There is an experience almost everyone has had, and almost no one talks about: receiving a message that was clearly not meant for you.
Sometimes it's harmless — "Meet at 7 outside the cinema?" from a stranger. Sometimes it's far less harmless: a login code for a bank account, a medical test result, a summons, a break-up message, a photo of a child. You didn't ask for anything, hack anything or intercept anything. The message reached you because someone got one digit wrong, or because your number belonged to somebody else before you.
And then a series of questions comes up that nobody has ever answered for you. Am I allowed to read it? Should I reply? Am I taking any risk? How do I make it stop?

Why your number receives someone else's messages
There are four main causes, and they don't call for the same responses.
The recycled number. By far the most frequent and the most persistent case. In France, a cancelled mobile number isn't destroyed: it goes back into the operator's pool, and the operator must observe a "quarantine" period before reassigning it. ARCEP governs this mechanism through its national numbering plan, but the waiting period is only a few months. Once that window passes, your brand-new number already has a past life: a gym membership, a customer account with an energy supplier, a sign-up on a delivery platform, a file at a medical testing lab. All those databases keep writing to the previous holder — meaning to you.
The typing error. A pair of digits swapped at a pharmacy counter, a prescription dictated over the phone, a form filled in too quickly. The message goes off to a stranger who doesn't even know there's a problem.
The customer database that was never cleaned up. A company has a number it obtained eight years ago and has never checked whether it's still valid. Yet the GDPR imposes a data accuracy requirement (Article 5.1.d): inaccurate data must be "erased or rectified without delay". In practice, this obligation is massively ignored in marketing databases.
The fraudulent text disguised as a mistake. This is the fourth case, and the most devious. A message along the lines of "Hi, it's Marie, are we still on for tomorrow?" is not a mistake: it's the opening move of a relationship scam, often steered towards a cryptocurrency investment fraud. The scenario, known as pig butchering in cybersecurity literature, always begins with a fake message sent "by mistake" to start a conversation.
Telling these four cases apart is the first thing to do, because the right course of action is radically different in the last one.
What French law says: reading isn't an offence, exploiting is
Many people believe that opening a message not intended for them is already an offence. That's false, and the distinction deserves to be set out clearly.
The privacy of correspondence is protected by Article 226-15 of the French Penal Code, which punishes with one year's imprisonment and a €45,000 fine "the act, committed in bad faith, of opening, deleting, delaying or diverting correspondence that has or has not arrived at its destination and is addressed to third parties". Two elements matter here:
- bad faith: intent is required. Passively receiving a text on your own phone and reading it in the notification is in no way intentional;
- diversion: the provision targets someone who goes looking for another person's correspondence, not someone to whom it is delivered by mistake.
Plainly put: you have committed no offence by reading a message that arrived at your phone unbidden. The red line lies elsewhere.
What's unlawful isn't having seen the message. It's using it, passing it on, or relying on it to access something that isn't yours.
Three behaviours tip the situation over:
- Using a code received by mistake. If a banking validation code or a login code reaches you and you use it, you immediately leave the territory of an honest mistake and enter that of fraudulent access to an automated data processing system (Article 323-1 of the Penal Code) and, depending on the use, of fraud.
- Sharing the content. Posting a screenshot of an intimate message received by mistake, with the number or name legible, may amount to invasion of privacy (Article 226-1) and, where the content is sexual in nature, to non-consensual distribution (Article 226-2-1).
- Keeping and exploiting health data. A lab result that lands on your phone remains covered by medical confidentiality. You aren't personally bound by it, but any exploitation would expose you.
In other words, the law protects the unintended recipient fairly well — provided they behave like an unintended recipient.
Should you reply? The rule of three answers
This is the most frequent question, and the right answer depends on the type of message.
Case 1: an obviously human, personal message
A friend writing to a friend, a parent writing to their child, a meeting being arranged. Here, replying is not only allowed but useful: "Hello, this isn't the number of the person you're looking for, you've reached the wrong recipient." One sentence, neutral, with no comment on the content.
This kind of reply avoids the worst-case scenario: a family emergency where nobody understands why the other person isn't answering.
One precaution, though: reply by text, don't call back, especially if the number displayed is foreign or starts with a premium-rate prefix.
Case 2: an automated message from a company or an organisation
A medical appointment, an invoice reminder, a delivery notification, a security code. Don't reply to the message itself: most of these are sent from short, non-routable numbers, and your reply will fall into a void.
The effective approach is to contact the organisation directly through its official channel — not via a link contained in the text — and ask for the number to be deleted or corrected. You can explicitly invoke the right to rectification set out in Article 16 of the GDPR. Wording that works:
"Your organisation is sending text messages containing another person's personal data to my number, of which I have been the holder since [date]. On the basis of Article 16 of the GDPR, I ask you to rectify or delete this number in the file concerned, and to confirm the update to me."
If the company doesn't respond within a month, the CNIL accepts online complaints on exactly this ground. This isn't some marginal use of the system: poorly maintained contact databases are a perfectly admissible basis for a complaint.

Case 3: a message that smells like a script
"Hello, is this Doctor Chen?" "Excuse me, is this Sophie's number?" "Sorry, wrong number… what region are you in?"
Don't reply at all. Absolutely nothing, not even "wrong number". Any response confirms that the line is active and read by a human, which raises the value of your number in the databases that get resold.
Report the message to 33700, the official French platform for reporting unwanted and fraudulent text messages, run by the operators under the supervision of public authorities. Forward the message to 33700, then send the sender's number when the platform asks for it. You can also file a report on cybermalveillance.gouv.fr, which centralises support for victims.
The special case of verification codes that have nothing to do with you
Receiving a one-time code meant for someone else is commonplace when you inherit a recycled number — and it's the trickiest scenario.
First, some good news: it usually means a previous holder never updated their online accounts, not that someone is trying to hack you.
But two situations should put you on alert:
| What you receive | What it probably means | Response |
|---|---|---|
| An isolated code, once a month | An old account that was never updated | Contact the service, ask for deletion |
| A burst of codes within a few minutes | An access attempt under way on an account linked to this number | Do nothing with the code, report it to the service concerned |
| A code followed by a call from "the security department" | A scam attempt targeting you | Hang up, never share the code |
The third case is worth knowing about: fraudsters deliberately trigger the sending of a code, then call the victim posing as the bank's or platform's security team and ask for the code "to verify". No French institution will ever ask you to read out a code over the phone. That's rule number one, and it's repeated by the Fédération bancaire française as well as by insurers.
If you inherit a number and regularly receive codes, it's also worth auditing your own accounts: switching your two-factor authentication from SMS to a dedicated app, or even to a physical FIDO2 security key, removes the problem at its root. A guide to everyday cybersecurity is a reasonable investment if the subject feels opaque to you: SMS remains the most fragile authentication factor in today's ecosystem, and ANSSI no longer recommends it as a second factor for sensitive uses.
Taking back control when your number is a recycled one
If messages arrive in a steady stream and come from multiple sources, this isn't a one-off mistake: your number is floating around in dozens of databases. The method that works unfolds in four stages.
1. Take inventory for two weeks. Note down every sender, the nature of the message and the frequency. A simple spiral notebook will do, but what matters is the record: it will help you prioritise and, if needed, document a complaint to the CNIL.
2. Deal with identifiable senders one by one. For each recognisable organisation, send the GDPR rectification request. It's tedious, but it's the only step that permanently stops the flow. Allow three to four weeks per case.
3. Turn on your phone's filters. Both iOS and Android let you filter unknown senders into a separate tab, and block a number in two taps. On Android, the spam filtering in Google Messages intercepts a good share of automated sendings. On iPhone, the "Filter Unknown Senders" option in the Messages settings does the same job. These filters don't delete anything, but they make the noise bearable.
4. Register the number with Bloctel. The public opt-out scheme for telephone marketing doesn't cover marketing texts in the same way as calls, but it cleans up the overall picture. Since the legislative changes on prior consent came into force, marketing without explicit agreement has been penalised ever more firmly by the DGCCRF.

And what if you're the one texting the wrong number?
The problem has a mirror image that gets talked about even less.
If you realise you've sent a sensitive message to the wrong recipient, be aware that a delivered text cannot be recalled: the network has no "unsend" function. RCS, on Android, allows a message to be deleted for everyone in certain configurations, but only if both parties are using RCS — which is rarely the case with a stranger.
What remains possible:
- immediately sending a second message politely asking for it to be deleted;
- if the message contained a code or an identifier, invalidating that code without delay by triggering a fresh authentication;
- if the message contained work-related data, alerting your organisation's data protection officer: an accidental disclosure of personal data to a third party constitutes a data breach within the meaning of Article 33 of the GDPR, potentially notifiable to the CNIL within 72 hours.
The best defence remains preventive: check the last three digits before sending a message containing sensitive information, and never send an identifier, an access code or a full card number by text. For passwords and logins shared within a family or between colleagues, a password manager or simply a secure password notebook kept at home completely removes the need to circulate them by message.
Key takeaways
- Receiving and reading a message that wasn't meant for you is not an offence; exploiting it, sharing it or using a code you received is.
- For an isolated human message: a short, neutral reply, with no comment on the content.
- For an automated message: contact the organisation through its official channel and invoke the right to rectification (Article 16 of the GDPR).
- For a message trying to start a conversation: reply nothing, forward it to 33700.
- No verification code should ever be shared over the phone, ever, with anyone.
- If your number is a recycled one, only a methodical clean-up of the sending databases will end the flow; your phone's filters merely mask the noise.
A misdirected text is never more than one extra error in a system that produces millions of them every day. But it is also, sometimes, a fragment of someone else's life landing on your screen. The right attitude fits into one sentence: flag the mistake, exploit nothing, and do what's needed so it doesn't happen again.



