"Your subscription has expired": the fake renewal texts that harvest your bank card in 2026

Back to the blog
11 September 202611 min read

The message arrives on a Sunday evening, at the exact moment you were about to start an episode:

"NOTICE: your subscription will be suspended on 13/09 following a failed payment. Update your payment method: rnwl-compte-serv.co/fr"

No spelling mistakes. No threat of police action. No astronomical sum. Just an ordinary inconvenience, the kind that genuinely happens: an expired card, a spending limit reached, a change of bank. The amount quoted, when there is one, hovers around two euros — sometimes €1.90, sometimes €2.49. Nothing to trigger suspicion.

That is precisely the problem. The most effective text-message scams of 2026 no longer demand €749: they ask for €1.90. And it is not that €1.90 the fraudster is after.

Person using a smartphone to scan the barcode on a parcel left in front of a door

Why subscriptions have become the perfect pretext

We live our lives on subscriptions. Video streaming, music, cloud storage, antivirus software, newspapers, the gym, vegetable boxes, mobile plans, phone insurance, electricity suppliers, VPN services, video games: the average French household now juggles around ten recurring payments, often taken out on different dates and sometimes on different cards.

That accumulation creates a perfect blind spot for fraudsters. Ask yourself honestly: could you say, right now, on exactly which date your cloud storage subscription is debited? On which card? For how much?

Almost nobody can. And it is that uncertainty the text message exploits. Unlike the parcel delivery scam, which assumes you are actually expecting a package, the subscription scam works all year round: there is always something that could be about to expire.

France's consumer protection and fraud authority (DGCCRF) and the public service Cybermalveillance.gouv.fr file these campaigns under the broad heading of phishing. But their distinctive feature deserves to be singled out: here, the victim is not robbed on the spot. They are enrolled.

The three business models behind the same text message

Not all fake renewal texts are after the same thing. Recognising which one you are dealing with changes what you need to do next.

1. Straightforward theft of card details

The classic scenario. The link leads to a page that imitates the service in question, asks for your login details, then your full card number, expiry date and security code. The "€1.90 payment" fails "for technical reasons", you are asked to try again with another card — and the fraudster walks away with two payment methods instead of one.

Since strong customer authentication became standard, these details alone are no longer enough for a large purchase. Hence the logical follow-up: a few days later, a call claiming to come from your bank's anti-fraud department will ask you to approve a transaction in your app. This is the manipulation-based fraud whose growth the Banque de France documents in the work of the Observatoire de la sécurité des moyens de paiement.

2. The subscription hidden behind the micro-transaction

More devious. The €1.90 payment is entirely real, and it goes through. What you did not read, because it was written in pale grey underneath the confirmation button, is that this payment opens an "unlimited access" plan billed at €39 to €59 a month, often by a company registered outside France.

The charge does not appear straight away. It starts after a trial period of seven or fourteen days, under a neutral label — "DGTL SRV LTD", "MEDIA ACCESS EU" — that looks like nothing recognisable on your statement.

3. Account theft, with no money involved

Sometimes the goal is not the card but the account itself. A family streaming account, a cloud storage account or a gaming account resold for a few euros on grey marketplaces — and above all, a password that many users reuse elsewhere. If that password is also the one for your email, the loss goes far beyond a subscription.

The six signs that give away a fake renewal

SignalWhat a genuine service doesWhat the fraudulent text does
The channelNotifies you first by email and in the appContacts you by text message only
The linkPoints to its official domainUses a truncated or exotic domain (.co, .icu, .top, .cfd)
The urgencyGives you several days, follows up gentlySets a deadline 24 or 48 hours away
The amountMatches your actual planQuotes a strangely low sum
The requestNever asks for your card's security code via a text linkDemands full card details and CVV
The identificationMentions your name or your specific planStays vague: "your subscription", "your account"

The sixth point is the most telling. A service you are genuinely subscribed to knows which plan you signed up for. A text that talks about "your subscription" without ever naming the plan, the date or the last four digits of your card does not know you.

Simple rule: a message asking you to prove your identity to a sender who cannot prove their own is always suspect.

The sender name trap

"But the text appeared in the same conversation as the real messages from the service."

This is the point that disarms victims, and there is a technical explanation for it. Legitimate commercial messages use an alphanumeric sender ID — a brand name rather than a number. That field was for a long time self-declared: nothing physically prevented a sender from identifying itself under a brand name that was not its own.

France has put in place a mechanism to combat this impersonation, with a register of authorised senders managed by the industry and built on the framework defined by Arcep and AF2M. French operators now filter a significant share of traffic impersonating registered trademarks. But the protection is not watertight: messages routed from abroad, slightly altered names ("NETFLlX" with a lowercase L in place of the I) and campaigns sent from ordinary mobile numbers still get through.

Practical conclusion: the name displayed at the top of the screen is not proof of identity. A fake message being grouped with genuine ones in the same thread is a mechanical consequence of how messages are displayed, not a validation by your operator.

Delivery driver in a red "Delivery" T-shirt carrying parcels and checking his mobile phone in front of a garage

What to do within five minutes, if you clicked

The most useful reflex is not to panic, it is to act in the right order.

  1. Cut off contact with the page. Close the tab, do not fill in anything else, do not "correct" anything.
  2. Block or cancel the card. Most banking apps now let you freeze a card with a single tap, reversibly. Do it immediately, before you even make a phone call.
  3. Do not take any incoming call claiming to be from your bank in the days that follow. Hang up and call back yourself, using the number on the back of your card.
  4. Change the password for the service concerned, and for every other account where you used the same one. This is the moment you realise how unmanageable handling passwords manually becomes: a password manager, whether software or even a password notebook kept out of sight, prevents the reuse that turns one incident into a chain reaction.
  5. Report the message to 33700, France's national service for reporting unwanted text messages. Simply forward the text to that number, then send the sender's number when prompted. It is free and it feeds into upstream blocking.
  6. File a complaint if money has been taken, and report it on the Cybermalveillance.gouv.fr platform or via the PHAROS portal for the illegal content aspect.

On reimbursement, Article L133-18 of the French Monetary and Financial Code provides that the bank must refund unauthorised transactions. In practice, the argument turns on the notion of gross negligence: handing over your details on a fake site after an unsolicited text is not, in itself, automatically classed as gross negligence — the Cour de cassation's case law has confirmed that the burden of proof lies with the payment service provider. So keep everything: a screenshot of the text, the site address, the timestamp.

Stopping the bleeding when the payments have already started

If you discover an unknown recurring charge, timing matters.

  • SEPA direct debit: you can request a refund without having to give a reason within 8 weeks of the debit date, and up to 13 months if it was unauthorised. This request goes to your bank, not to the merchant.
  • Recurring card payment: first send the company a written cancellation, then dispute the charge with your bank. Simply blocking the card is not always enough, because some networks automatically carry subscriptions over to the replacement card.
  • Billing via your mobile operator: if the charge appears on your phone bill (premium-rate services), contact your operator's customer service and ask for premium-rate purchases to be blocked — this can be done permanently.

Get into the habit of reading your statements. A simple account notebook or a folder for filing administrative documents is enough to spot an unfamiliar label that keeps recurring — most victims only discover the charge after four to six months, purely because nobody reads the lines under €60.

Shrinking the attack surface before the next text arrives

You cannot stop a fraudster from sending a message. You can, however, make sure it achieves nothing.

Keep your money separate from your subscriptions

The most effective measure, and the most under-used: never store your main card with a subscription service. Use a single-use or capped virtual card, offered by most French banks, or a rechargeable prepaid card dedicated to online payments. If the data leaks, it only gives access to a near-empty account.

Keep an inventory of your subscriptions

Five minutes, once. List each service, the payment date, the amount, the payment method. A simple table will do. Once you know that Spotify is charged on the 6th and your cloud storage on the 22nd, a text announcing a suspension on the 13th becomes instantly absurd.

Protect the accounts themselves

Turn on two-factor authentication wherever possible, favouring an authenticator app over text messages. For your most sensitive accounts — main email, bank, government services — a physical USB security key remains the most robust protection against phishing, because it simply refuses to authenticate on a fake domain.

Filter upstream

On both iPhone and Android, turn on filtering for unknown senders: messages from numbers that are not in your contacts are grouped into a separate tab. You still receive them, but without a notification catching you off guard at 10 p.m.

A delivery driver checks his smartphone next to a woman carrying cardboard parcels in a hallway

The special case of fake energy texts

One variant deserves a separate mention, because it has exploded alongside recent changes in energy tariffs: the text announcing an overpayment to be refunded or an electricity bill adjustment.

The setup is reversed and therefore even more effective: you are not being asked to pay, you are being offered money. "Following the annual adjustment, a refund of €187.42 is due to you. Please provide your bank details." You lower your guard because the money is flowing in the right direction.

No energy supplier, no tax authority, no social security body will ever ask for your full bank details by text message in order to refund you. Refunds are made to bank details already on file, through official customer portals. If you have any doubt about a message claiming to come from a public body, the rule never changes: close the text and type the official website address into your browser yourself.

Key takeaways

The fake subscription renewal scam relies on no technical feat whatsoever. It relies on the fact that we have collectively agreed to pay, every month, a dozen small sums we no longer keep track of. The fraudster simply slips into that blind spot.

Three sentences are enough to protect yourself for good:

  • A subscription is never sorted out via a link received by text, always through the app or the website address typed in by hand.
  • A trivial amount is a warning sign, not a guarantee that it is harmless.
  • The name shown as the sender proves nothing.

And if any doubt remains, there is a foolproof test: open the app of the service concerned. If your subscription is active and up to date, the text is lying. If it mentions no payment problem, the text is lying. What is in your account is what counts; what appears in your message thread counts for nothing at all.

#smishing#arnaque#fraude#SMS#Sécurité#Conseil Sécurité#2026#Vie privée

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS