There's a category of text-message scam that gets little attention, because it doesn't look like a scam at all. No fake banking site, no six-digit code to be copied out urgently, no threat of account suspension. Just good news: you've been drawn at random, your loyalty is being rewarded, your parcel is free — all that's left is to pay €1.95 in shipping costs.
Six weeks later, your bank statement shows three charges of €49.90 to a company you've never heard of. And here's the most unpleasant part of the story: somewhere on the page you filled in within thirty seconds, it was written — in light grey, in 7-point type, beneath the confirm button — that you were signing up for a rolling monthly subscription.
This is what's known as negative option billing, or in plainer terms a default sign-up or hidden subscription. It isn't exactly theft. It's far worse to deal with: it's a legal grey area designed to look like a contract.

Why this trap works better than a fake banking site
Classic smishing campaigns — bogus texts from the postal service, from health insurance bodies, from your bank — rely on fear and urgency. They work, but they're meeting growing resistance: the public has been extensively warned, banks keep repeating that they never ask for a code by text, and Cybermalveillance.gouv.fr has been hammering the message home for years.
The prize text bypasses that mental defence entirely. It sets off none of the alarms you've been trained to listen for:
- It asks for no password.
- It asks for no bank validation code — well, it does, but later, and for a trivial amount you approve without thinking.
- It doesn't necessarily impersonate a public body: it often just makes a vague reference to "your operator", "a major retailer", "our partner".
- It doesn't put you in danger, it gives you a treat.
The psychological lever isn't fear but reciprocity and the endowment effect: from the moment you're told that something already belongs to you, giving it up feels like a loss. Add a countdown on screen ("your prize is reserved for 9 min 47"), and any time for reflection disappears.
The crooks running this model aren't trying to steal €800 in one go. They're trying to take €49 a month for six months from thousands of people who, individually, will never file a complaint over that amount.
The mechanism, step by step
1. The hook message
The text is short, often free of spelling mistakes, and increasingly personalised — inevitably, thanks to cross-referencing with leaked databases. The recurring wordings in 2026:
- "Hello [First name], your order no. 8842 qualifies for a gift. Choose it here: …"
- "Your plan entitles you to 1 free accessory this month."
- "A refund of €74.32 is available on your file. Confirm your details."
- "Product test: receive [well-known brand] and keep it."
The link points to a recently registered, short domain unrelated to the brand mentioned, often hosted on an exotic extension or a generic subdomain.
2. The qualification funnel
The page doesn't ask for your card straight away. First it makes you play: a spinning wheel, three chests to open, a four-question quiz. This detour isn't decorative. It serves two purposes:
- Committing you gradually. Someone who has already answered four questions is far less likely to drop out at the fifth step.
- Harvesting your data. Age, circumstances, interests, postcode: this information is sometimes worth more than the subscription itself on the data-resale market.
3. The bank card for "the fees"
Then comes the request for card details, justified by a tiny amount: €1, €1.95, €2.90 towards postage. You approve it through your banking app — strong authentication works perfectly, validating a payment you genuinely authorised.
That's the heart of the problem: PSD2 and two-factor authentication don't protect you from a contract you signed without reading. They verify that it's really you, not that the transaction is honest.
4. The invisible clause
Beneath the button, in a block of grey text on a white background, a sentence along the lines of: "By confirming, you subscribe to the Premium service at €49.90 per month after a 3-day trial period, cancellable at any time." The first charge lands a week later, with an opaque bank descriptor: a three-letter acronym, a company based outside France, no connection whatsoever to the original text.
What French law says — and why it's on your side
Contrary to what many victims believe, this practice isn't legal simply because the clause was there. French and European law regulates this type of distance selling very strictly.
| Rule | Applicable text | What it means for you |
|---|---|---|
| Express consent to any additional payment | Article L. 224-2 of the Consumer Code | A pre-ticked box or a buried mention does not constitute consent |
| Misleading commercial practice | Articles L. 121-2 et seq. | Concealing material information (the real price) is a criminal offence |
| 14-day right of withdrawal | Article L. 221-18 | It runs from the conclusion of the contract for a service |
| Clear and comprehensible pre-contractual information | Article L. 221-5 | Light grey 7-point type under the button is neither clear nor legible |
| Disputing an unauthorised payment | Article L. 133-18 of the Monetary and Financial Code | Refund by the bank, subject to conditions |
The Direction générale de la concurrence, de la consommation et de la répression des fraudes (DGCCRF) regularly issues warnings about these "prize draws" that end in subscriptions. Reports go through the SignalConso platform. For the cybercrime dimension, Cybermalveillance.gouv.fr points you to the appropriate channels, and the Pharos platform receives reports of illegal content.
As for the text message itself: any fraudulent message can be forwarded free of charge to 33700, the national SMS spam reporting scheme run by the Association Française du Multimédia Mobile in conjunction with the mobile operators.
What to do if you're already being charged
The order matters. Many victims start by writing to the company's customer service — the worst possible first step, because it wastes days during which fresh charges keep coming.
Step 1 — Stop the flow, not just dispute it
Call your bank and explicitly ask for:
- a block on the merchant (stopping future charges from that payee);
- and, if there's serious doubt, a card replacement. The new number invalidates recurring authorisations.
Be careful: a simple "stop for loss" doesn't always suffice to halt recurring payments already authorised. Use the exact words: "I am disputing a recurring payment authorisation and requesting that it be blocked."
Step 2 — Claim your refund in writing
Send your bank a written dispute (registered letter or secure messaging in your online banking area), citing the absence of express consent. Attach:
- a screenshot of the text you received;
- the website address, if you still have it in your history;
- the statement showing the charges;
- a precise timeline.
The legal deadline for disputing an unauthorised transaction is 13 months from the debit date (Article L. 133-24 of the Monetary and Financial Code). Don't let that window slip by thinking "it's too late anyway".
Step 3 — Cancel formally, even if the contract is shaky
Send a registered letter of cancellation and withdrawal to the address given in the site's legal notices. That's the document you'll rely on later. Many people keep no paper trail of their steps; storing the acknowledgements of receipt in a clear-pocket document folder saves you from having to rebuild the whole file in a hurry six months down the line.
Step 4 — Report it
- SignalConso (DGCCRF) for the commercial practice.
- 33700 for the text message.
- A complaint at a gendarmerie or police station if the amount is significant, or an online pre-complaint.
- Your consumer association (UFC-Que Choisir, CLCV) if you hit a wall with the bank.

Seven habits that neutralise this kind of trap
1. No lottery knows who you are. You can't win a game you never entered. That rule alone rules out 90% of cases.
2. Be wary of micro-payments. A deliberately trivial amount is a warning sign, not a guarantee. Its only purpose is to obtain your card details and your approval.
3. Read what's below the button, not above it. The decisive terms are always placed after the call to action, in a low-contrast colour.
4. Compartmentalise your payment methods. Keep a single-use virtual card or a rechargeable prepaid card for purchases on sites you don't know. The spending cap mechanically limits the damage. Most French banks offer this service in their app.
5. Check your statements every month. A €49 charge goes unnoticed by anyone who only looks at their balance. A simple personal accounts notebook, or a spreadsheet, is enough to spot an unfamiliar descriptor.
6. Don't reuse your main number everywhere. Every prize-draw form, every raffle in a shopping centre feeds the databases that get resold. For non-essential sign-ups, a second number on a no-contract prepaid SIM does the job nicely.
7. Never reply "STOP" to a fraudulent message. The legal STOP mechanism only works for declared marketing from identified companies. With a scammer, it simply confirms that the number is live.
The particular case of vulnerable people
This type of scam strikes very unevenly. People who are isolated, uncomfortable with interfaces, or using their smartphone without the right glasses will simply never see the 7-point disclaimer. That's not a lapse in attention: it's deliberately hostile design.
A few concrete measures, without being patronising:
- Turn on larger text and high contrast in the phone's accessibility settings.
- For extended screen reading, high-magnification reading glasses make legible the legal notices that interfaces deliberately bury.
- Agree on a simple, non-negotiable family rule: no bank card details are ever entered from a link received by text, ever, for any reason.
- Set a low payment limit on the card, to be adjusted as needed.
For those who want a broader understanding of how these manipulations work, several accessible books on cybersecurity written for a general audience explain social engineering mechanisms very clearly, with no technical background required.
And if all you did was click?
Clicking the link without filling anything in is, in the vast majority of cases, harmless on an up-to-date smartphone. The real risk starts when you enter information. That said, a few sensible precautions:
- Check that your operating system is up to date — it's the most effective protection, and the most neglected.
- On Android, make sure no app has been installed from outside the official store.
- If you entered your email address, expect an increase in spam; consider a password manager to compartmentalise your logins if you reuse the same password everywhere.
- Keep an eye on your accounts for three months.
Key takeaways
The prize text is the smiling face of smishing. It doesn't attack your bank, it attacks your reading. It doesn't bank on panic, it banks on thirty seconds of excitement and on typography designed to be overlooked.
The countermeasure is neither technical nor complicated: no payment, not even of one euro, should ever be entered from a link received by text. If the offer is real, it will still be there when you type the official website address into your browser yourself. And if it only exists in the text message, it never existed at all.
If in doubt, forward the message to 33700, report it on SignalConso, and delete it. A gift that demands your bank card isn't a gift: it's an invoice in disguise.



