you open the channel you already know yourself.

Worried by something from the bank? Call the number printed on the back of the card. Contacted by the health insurance service? Log into the usual account as always. A parcel supposedly held up? Go to the carrier's website chosen personally. That instinct alone neutralises almost everything, without requiring the slightest technical skill.

To anchor it, nothing beats a physical medium. A paper password notebook kept next to the landline, with the real numbers written down — bank, health insurer, doctor, phone provider — and two or three rules in large letters, often does more than an hour of explanations. The object is old-fashioned, but it can be consulted in three seconds, mid-panic, with no battery required.

Close-up of a tattooed man's hands typing a message on a black smartphone

Setting up the phone: an hour well spent

Support isn't only a matter of conversation. Half an hour of settings mechanically reduces the volume of dubious messages reaching the screen.

Filter unknown senders

On iPhone, under Settings → Apps → Messages, the "Filter Unknown Senders" option automatically sorts messages from numbers not in the contacts list into a separate tab. They no longer show up as notifications. The main thread then contains only family, friends and registered services.

On Android, Google Messages offers spam protection and detection of potentially dangerous messages, which can be enabled under Settings → Spam protection. Recent versions also flag links deemed suspicious before they're opened.

This filtering has a cost: a legitimate message from a new number (a tradesperson, a laboratory) can end up in the secondary tab. So you need to explain that this tab exists, and where to find it.

Lock down the financial layer

This is the most cost-effective step, and it doesn't involve the phone but the bank. Many institutions allow you, from the app or in branch, to:

  • set a low daily transfer limit (a few hundred euros);
  • impose a 24- to 48-hour delay before a new payee can be used;
  • disable payments abroad or online when they aren't being used.

A low limit doesn't protect against the scam, but it turns a catastrophe into an incident. That is exactly what you should expect from a security measure.

Document the genuine contacts

Save the official contacts in the address book under unambiguous names ("BANK — real number", "HEALTH INSURER — real number"). When an incoming call shows up with no name yet claims to come from the bank, the inconsistency is obvious.

For people who struggle to navigate menus, a big-button mobile phone kept as a second device, with the five essential numbers on speed dial, remains a very effective fallback — particularly for calling a bank back without going through a potentially compromised smartphone.

Improve reading conditions

A far from negligible share of unfortunate clicks simply comes down to not reading what you're clicking. Increasing the text size in the accessibility settings, turning on high contrast, and keeping a pair of reading glasses within reach of the armchair genuinely changes things. This isn't a comfort tip: it's a security measure.

Talking about it without humiliating anyone

This is the trickiest part, and the one most often botched. A few principles drawn from experience.

Never open with "be careful"

"Watch out for scams" conveys no usable information and sets up a guardianship dynamic. Prefer a concrete story: describe a message you received, explain how you checked it, admit that you hesitated. The point is to show that doubting is normal, including for someone younger.

Create an explicit right to make mistakes

Say it out loud, once, clearly: "If you ever click on something, you call me straight away, even at 11 p.m., even if you think it's silly. I won't laugh at you." That sentence is worth every spam filter in the world, because it shortens the reaction time.

Set up a family password

Against the fake-relative scam, the defence is old and effective: agree on a word or a question that only family members know. Not a birthday (it circulates), not a pet's name (it's on Facebook). A detail with no digital footprint. If the supposed grandson in distress can't produce it, the conversation ends there.

Go through the written word, and through a third party

Some people take advice badly from their children and very well from a book or a workshop. France Services centres, municipal social action centres and many public libraries run free digital-support workshops. A practical guide to digital security left on the coffee table, to be leafed through at one's own pace with nobody looking over the shoulder, often has more effect than a demonstration.

Hand holding an iPhone displaying a "Social Networks" folder with messaging apps

The click has happened: the procedure, in order

A clicked link is not yet a loss. What matters is what was entered after the click. Here's what to do, from most to least urgent.

  1. Enter nothing further, and don't call any number given in the message. Close the page.
  2. If bank details were entered: call the bank immediately on the number shown on the back of the card, cancel the card, and ask for pending transactions to be blocked. In France, the interbank card-cancellation service operates 24/7 on 0 892 705 705.
  3. If a code received by text was passed on: this is the most serious case, because such a code usually validates a transaction in progress. Calling the bank is the absolute priority.
  4. Change the passwords of the accounts concerned, starting with the email account, which serves as the recovery key for everything else.
  5. Report the message by forwarding it to 33700, the national reporting service for unwanted text messages operated by French carriers. Reporting is free and allows sending numbers to be blocked.
  6. File a complaint if there has been a financial loss, and report the facts on the Cybermalveillance.gouv.fr platform, which points you towards the right procedures and providers. For phishing, the Phishing Initiative site also allows fraudulent URLs to be reported.

A word on reimbursement: European payment services regulations require the provider to refund an unauthorised transaction, unless the user has been grossly negligent. Where that line falls is contested, and several rulings by the French Cour de cassation have made clear that a customer deceived by a particularly credible impersonation scheme is not necessarily at fault. An initial refusal from the bank is therefore not the last word: the banking ombudsman, and then the courts, can still be approached.

What to keep as evidence

Before deleting anything, take screenshots of the message, the sending number, the time it was received, and any page visited. These items serve both the complaint and the dispute file. On a family computer, a small external hard drive where those screenshots are filed in a dated folder stops them disappearing at the next phone change.

Protecting without monitoring: where to draw the line

The temptation is real: install a monitoring app, get access to the message thread, "just in case." It's a bad idea, for three reasons.

First, the law. Accessing an adult's messages without their consent exposes you to prosecution for breaching the privacy of correspondence, punishable under article 226-15 of the French penal code. Being a caring child creates no exemption, unless a judge has ordered a legal protection measure.

Second, effectiveness. Passive monitoring prevents nothing: it merely observes. And it removes responsibility from the person, who then relies on a safety net whose mesh size they don't know.

Third, the relationship. The day your parent discovers the arrangement, the trust needed for rapid reporting — the famous "call me even at 11 p.m." — evaporates.

The right stance fits into one formula: you equip the person, you don't replace them. Settings configured together, banking limits decided together, numbers verified together, and a permanently open door in case of doubt. Control, meanwhile, stays with them.

Key takeaways

  • Scam texts don't target naivety but emotion: fear, urgency, affection. They work on everyone.
  • One instinct is enough in 90% of cases: never click inside the message, always reopen the known official channel yourself.
  • Filtering unknown senders (iOS and Google Messages) and setting low banking limits do most of the preventive work.
  • A family password neutralises the fake-relative scam.
  • If a click happens: bank first, passwords next, report to 33700 and on Cybermalveillance.gouv.fr, and file a complaint if there's been a loss.
  • Protecting is not monitoring: reading an adult's messages without their consent is illegal, and counterproductive.

The best measure of success isn't the absence of incidents — that doesn't depend on you. It's the delay between the click and the phone call. If it drops below ten minutes, you've won.

#SMS#Sécurité#smishing#fraude#Vie privée#Conseil Sécurité#Mobile#2026

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS