The Text Message Targeting Your Company: When Smishing Comes Through Employees' Phones in 2026

Back to the blog
10 September 202611 min read

It is 5:40 p.m. on a Friday. You are packing up. Your phone buzzes: an unknown number, a short message:

"Hi, it's Laurent. I'm in a meeting and can't take calls. I need you for a confidential transaction — are you available?"

Laurent is your managing director's first name. The message is polite, error-free, with no link and no attachment. It asks for nothing — not yet. It only asks whether you are there. And it is precisely because it asks for nothing that most people reply "yes".

Corporate smishing was long treated as an IT problem, solved with filters on the company email system. In 2026, it has changed its point of entry: it now comes through employees' mobile phones, a space where the employer filters nothing, where security alerts do not exist, and where the message lands in among texts from the dentist and the school.

Man with glasses in a white t-shirt checking a message on his mobile phone, looking worried

Why mobile has become the chosen weak link

A company, even a small one, protects its mailboxes reasonably well. Spam filtering, "external sender" banners, blocking of executable attachments, multi-factor authentication: a fraudulent email stands a good chance of being quarantined or flagged before anyone reads it.

Business texting, by contrast, barely exists as a governed channel. In the vast majority of French organisations, urgent internal exchanges go through personal mobiles or an unsupervised company handset. The result:

  • No filtering comparable to that applied to email.
  • No banner flagging an external or unusual sender.
  • A narrow screen, read quickly, often standing up, often while walking.
  • A social norm of brevity: a three-line text with no greeting shocks nobody, whereas an equivalent email would look suspicious.

On top of that, professional information is now massively available. A scammer no longer needs to infiltrate anything: public org charts, professional networks, press releases, legal notices and job postings are enough to reconstruct who runs the company, who handles payroll, who signs off transfers and who has just joined the team. Newcomers, incidentally, are a statistically favoured target: they do not yet know how the place works and will not dare say no.

The four scenarios that come up most often

1. CEO fraud, text-message edition

This is the opening scenario described above. It never starts with a request for money. It starts with an innocuous first contact — "are you available?", "I've changed number, save this one" — whose sole purpose is to obtain a first reply. That reply shifts the relationship: from the moment you have written "yes, go ahead", you are in a conversation, and a conversation creates an implicit obligation to keep responding.

What follows rarely takes the form of a direct bank transfer. It often takes quieter routes: buying digital gift cards "for a client", urgently sending a scanned document, forwarding a contact list, or approving a payment already "prepared by the accountants".

The French national police and the public service Cybermalveillance.gouv.fr have been documenting this family of scams — known as "fake payment order fraud" — for several years now. The mobile version is simply an adaptation to the fastest channel available.

2. Fake IT support

Here, the message imitates a ticket or a technical alert:

"[IT] Your Microsoft session expires today. Reconnect to avoid suspension of your account: …"

This scenario targets your password and, above all, your one-time verification code. Its most effective 2026 variant combines text and phone call: you first receive the message, then a very calm caller explains that he is "handling the ticket" and asks you to read out the code you have just received. That code is the one the fraudster triggered himself while trying to log into your work account.

3. The change of bank details

The accounting version of the scam. A message appears to come from a regular supplier and announces a change of bank account details, sometimes quoting an exact invoice reference — obtained during an earlier compromise of the genuine supplier's mailbox. The text serves as a reminder or confirmation of a fraudulent email: receiving the same information through two different channels creates a dangerously effective impression of consistency.

4. The fake HR message

"Mandatory update of your employee file before 15/09: employment certificate, bank details and ID document to be uploaded here."

This campaign targets the employee directly, not the company. The aim is to collect a complete identity: proof of address, bank details, social security number. Enough to open consumer credit lines, divert a reimbursement, or feed an identity theft case that will resurface months later.

What makes these messages hard to spot in 2026

Three developments have knocked away the usual landmarks.

The quality of the language. Spelling mistakes and clumsy translations are no longer a reliable clue. The texts are now fluent, properly punctuated, and tailored to the vocabulary of the sector being targeted.

The displayed number. Sender ID spoofing makes it possible to display a name instead of a number, sometimes inside an existing conversation thread. France's Arcep and the Fédération française des télécoms have backed the roll-out of the number authentication mechanism — the "MAN" — which limits the phenomenon for voice calls, but the alphanumeric sender ecosystem remains imperfectly sealed.

Knowledge of context. The fraudster quotes a real project name, a real deadline, a real client name. That information rarely comes from a hack: it comes from the company's own publications.

The right instinct is no longer "is this message credible?" but "is this request normal through this channel?". A director requesting a financial transaction by text is abnormal, even if everything else looks perfect.

The single rule that protects best: call back through a channel you choose

Every recommendation boils down to one sentence: never verify a request using the contact details supplied by the request itself.

In practice:

  1. Do not reply to the text, not even with "who is this?". Any reply confirms the number is live and that you read it.
  2. Call the person back on the number you already have in your contacts, or through the internal directory, or by putting your head round the door of the next office.
  3. If the request involves money, apply the four-eyes rule: two people, two different channels, no exceptions on grounds of urgency.
  4. Report the message to 33700, France's national reporting service for unwanted texts, and forward it to your IT manager or management.
  5. Keep a dated screenshot: it will be useful if a complaint has to be filed.

Urgency is the fraudster's only truly indispensable tool. A scammer who cannot rush his victim has no script left. That is why the most effective countermeasure in a company is not technical but cultural: state explicitly that no urgent request ever needs handling in under an hour, and that nobody will ever be blamed for checking.

Smiling man with glasses looking at his smartphone on a balcony, near a hanging hammock

Separating work from personal life, without overcomplicating things

Part of the problem comes from mixed usage. When the same phone receives texts from the bank, the nursery and the office, everything looks alike and nothing gets checked.

Several simple solutions exist, without needing a heavy corporate policy:

  • A second number. A dual-SIM phone, or a secondary eSIM dedicated to work, allows you to compartmentalise. A work-related message arriving on the personal line becomes instantly suspicious — a free and highly reliable signal.
  • A work profile. Android offers a separate work space; iOS allows distinct focus modes. Work notifications stop appearing in the evening, which mechanically shrinks the attack window for messages sent outside office hours.
  • An up-to-date contact list. A complete, carefully maintained address book, with photos where possible, turns an unknown number into a warning sign. It is the cheapest and most neglected measure of all.

For employees handling sensitive accounts — accounting, payroll, systems administration — replacing the code received by text with a physical FIDO2 security key changes the nature of the risk: a code can be read out over the phone to a scammer, a physical key cannot. It is currently the only protection that withstands the "fake IT support calls you" scenario.

In the same spirit, a password manager prevents the same credentials being reused between a compromised personal service and a work login. And on laptops used in open-plan offices, on trains or in coworking spaces, a privacy screen filter stops anyone reading that same information over your shoulder — the best-organised fraudsters also collect data offline.

What the French legal framework says

Three points are worth knowing for every employee.

A personal mobile cannot be monitored. If you use your own phone for work, your employer cannot install monitoring tools on it without strict safeguards and prior notice. France's data protection authority, the CNIL, regularly reminds employers that deploying security measures on personal equipment requires transparency, proportionality and consultation of employee representative bodies. An employee who falls victim to smishing therefore has no reason to fear an inspection of their private phone.

Reporting is not a fault. Many employees say nothing after clicking, out of shame or fear of sanctions. That is the worst possible outcome: the delay between the click and the report is the variable that determines the scale of the damage. A company that punishes reporting simply guarantees it will no longer be told anything.

Bank reimbursement depends on the channel. The French Monetary and Financial Code provides for reimbursement of unauthorised payment transactions, but a transaction the victim approved themselves in their banking app falls under a different regime, that of gross negligence, assessed case by case. The Cour de cassation has ruled several times that the sophistication of the scheme — notably spoofing of the bank's own phone number — could rule out such gross negligence. In other words: the quality of the impersonation works in the victim's favour, provided it can be documented.

A simple plan to put up in the workplace

SituationImmediate reflexAbsolutely avoid
Text from a company director from an unknown numberCall back on the number in the internal directoryReplying "yes" or "is that you?"
Request for a code received by textHang up, no exceptionsReading out the code, even to a "technician"
Change of bank details announced by messageCall the supplier on the number from an old invoiceApproving it on the strength of the message alone
Link to an HR or IT portalOpen the portal via an existing bookmarkClicking from the text message
Message already clickedAlert IT within the hour, change the passwordWaiting to see whether anything happens

For organisations without an IT department, a practical cybersecurity guide for small businesses in paper form, left in the break room, often achieves more than an internal memo: it provides shared vocabulary and makes it legitimate to ask questions.

The heart of the matter

Corporate smishing relies on no technical feat whatsoever. It relies on a way of organising work in which urgency is prized, in which personal mobiles absorb professional traffic, and in which saying "let me check" is still taken as a lack of responsiveness.

The 2026 campaigns exploit that grey area with formidable efficiency, because they attack habits rather than systems. The good news is that habits change faster than infrastructure: collectively deciding that no financial request is ever handled by text is enough to neutralise an entire family of scams.

And if a message has already left you in doubt, keep this rule in mind: a genuine director, a genuine supplier, a genuine IT department will always understand that you took five minutes to check. A scammer, never.

Useful resources: report fraudulent texts to 33700; the Cybermalveillance.gouv.fr platform for diagnosis and assistance; the Perceval service (service-public.fr) for fraudulent bank card use; Info Escroqueries on 0 805 805 817 (free call).

#smishing#fraude#arnaque#Sécurité#Conseil Sécurité#Mobile#2026#Vie privée

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS