After an SMS Scam: How to Report It, File a Complaint and Get Refunded in France

Back to the blog
23 August 202612 min read

There is a very precise tipping point in an SMS scam. It isn't the moment the message arrives, nor even the moment you click. It's the one that comes a few seconds — or a few hours — later, when you understand. The site looked right, the page "glitched", and then doubt creeps in. You reread the message. The sender's number no longer looks anything like your bank's.

What follows is almost always experienced badly and handled badly. Not for lack of intelligence, but because nobody has ever explained in what order to act. Should you call the bank before or after filing a complaint? Is 33700 of any use? Does a complaint stand any chance of going anywhere? And above all: is the bank obliged to refund you?

Here is the complete journey, as it actually exists in France in 2026, with the legal deadlines, the applicable texts and the phrases that make all the difference when you're facing an adviser.

Person in a white hoodie sitting and checking messages on a smartphone held in both hands

The first three hours: the order of priorities

The rule is simple: start with what's bleeding. Declaratory formalities come afterwards, never before.

1. Block your payment methods

If you entered a card number, a one-time code, or your online banking credentials, the absolute priority is to have the card blocked. Three channels, in this order of effectiveness:

  • Your banking app, which nowadays almost always offers an instant card-freeze button;
  • Your bank's card-blocking hotline, printed on the back of the card and in your online account;
  • The interbank card-blocking service, on 0 892 705 705, available 24/7 if you can't reach your own institution.

One point that's often overlooked: blocking the card isn't always enough. If the fraudsters have obtained your online banking credentials, they may attempt a transfer. Explicitly request that access to your online account be blocked and that your credentials be reset.

2. Take back control of your phone

If you installed an app from the link, or granted a permission, treat the device as compromised. Restart it, uninstall anything that was added, check in the settings which apps have access to your text messages, and change your passwords from a different device — a computer, a tablet. This is also the right moment to consider a physical FIDO2 security key for your most sensitive accounts: it renders SMS code interception useless, since there is no longer any code to intercept.

3. Document before you delete

A counter-intuitive but decisive reflex: do not delete the fraudulent message. Take screenshots of the text, the sender's number, the URL you visited, the time, and the disputed transactions. These elements make up your case file. Without them, your complaint is a sworn statement; with them, it's a file.

33700: what it's really for (and what it isn't)

33700 is the national reporting service for unwanted texts and calls, operated by French mobile operators under the auspices of the Association Française du Multimédia Mobile. It works in the simplest of ways: you forward the suspicious text to 33700, then send the sender's number in a second message.

What it does: it feeds a shared database that allows operators to shut down the numbers and spam kits used on a mass scale. A number reported hundreds of times is neutralised quickly.

What it doesn't do: it doesn't handle your individual case, doesn't trigger any investigation into your loss, and doesn't refund you anything. 33700 is a collective gesture, not an individual remedy. It's worth doing — thirty seconds — but it replaces none of the steps that follow.

Also worth noting: reporting to 33700 works for conventional text messages. For messages coming through apps or via RCS, reporting is done within the app itself, which has its own escalation mechanisms.

Reporting to the official platforms: Cybermalveillance and Pharos

Two public schemes complete the picture, and they serve different purposes.

Cybermalveillance.gouv.fr is the national assistance scheme for victims of cybercrime, run by a public interest grouping involving the State. Its online diagnostic pathway directs you according to your situation (phishing, identity theft, account hacking) and puts you in touch with local providers if technical intervention is needed. It's the right entry point if you don't know where to start.

Pharos, the platform for the harmonisation, analysis, cross-checking and routing of reports, is run by the Office anti-cybercriminalité. Reports are made at internet-signalement.gouv.fr. Pharos receives reports of illegal online content and behaviour — phishing sites included. Here again: reporting ≠ filing a complaint.

Finally, Perceval is the online service for reporting bank card fraud, accessible via FranceConnect on service-public.fr. It specifically covers fraudulent debits on a card that has remained in your possession. The Perceval acknowledgement receipt is a useful document to include in the file you submit to your bank.

Young woman with curly hair reading a message on her smartphone, sitting by a window

Filing a complaint: where, how, and with what chances

Contrary to a persistent belief, a complaint can never be refused. Article 15-3 of the French Code of Criminal Procedure requires judicial police officers and agents to accept complaints, including outside their territorial jurisdiction, and to issue a receipt for them. If an officer tells you "there's no point", the answer is: "I nevertheless wish to file a complaint, please issue me a receipt."

Three possible routes:

RouteIndicative timeframeBenefit
Police station or gendarmerie brigadeImmediate to a few daysReceipt issued on the spot, file compiled with the officer
Online complaint (digital complaint service)A few daysConvenient, but sometimes downgraded to a logged report if the file is thin
Letter to the public prosecutor1 to 3 weeksUseful for significant losses, allows you to set everything out in writing

For the letter to the prosecutor, write to the judicial court of the place where the offence occurred or of your home address, by registered post with acknowledgement of receipt. The letter should contain your full contact details, a dated chronological account, the proposed legal classification (fraud, article 313-1 of the French Criminal Code; fraudulent collection of personal data, article 226-18) and the supporting documents. A simple archive binder for administrative documents saves you from digging out a jumbled pile three months later, when the insurer or the bank asks for an extra document.

As for the chances of success: let's be honest. Smishing campaigns are mostly run from abroad, using rented infrastructure and disposable numbers. Identifying the perpetrators is rare. But the complaint isn't only about prosecution: it is the cornerstone of your case with the bank and the insurer. Without it, the bank has an easy time claiming doubt as to whether the fraud really happened.

The real stake: getting your money back

This is where the essential battle is fought, and this is where most victims stop too soon, discouraged by an initial refusal.

What the law says

The French Monetary and Financial Code sets out a clear principle. Article L. 133-18 provides that, where an unauthorised payment transaction is reported by the user, the payment service provider must refund it immediately, and at the latest by the end of the first business day following the report, unless it has grounds to suspect fraud by the user and has communicated this to the Banque de France.

Article L. 133-19 caps the share borne by the payer and, crucially: where the transaction was carried out without strong authentication when such authentication was required, the payer bears no loss at all.

Article L. 133-23 places the burden of proof on the bank: it is for the bank to prove that the transaction was authenticated, recorded, and not affected by a technical failure. And the text explicitly states that the use of the payment instrument as recorded by the provider is not necessarily sufficient to prove gross negligence.

The concept of gross negligence, and the turning point in case law

The bank escapes its refund obligation only if it demonstrates gross negligence on your part (article L. 133-19, IV). For a long time, institutions took the view that passing on a code received by text message was by its very nature gross negligence.

The Cour de cassation has considerably narrowed that interpretation. In a much-noticed ruling by its commercial chamber (judgment of 12 November 2020, appeal no. 19-12.112), it held that it is for the bank to prove gross negligence, and that such negligence cannot be inferred from the mere fact that the customer disclosed their details. Subsequent case law has confirmed this line in cases of spoofing — that is, where the bank's sender number or name is impersonated: when the fraudulent message slots into the institution's genuine message thread, the victim cannot reasonably be held grossly negligent.

This is the central argument to put forward in writing:

The message in question appeared in the usual conversation thread from your institution, under the same sender name, making any distinction impossible for a normally vigilant user. Pursuant to articles L. 133-18 and L. 133-23 of the French Monetary and Financial Code, it falls to you to establish gross negligence on my part, which cannot result from the mere disclosure of the data.

The procedure, step by step

  1. Written dispute submitted to your branch, by registered post with acknowledgement of receipt, as promptly as possible. The maximum legal deadline for disputing an unauthorised transaction is thirteen months from the debit date (article L. 133-24), but don't wait: how quickly you react weighs in the assessment.
  2. Referral to the bank's complaints department if the refusal stands, with the same documents plus a copy of the refusal.
  3. Banking ombudsman: free of charge, contactable online, with ninety days to issue an opinion. Their contact details must appear on your statements and on the bank's website. A significant share of fraud disputes is settled at this stage.
  4. Judicial court as a last resort. For modest amounts, the simplified procedure before the protection litigation judge is available without a lawyer. While you're at it, check your legal expenses insurance cover: many home insurance policies and premium cards include one, and it covers the costs.

To draft your letters without spending the whole evening on them, an up-to-date practical guide to consumer law provides formal notice templates you can transpose directly.

Man sitting cross-legged on a bed in a purple shirt, looking at his blue smartphone with a laptop on his knees

The harms people forget to deal with

A bank refund doesn't close everything. Three blind spots deserve separate action.

Identity theft. If you handed over a copy of an ID document, a proof of address or your bank details (RIB), there is a risk of fraudulent credit applications in your name. You can request registration on the Fichier national des incidents de remboursement des crédits aux particuliers as a victim of identity theft, via the Banque de France, and exercise your right of access to the incident files.

Personal data. If your data was fraudulently collected through a fake site imitating an organisation, a report to the CNIL is appropriate, particularly where the real organisation suffered a data breach that led to the targeting. The CNIL won't compensate you, but its action may trigger an audit.

Long-term account security. After the incident, replace SMS codes with a two-factor authentication app wherever possible, and centralise your passwords in a dedicated manager. An encrypted password notebook in paper form, kept at home, remains an acceptable fallback for people who won't use apps — provided it never leaves the house.

The timeline to remember

TimingAction
H+0Block the card and online account access
H+0Screenshots of the text, the URL and the transactions
H+1Change passwords from another device
D+0 to D+1Written dispute to the bank (registered post with acknowledgement)
D+0 to D+2Complaint at the police station or online, receipt kept
D+0 to D+2Perceval report, forward the text to 33700
D+30Follow-up and referral to the complaints department if no reply
D+60Banking ombudsman
D+395 maxLegal deadline for disputing (13 months)

Key takeaways

Smishing thrives on a simple mechanism: the victim feels ashamed, so they delay, so the deadlines close in. Yet French law is, in this area, rather favourable to the consumer. The burden of proof lies with the bank, gross negligence must be demonstrated rather than assumed, and case law has explicitly acknowledged that a message impersonating a financial institution is technically undetectable by an ordinary user.

The only genuinely damaging behaviour is waiting. A report made within the hour, a file of screenshots, a well-argued registered letter: that's what separates a refunded case from a shelved one.

And going forward: the best reflex remains never to use a link received by message, however perfectly credible it looks. Close the text, open the official app, check. Three extra seconds, and the story never happens.

Main sources: French Monetary and Financial Code (articles L. 133-18, L. 133-19, L. 133-23, L. 133-24), French Code of Criminal Procedure (article 15-3), French Criminal Code (articles 313-1 and 226-18), Cour de cassation, commercial chamber (judgment of 12 November 2020, no. 19-12.112), Cybermalveillance.gouv.fr, service-public.fr (Perceval), Banque de France, CNIL.

#smishing#fraude#Sécurité#SMS#Guide#Vie privée#piratage#2026

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS