When the scam appears in your bank's real message thread: sender spoofing in 2026

Back to the blog
1 September 202611 min read

There is a category of scam text message against which all the usual advice falls flat.

"Check the sender's number." It checks out. "See whether the message is coming from an unknown number." It isn't. "Compare it with previous messages from your bank." It is right below the previous messages from your bank, in the same thread, with the same header, the same sender name, the same layout.

This phenomenon has a name: sender impersonation, or spoofing. It isn't technically new — the weakness is as old as commercial SMS itself — but its industrialisation by fraud networks, combined with the AI-driven automation of manipulation scripts, has made it the number one vector for phone-based banking fraud in France.

And unlike the fake parcel notice or the fake medical reminder, this type of message cannot be spotted with the naked eye. You need a different method.

Hand with red nails typing a message on the touchscreen keyboard of a smartphone resting on a white sheet

Why a fraudster can write "CreditMutuel" in the sender field

When a company sends you a text message, it generally doesn't use a phone number but an alphanumeric identifier: "Ameli", "Colissimo", "SFR", "BNPPARIBAS". Technically, this field is called the Sender ID and it has been part of the GSM standard since the 1990s.

The problem can be summed up in one sentence: this field is self-declared.

In the original SMS protocol there is no authentication mechanism comparable to what we know from email (SPF, DKIM, DMARC). The sender fills in a string of up to eleven characters, and the network carries it as-is all the way to your screen. Nothing in the standard verifies that the organisation writing "CAISSEEPARGNE" really is Caisse d'Épargne.

With a reputable French carrier and what is known as a "premium" route, controls do exist: the A2P (Application-to-Person) aggregator requires a mandate, verifies the identity of the party placing the order, and registers the Sender ID. But SMS is a globally interconnected network. A message can be injected from a foreign operator, via a cheaply bought "grey" route, and arrive in France with a spoofed identifier. That is exactly what fraud platforms do — often hosted outside Europe and sold on a subscription basis.

The detail that makes spoofing devastating: thread grouping

Where things get serious is on the smartphone side.

Both iOS and Android group conversations by sender identifier, not by technical route or certificate. If your bank writes to you from "MABANQUE" and a fraudster injects a message with exactly the same string, both land in the same conversation.

The fraudulent message then inherits all the accumulated trust:

  • it appears below your genuine verification codes;
  • it shares the visible history of your legitimate exchanges;
  • it benefits from context ("ah yes, this really is my bank's thread");
  • it slips past anti-spam filters based on unknown numbers.

No amount of visual vigilance can compensate for this. It is structural.

The typical 2026 scenario: the text message is only the opener

It would be a mistake to think the message's goal is to make you click a link. More and more often, there is no link at all — which defeats automatic filters and security alerts.

The dominant pattern is this:

  1. The alert message. "Payment attempt of €749 at [retailer] detected. If you did not initiate this transaction, call 09 XX XX XX XX." It appears in the bank's legitimate thread.
  2. The call. Either you call the number provided, or — in a more aggressive variant — an "adviser" calls you within minutes, from a number that is itself spoofed (spoofing exists in voice telephony too).
  3. The manipulation. The person on the line knows your name, sometimes your recent purchases, your branch. They are calm, professional, and advise you against rushing. They ask you to "block" the fraudulent transaction.
  4. The capture. They get you to approve an operation in your banking app, read out a code received by text, or enrol a new device on your account. You are the one authorising the transfer.

This is what is known as "fake bank adviser" fraud, which the Banque de France and the Observatoire de la sécurité des moyens de paiement document year after year as one of the costliest per victim. The spoofed text message isn't the scam: it's the key that opens the door.

The rule that protects against 90% of these scenarios fits in one sentence: no bank will ever ask you to approve, cancel or "block" a transaction by reading out a code or confirming a notification during a phone call. An approval only ever serves to authorise, never to cancel.

What France has put in place (and its limits)

Contrary to a common assumption, the issue is not being ignored by the regulator.

The law of 30 May 2023 on combating fraud and abuse in telephone canvassing established the principle of a number authentication mechanism. Arcep then published the technical framework known as MAN (Mécanisme d'Authentification des Numéros), which has been rolled out in stages since October 2024, first for landline numbers and then for mobile numbers.

The principle: a French operator must verify that a call or message presented with a French number genuinely comes from a legitimate user of that number. Failing that, the traffic must be cut off. The results are tangible for fraudulent calls displaying fake French geographic numbers.

But we have to be honest about what this system does not solve:

ScenarioCovered by MAN?
Call displaying a fake French 01/09 numberYes, largely filtered
Call displaying a fake French mobile numberYes, since the scheme was extended
Text message with a fake French numberPartially
Text message with a spoofed alphanumeric Sender IDNo, outside the direct scope
Text message injected from abroad with a brand identifierDepends on the receiving operator's filters

In parallel, the Fédération française des télécoms and the operators have developed lists of protected alphanumeric identifiers: a brand registers its Sender ID, and operators block foreign messages attempting to spoof it. This system works — but it relies on companies volunteering, and it does not cover the thousands of unregistered brands, nor typographic variants ("MA-BANQUE", "MABANQUE1").

In other words: the situation is improving, but it is not fixed.

The verification method that works, in three steps

Since visual inspection is useless, you have to switch to a logic of out-of-band verification. The principle is simple: never validate a piece of information within the channel that delivered it.

1. Suspend the action, not the thinking

All these scenarios rely on artificial urgency. The amount is large, the deadline is short, the caller creates tension. The countermeasure is mechanical: nothing to do with banking is decided in five minutes. No fraudulent transaction detected by a bank requires your immediate intervention by phone; stop-payment procedures exist and work after the fact.

2. Hang up and call back yourself

The number to dial is never the one provided in the message or displayed on your screen. It is the one printed on the back of your bank card or in your official app. One important point that is often overlooked: on older landlines, a fraudster could keep the line open to simulate a callback. On mobile this risk is virtually nil, but still wait a few seconds before dialling.

For people managing several accounts or several cards, keeping stop-payment numbers recorded outside the phone remains the most robust solution: a simple paper phone address book kept near the desk, or a laminated card in your wallet, is better than a note lost in a smartphone that can be stolen or compromised.

3. Check in the app, never from a link

Open your banking app from its icon, not from the text message. If a suspicious transaction exists, it will be there. If nothing shows up, the message is fake. This check takes twenty seconds and neutralises the overwhelming majority of attempts.

Person holding a smartphone with a lit screen in the dark, hands lit by a purple light

Reducing the attack surface upstream

Spoofing works all the better when the fraudster knows a lot about you. The message "your card ending in 4412" is nothing magical: this data circulates after customer database leaks. A few measures limit your exposure.

Compartmentalise your main number. Using a second line — a prepaid card or a secondary eSIM — for commercial sign-ups, deliveries and classified ads sharply reduces the volume of fraudulent messages targeting your banking line. Dual-SIM phones have become commonplace and make the process painless.

Move authentication away from SMS. The one-time code sent by text remains the weak link: it can be intercepted, extracted through manipulation, and is vulnerable to SIM swapping. Wherever a service allows it, a two-factor authentication app — or even a FIDO2 physical security key for the most sensitive accounts (primary email, password manager) — completely changes the level of protection. A hardware key cannot be read out over the phone to a fake adviser.

Avoid reused passwords. The fake adviser scenario becomes far more credible when the scammer already has access to a retail account. A password manager, including in its free versions, breaks that chain. For those who prefer paper, a lockable password notebook kept at home is still far better than a sticky note under the keyboard.

Always report. 33700 is the French national reporting service for unwanted text messages and calls, operated by French carriers. Forward the message to 33700, then reply with the sender's number if asked. It's free, and it feeds the blocklists. In addition, the Cybermalveillance.gouv.fr platform points you towards the right procedures, and Perceval, on service-public.fr, lets you report the fraudulent use of a bank card.

Does RCS change things?

This is the genuinely good news of the moment. RCS (Rich Communication Services), the successor to SMS deployed by carriers and now supported by both iOS and Android, includes something SMS lacks: the verified sender.

Under RCS Business Messaging, a company must have its identity validated by an approved aggregator. The message then arrives with a logo, a verified name and a verification badge displayed by the messaging app. Google Messages has also strengthened its automatic scam detection in 2025 and 2026, with suspicious messages classified locally on the device.

Two caveats, however:

  • Coexistence creates a grey area. As long as classic SMS remains available as a fallback, a fraudster can deliberately target that unauthenticated channel. An unverified message isn't necessarily fraudulent — many small businesses haven't made the switch — but a verified message is a solid guarantee.
  • The badge protects identity, not content. A legitimate brand can send an aggressive campaign; conversely, the absence of a badge on a message that looks like it's from a bank should now be treated as a warning sign in its own right.

The habit to build is therefore simple: on any message with financial stakes, look for the badge. If it isn't there, apply the out-of-band verification procedure without exception.

Key takeaways

  • The sender field of a text message is self-declared: it can be spoofed, and the fraudulent message then files itself into your bank's legitimate thread.
  • Visual inspection is useless in this specific case. Only out-of-band verification protects you.
  • France's number authentication scheme (Arcep's MAN framework) has sharply reduced calls spoofing French numbers, but does not cover alphanumeric identifiers.
  • No bank ever asks you to approve, read out or confirm anything during a phone call.
  • RCS with verified senders is the first structural answer to the problem; full adoption will still take time.

SMS was designed in 1992 as a technical service channel between engineers. Thirty-four years later it has become the front door to our bank accounts — without ever having been given the corresponding authentication mechanisms. Until that gap is closed, the best protection remains a very human reflex: step outside the channel to check.

#SMS#Sécurité#smishing#fraude#Vie privée#Opérateurs#RCS#2026#Conseil Sécurité

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS