First the Text, Then the Call: How the Fake Bank Adviser Scam Works in 2026

Back to the blog
9 September 202612 min read

There is a category of scam in which the text message serves no purpose other than to make your phone ring a second time. Sometimes the message doesn't even contain a link. It simply says:

"ALERT: unrecognised payment attempt of €749.00 at ELEC-STORE. If you did not authorise this transaction, do nothing — an adviser will contact you."

No link to click, no form, nothing resembling the phishing campaigns you've been taught to distrust. You read it again, you look for the trap, you can't find it. Three minutes later the phone rings — and the screen shows your branch's number, the one you saved in your own contacts. That is where the scam really begins.

In its regular work through the Observatoire de la sécurité des moyens de paiement, the Banque de France has for several years now highlighted the growth of so-called "manipulation" fraud: cases in which the fraudster needs no technical flaw at all, because it is the victim who authorises the transactions. The text message is no longer the weapon. It is the doorbell.

Man holding a bank card and a smartphone in front of a computer on a wooden desk

Why this scenario has replaced the simple booby-trapped link

For ten years, banking smishing ran on a simple model: a text, a link, a fake login page, harvested credentials. That model is running out of steam for three very concrete reasons.

First, banks have rolled out strong authentication for transactions across the board. Stealing your credentials is no longer enough: someone also has to tap "Confirm" in the app. Second, browsers and mobile operating systems block a growing share of fake domains within hours. And third, the public has internalised the reflex: "I don't click on links in text messages."

So fraudsters have shifted the problem: since the victim has to authorise the transaction anyway, they might as well obtain that authorisation by talking. It's slower, more hands-on, but infinitely more profitable. A booby-trapped link yields credentials that resell for a few euros. A successful call yields a transfer with four or five figures.

The text message keeps a very specific role in the setup:

  • it creates expectation. You're not receiving an unexpected call, you're receiving the announced call. The normal wariness towards an unknown number never kicks in;
  • it plants the vocabulary. "Unrecognised transaction", "anti-fraud department", "securing your funds": the words used later in the conversation are already in place;
  • it triggers adrenaline. Seven hundred and forty-nine euros is enough to raise your pulse, and low enough to stay believable.

Your bank's number showing on screen no longer proves anything

The tipping point, in almost every account, is the incoming-call screen. The number displayed is the genuine customer service number, sometimes even the branch's direct line. Some victims say they checked the number on the back of their bank card during the conversation and found it identical.

This isn't magic, it's caller ID spoofing: falsifying the calling number. The call routing protocol was designed at a time when nobody imagined anyone would lie about their identity, and the "calling number" information remains, essentially, self-declared.

France has tightened the framework with the caller number authentication mechanism (known as MAN) imposed on operators by Arcep since 2024-2025: calls originating abroad and displaying an unauthenticated French landline number must be blocked. The system has cut back part of the fraudulent cold-calling, but it has blind spots: French mobile numbers legitimately used while roaming, number ranges leased to less-than-scrupulous operators, and calls placed from within the country via gateways.

Remember one simple rule, as valid in 2026 as it was in 2020: a displayed number is not an identity. It's a label stuck on the envelope by whoever sent it.

The same goes for the SMS thread. A fraudulent message using the same alphanumeric sender ID as your bank slots neatly into the existing conversation, below the genuine messages, with the real history above it. The illusion is complete.

The script, phase by phase

Fraudulent calls follow remarkably stable scripts. Knowing their structure is worth more than any list of "warning signs", because the structure itself doesn't change.

Phase 1 — Taking control through legitimacy

The caller introduces himself with a first name, a surname, an "employee number". He gives you information only your bank is supposed to hold: the last four digits of your card, your branch, sometimes one or two recent direct debits. This data comes from leaked commercial databases, sold by the bucketload. It proves nothing, but it buys your trust in ten seconds.

Phase 2 — Reversing the roles

He asks you for nothing. On the contrary, he's protecting you. This is the script's most effective reversal: the victim stops wondering "who am I talking to?" and starts wondering "how do I get out of this?". Vigilance gives way to cooperation.

Phase 3 — The loyalty test

"I'll never ask you for your code, you know that, don't you?" Coming from the fraudster himself, this sentence disarms completely. It repeats, word for word, banks' official advice, and by saying it he places himself firmly on the right side in your mind.

Phase 4 — "Securing the funds"

This is the heart of the scam. He says your money must be moved to safety in a "buffer account", "escrow account" or "technical account" while the compromised card is blocked. You're about to get a notification in your app: it's the cancellation of the fraudulent transaction, you just need to confirm it. In reality, you're authorising an outgoing transfer, adding a payee, or enrolling his phone in place of yours.

Phase 5 — Locking down the clock

"Stay on the line, don't hang up, the procedure expires in four minutes." As long as you're on the phone, you can't call your bank or ask someone close to you for a second opinion. The time pressure serves no technical purpose whatsoever: its only function is to stop you from checking.

Man holding a black bank card in one hand and a smartphone with a blank screen in the other

This has nothing to do with being gullible

It needs to be said plainly, because shame is the main obstacle to reporting: these scams don't target credulous people. They target available people. A manager in a meeting, a parent keeping an eye on a child, a tradesperson on site, someone who happens to have just ordered something online. The target isn't a person, it's a moment of divided attention.

The scripts are written by teams who test them on thousands of calls and keep whatever converts. Faced with a professional persuader working eight hours a day, intelligence offers no protection. Only procedure protects you: a rule decided calmly in advance, applied mechanically in the heat of the moment.

The procedure that shuts it down, in four steps

1. Hang up. Always. There is no banking situation, none whatsoever, that requires you to stay on the line. A real adviser will completely understand you calling back. A fake adviser will beg you not to hang up — it's the best test there is.

2. Call back, but not immediately and not from the same call. Two classic traps here. Dialling back the number that just called proves nothing: the fraudster may have spoofed a number he doesn't control, so you'll reach the real bank, which will wrongly reassure you about the first call. More importantly, on some landlines the line can stay open for a few seconds if the caller doesn't hang up: dial the number from another device, or wait a full minute. Use only the number printed on the back of your card or shown in your app.

3. Open your app yourself and read the full wording of every notification before confirming. French banking apps now display the actual purpose of the transaction: "Adding payee X", "Transfer of €4,200", "New trusted device". That wording is the only truth in the whole exchange. Read it slowly, out loud if necessary.

4. Write everything down, right away. Time of the call, number displayed, name given, amounts mentioned. A screenshot of the original text is worth more than a memory. If the case goes as far as a formal complaint, these details will make the difference.

For people who manage their accounts from a family computer, a laminated checklist placed near the desk — or simply a handwritten card slipped into a rigid document holder — has a disproportionate effect: it turns an emotional reflex into an administrative gesture.

The particular case of family carers

This scenario is especially devastating for older people, for a reason that has nothing to do with mental sharpness: they grew up in an era when you answered the phone and trusted a voice that introduced itself. Refusing to hang up on someone is a deeply ingrained form of politeness.

A few practical adjustments, without being patronising:

  • install a large-button landline phone with call filtering and a whitelist, letting known numbers through and sending the rest to a message;
  • agree on a family password, a word only you know, to be asked of anyone calling on behalf of an institution;
  • pin up on the wall next to the phone the sentence to say: "I never deal with anything over the phone, I'll call my branch back" — a simple magnetic notepad stuck to the fridge will do;
  • check that the online transfer limit is set to a low amount, and that raising it requires a visit to the branch.

The transfer limit is probably the most effective measure on this entire list. It doesn't depend on anyone's vigilance and works even on an off day.

And if it has already happened: what the law says

The French Monetary and Financial Code (articles L133-18 onwards) sets out a strong principle: in the case of an unauthorised payment transaction, the bank must refund immediately, unless the customer has acted fraudulently or with gross negligence. So the entire legal battle turns on two terms: "authorised" and "gross negligence".

Case law has evolved in a direction that is broadly favourable to victims. In several rulings handed down since 2023, the Cour de cassation has held that disclosing a code after being deceived by a sophisticated fraudulent scheme — particularly where the bank's number had been spoofed — does not automatically constitute gross negligence. The burden of proof lies with the bank, which must precisely demonstrate the failing, rather than merely assert that the customer "confirmed it".

That doesn't mean an automatic refund. It means a blanket refusal can be challenged.

The steps, in order:

StepWhereDeadline
Block the cardBank's emergency number, then written confirmationImmediately
Dispute in writingRegistered letter to the branch, claiming a refund under L133-1813 months maximum
File a complaintPolice station, gendarmerie or online complaintWithout delay
Report the text33700 platform (by forwarding the message)Immediately
Refer to the ombudsmanBanking ombudsman, free of chargeAfter the bank's written refusal
Raise the alertInfo Escroqueries 0 805 805 817, Cybermalveillance.gouv.frAt any time

One practical piece of advice that's often overlooked: send the dispute letter even if an adviser has told you verbally that "the case is being processed". Verbal statements leave no trace, and the thirteen-month clock is running. A pack of pre-paid registered mail envelopes, or simply a logbook for tracking correspondence, will stop you losing track of those dates.

Person holding a smartphone and a bank card, reading text on the screen in front of a laptop

Three myths to throw out

"My bank will never call me." False — and that's precisely what makes the scam possible. Anti-fraud departments really do call, often from unknown numbers. The right rule isn't "my bank doesn't call" but "I never deal with anything during an incoming call".

"A text with no link is harmless." That's exactly the model described here. The absence of a link is a credibility device, not proof of innocence.

"2FA protects me." Two-factor authentication protects you against someone stealing your credentials, not against someone politely asking you to tap "Confirm". Fraudsters' entire effort now focuses on that final gesture.

What to keep in mind

Manipulation fraud isn't fought with an antivirus, a filter or an app. It's fought with a sentence learned by heart and a sensible transfer limit.

Here is the sentence: "I'm going to hang up and call my bank back on the number printed on the back of my card." Said calmly, it puts an end to 100% of fraudulent calls. No scammer stays on the line after that. No genuine adviser takes offence.

To go further, France's public resources are solid and free: the quick-reference sheets from Cybermalveillance.gouv.fr, the publications of the Banque de France's Observatoire de la sécurité des moyens de paiement, alerts from the DGCCRF, and the 33700 service for reporting fraudulent texts by simple forwarding. A practical cybersecurity guide for consumers in paper form can also serve as a conversation starter with the family, especially with teenagers or elderly parents — the subject often goes down better around a book than as a head-on piece of advice.

And if you've already confirmed something: don't spend an hour feeling ashamed. That hour counts when it comes to stopping a transfer.

#smishing#fraude#arnaque#Sécurité#Conseil Sécurité#2026#SMS#Cadre légal

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS