Selling on Leboncoin or Vinted: anatomy of the scam texts targeting sellers in 2026

Back to the blog
27 August 202611 min read

There's a very specific moment when your guard drops: the one right after the ad goes live. The sofa has been photographed, the description written, the price set. And twenty minutes later, the phone buzzes. "Hello, I'm interested in your item, is it still available?" The message is polite, well written, error-free. It arrives by text, straight to your personal number.

From that point on, a well-oiled machine kicks in. It doesn't target buyers — that's the most widespread misreading — but sellers. The people waiting for a reply, hoping to close quickly, who have already mentally spent the €250 from the bike they're getting rid of.

Posting a classified ad, in 2026, means publishing a phone number in a space anyone can browse, including organised networks that automate the harvesting. What you think of as a transaction between private individuals becomes a hunting ground. Here's how these scams actually work, why they succeed so well, and which habits to adopt before you even list your first item.

Close-up of a smartphone screen showing messaging app icons with a notification

Why sellers are ideal targets

A private seller ticks three boxes that fraudsters look for.

First, they're expecting a message. Unlike mass smishing — the fake tax office or health insurance text blasted to millions of random numbers — the message a seller receives fits into a context they created themselves. The brain isn't looking for inconsistencies: it's looking for confirmation.

Second, they've made their number reachable. Even when the platform offers internal messaging, a significant share of sellers put their number in the ad text or hand it over during the first exchange, to "speed things up". Those numbers are then scraped automatically, resold and reused for months.

Third, they're in a position of financial expectation. They're due to receive money. That asymmetry is exactly what the scam exploits: nobody asks them to pay, they're told they must complete a formality in order to get paid. Psychologically, that's infinitely more effective.

The Signal Arnaques platform and the official 33700 scheme, run by the Fédération française des télécoms under the aegis of the French Ministry of the Economy, record this type of report in the highest volumes year after year, alongside fake parcel delivery texts.

The four most common scenarios in 2026

1. The fake "secure" payment link

This is the great classic, and it remains the most profitable. The buyer explains they can't travel, offers to pay through the platform's built-in payment system, then sends a text containing a link.

The page that opens is a faithful copy: logo, typography, legal notices, HTTPS padlock. It asks for the bank card number "to receive the transfer". Yet no payment system in the world asks for card details in order to credit an account. Receiving money requires an IBAN, never a three-digit security code.

A more sophisticated variant: the page asks you to log into your online banking to "confirm receipt". The fraudster harvests the credentials in real time and initiates a transfer, while an accomplice calls posing as the bank's anti-fraud adviser to obtain the confirmation code.

2. The fake courier text

The seller has shipped the parcel. A few days later: "Your parcel no. FR8842… is held at the sorting centre, a redelivery fee of €1.95 is due." The amount is deliberately trivial — the aim isn't to steal €1.95, but to obtain card details in order to set up a recurring charge or resell the number.

This scenario is notable for being credible even among well-informed people, precisely because a parcel really is in transit. The only reliable habit: never follow a link received by text, but type the tracking number yourself on the courier's website.

3. The overpayment and refund

The buyer announces they've "paid too much by mistake" and sends a screenshot of an €800 transfer instead of €300. They ask for the difference to be refunded, by instant transfer or prepaid voucher. The screenshot is fabricated, the transfer doesn't exist, or it will be reversed a few days later.

The principle to remember is simple: an incoming transfer is only definitively yours once it appears on your bank statement, not on a notification, not on a screenshot, not in an email.

4. Moving the conversation elsewhere

A short, innocuous opening message, then: "Can we carry on over WhatsApp?" or "Send me your number, I'll call you." Leaving the platform's messaging system wipes out any usable trace in case of a dispute, disables automatic anti-fraud filters and makes it possible to send links that would be blocked elsewhere.

This is no small thing: it's the first step in almost every scam that follows.

General rule: the harder someone pushes to leave the official channel, the higher the probability of fraud. That's true for classified ads, it's true for fake bank advisers, it's true for fake recruiters.

The warning signs table

Signal observedInterpretationRisk level
Buyer who doesn't haggle over the priceAbnormal on a peer-to-peer platformHigh
Request for your phone number in the very first messageAttempt to leave the secure channelHigh
Payment link sent by textNo legitimate platform operates this wayCritical
Slightly off phrasing, machine translationNetwork operating from abroadMedium
Displayed urgency ("I'm leaving tonight")Classic pressure leverHigh
Request for bank card details in order to receive moneyTechnically impossibleCritical
Offer to pay more than the asking priceOverpayment scenarioCritical

What to do before publishing an ad

The best defence isn't played out when the suspicious text arrives, but well before.

Never put your number in the ad text. Not in the description, not in the photos — some sellers unthinkingly photograph a document, a label or an invoice showing their contact details. Checking your images before publishing takes ten seconds.

Clean up the photos. A shot taken with a smartphone contains metadata, sometimes the exact GPS location of your home. Most major platforms strip it on upload, but not all of them, and not on private messaging uploads. For valuable items, photographing against a neutral background with a small foldable photo studio also avoids showing the inside of your home, your furniture or the view from the window — all useful clues for anyone casing the place.

Consider a second number. For anyone who sells regularly, dedicating a line to classified ads is the most robust solution. A no-contract prepaid SIM card, slipped into a spare phone or a second SIM slot, completely isolates your selling activity from your main number — the one that receives banking codes and two-factor authentication. The day that secondary number is drowning in spam, you replace it with no consequences.

Lock down your main account. Since your personal number acts as the backup key for your bank, your email and your social networks, it should be the best protected. Switching two-factor authentication on sensitive accounts to a dedicated app, or even to a physical FIDO2 security key, removes the dependency on SMS — a channel which, let's remember, is unencrypted and remains vulnerable to line hijacking.

What to do once the suspicious text has already arrived

Don't click, don't reply

A simple "STOP" or an irritated reply confirms that the number is active and belongs to a real person. That information has market value: it then circulates to other networks.

Report to 33700

The scheme is free and works in two steps:

  1. Forward the fraudulent text to 33700.
  2. Reply to the automated message giving the sender's number.

The report feeds a database shared by the operators, allowing sending numbers to be suspended and campaigns to be blocked. Via a web form, the official 33700 website also lets you report messages received through messaging apps.

For fraudulent links, the Phishing Initiative platform (operated in France by Orange Cyberdefense) allows the URL to be blacklisted in browsers. And for any question or support, Cybermalveillance.gouv.fr is the French state's official point of entry.

If data has been entered

Time matters, and it's measured in minutes.

  • Call your bank immediately to block the card. The number is on the back of the card; never call back a number received by text.
  • Change the passwords of the affected accounts, starting with your email, which controls the reset of all the others. A password manager stops you reusing the same credentials from one site to the next — that's the weakness exploited in the majority of cascading compromises.
  • File a complaint, at a police station, a gendarmerie or via the online pre-complaint service. The receipt is essential for everything that follows.
  • Request a refund. Article L133-18 of the French Monetary and Financial Code requires the bank to reimburse an unauthorised payment transaction immediately after it is reported, unless the account holder has been grossly negligent. The Cour de cassation has repeatedly held that disclosing data following a well-crafted phishing attempt does not automatically amount to gross negligence: it's up to the bank to prove it.

Document everything, systematically

Screenshots of the text with the sender's number visible, timestamps, the conversation history on the platform, the ad reference. These are what separates a case that gets investigated from one that's dropped. For regular sellers, keeping a transaction log book with dates, amounts and buyers makes reconstructing a history months later far easier.

Handing the item over in person remains the safest method

Despite the spread of integrated payments, the in-person transaction remains statistically the least risky — provided a few principles are respected.

  • Meet in a public, busy place: a station concourse, a shopping centre car park; some town halls now offer secure, CCTV-monitored "meeting points".
  • Never give your home address for a first contact.
  • Check the cash: €50 and €100 notes are the most commonly counterfeited. A portable counterfeit note detector costs about as much as one failed transaction and fits in a pocket.
  • For an instant transfer made on the spot, wait for the bank notification on your own phone, never on the buyer's.
  • Draw up a short written receipt stating the item, the price, the date and both parties' identities. That's nothing excessive for a scooter, a musical instrument or camera gear.

For bulky or valuable items, bringing someone along remains the simplest precaution. And for shipments, using secure packaging with a tamper-proof seal and photographing the sealed parcel with its label heads off the classic "the parcel arrived empty" dispute.

What the platforms do — and don't do

The major marketplaces have considerably tightened their filters: detecting phone numbers in descriptions, masking contact details, automatic warnings when a conversation contains certain keywords. Leboncoin, Vinted and the rest are genuinely investing in the issue, under combined pressure from the DGCCRF and the European Digital Services Act (DSA), which since 2024 has imposed stricter obligations on traceability of professional sellers and the handling of reports.

But two limits persist.

The first is that the scam takes place off-platform. As soon as the exchange moves to SMS or a third-party messaging app, no filter applies. The marketplace operator's responsibility stops at its own infrastructure.

The second is that reports arrive too late. A fraudulent account is created, used for a few days, then abandoned before it can even be suspended. The speed of that turnover leaves moderation structurally one step behind.

Hence a simple conclusion: individual vigilance isn't an optional extra, it's the first line of defence.

Three sentences worth memorising

If you were to keep only the essentials, it would be these.

"Receiving money never requires a bank card number." That single rule neutralises the majority of these scenarios.

"A link received by text is not to be clicked." You open the official app, you type the address yourself, you check the tracking number at the source.

"Urgency is a manipulation tool." A genuinely interested buyer will accept waiting twenty-four hours. A fraudster won't.

Selling online remains a useful, economical and environmentally sound practice that millions of people in France turn to every month. The risk isn't a reason to give it up — it's a reason to cleanly separate what should be separate: your selling number and your life number, your public photos and your private life, the promise of a payment and its reality on your bank statement.

#smishing#fraude#SMS#Sécurité#Vie privée#Conseil Sécurité#2026#Mobile

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS