Three weeks after losing €2,400 in a fraudulent bank transfer, Claire received this text message:
"Ms MOREAU, your case no. RF-2026-8841 has been selected by our recovery unit for victims of banking fraud. Identifiable amount: €2,380. Call back 01 84 XX XX XX or visit: recouv-victimes-fr.net"
The amount is almost right. The name is correct. The word "case" echoes the complaint number she did in fact file. And above all: Claire desperately wants to believe that this money isn't gone for good.
She will call back. She will pay €380 in "case file set-up fees". Then €750 as a "release deposit". She will never see the original €2,400 again, nor the additional €1,130.
This mechanism has a name in international police vocabulary: the recovery room, or fund recovery scam. In France, the Autorité des marchés financiers (AMF) has been warning about this pattern for several years, initially in the field of fraudulent investments. In 2026, it has shifted massively to text messages and now targets all scam victims, not just defrauded investors.

Why fraudsters come back to the same victims
This is the hardest part to hear, and yet it's central: being a victim once statistically increases the likelihood of being targeted again.
Three reasons combine.
1. Victim lists circulate. When a smishing campaign succeeds — form filled in, card details entered, call completed — the operator records the result. These files, known as "sucker lists" in English-speaking jargon, are worth more on the market than a list of raw phone numbers, because they identify people who have already taken the plunge. They are resold between criminal groups, exactly like any other marketing database.
2. The psychological profile is known. The fraudster doesn't just know that you have a mobile number: they know which scenario worked on you, what amount you agreed to pay, and at what time of day you answer. This is behavioural targeting applied to fraud.
3. The victim is in an exploitable emotional state. Shame, anger, a sense of injustice, a need for redress. The prospect of "getting it back" acts as a far more powerful lever than the fear of a fine or the lure of a prize. Cybermalveillance.gouv.fr and the Direction générale de la concurrence, de la consommation et de la répression des fraudes (DGCCRF) regularly stress this point: secondary campaigns exploit the distress created by the first one.
In other words, the first scam produces the raw material for the second.
Anatomy of the fake recovery text message
These messages don't look like parcel delivery or traffic fine texts. They are more sober, more administrative, often longer. A few recurring markers observed in 2026:
| Element | What the text says | What it's actually worth |
|---|---|---|
| Case number | "Case no. RF-2026-8841" | Randomly generated, no basis whatsoever |
| Amount | Close to but not identical to the amount lost | Estimate based on resold data or a plausible range |
| Entity named | "recovery unit", "ombudsman", "approved firm" | No legal existence under that name |
| Urgency | "within 72 hrs before closure" | Prevents reflection and verification |
| Callback channel | 01/09 number or web link | Offshore call centre, disposable website |
Some messages go further and impersonate real names: Banque de France, AMF, Tracfin, "national anti-fraud service", or even an existing law firm whose name has been copied. Impersonating public bodies remains one of the most effective levers in smishing — the same mechanism as sender spoofing, but applied to a promise of redress rather than a threat.
The most common variants
- The fake specialist lawyer. They offer a "class action" against the fraudulent platform, in exchange for fees paid up front.
- The fake regulator. It announces that your funds have been "frozen in an escrow account" and that a release tax is due.
- The fake bank department. It claims to have "identified the beneficiary" of the transfer and asks for your login credentials to start the recall of funds.
- The fake compensation fund. It mentions a European guarantee fund and requests supporting documents — ID, bank details, an invoice — which in reality feed a full-blown identity theft.
- The fake "crypto hunter". They claim to be able to trace your crypto-assets on the blockchain, a technically plausible service but commercially bogus in 99% of cases.
The one signal that never lies: you're asked to pay
Remember this sentence, it sums up the whole article:
No legitimate organisation in France will ask you to pay, in advance and through untraceable means, in order to return money that belongs to you.
Not the Banque de France, not the AMF, not the police, not the gendarmerie, not your bank. Filing a complaint is free. Referring a case to the banking ombudsman is free. The procedure for disputing a payment with your bank, provided for by the French Monetary and Financial Code, is free.
When fees appear — "processing fees", "release tax", "deposit", "VAT on recovery", "success commission payable in advance" — the question is no longer is this genuine? but how do I end this conversation?
A second, equally reliable signal: the method of payment requested. Gift cards (PCS, Transcash, Neosurf), transfers abroad, crypto-assets, cash sent by courier. These channels are chosen precisely because they are irreversible. A legitimate organisation never operates this way.

What to actually do when you receive the message
1. Don't call the number provided
Not even out of curiosity. A callback confirms that the line is active and that a human answers — information that has value. The call centres running these campaigns are trained: they have a script for the suspicious person, another for the angry one, another for the person who "just wants to understand".
2. Verify through a channel you choose yourself
The cardinal principle of any verification: never use a contact provided by the suspicious message. Type the official address yourself, or dial the number on the back of your bank card.
- AMF: public blacklist of unauthorised operators, available on the official website
- Assurance Banque Épargne Info Service (ABE IS), a joint public service of the AMF / ACPR / Banque de France: 34 14 (standard rate call)
- Cybermalveillance.gouv.fr for an assessment and referral
3. Report the message
The number 33700 remains the national reporting system for fraudulent text messages: forward the text to 33700, then send the sender's number when prompted. In parallel, the PHAROS platform (internet-signalement.gouv.fr) collects reports of illegal online content.
4. Document everything
This is where most cases fall apart. Screenshots, statements, timestamps: everything must be kept in a legible and orderly manner. Many victims write to me with a dozen blurry photos of a screen taken with another phone. A simple archive binder with document sleeves, in which you file dated printouts, annotated bank statements and the complaint receipt, often does more for a case than an hour of online research. Number the items. Date them. It will serve you before the bank, the insurer and, where applicable, the court.
5. Block, but don't expect miracles
Blocking the number is useful, but these campaigns run on thousands of disposable lines. Blocking protects you from that one number, not from the campaign.
The genuine avenues of recourse in France
Since the scam exploits a lack of knowledge about real procedures, it's worth setting them out clearly.
For an unauthorised card payment: you have the right to dispute it with your bank. Article L133-18 of the Monetary and Financial Code provides for immediate reimbursement of unauthorised transactions, except in cases of gross negligence on your part — and that is precisely the point of contention when the victim entered their own codes. The dispute window is 13 months (70 days for certain transactions outside the European Union).
For a transfer you made yourself under manipulation: the situation is harder, but it is evolving. The Banque de France and the Observatoire de la sécurité des moyens de paiement are closely monitoring the rise in "manipulation scams", where the victim carries out the transaction themselves. Ask your bank to attempt a recall of the funds as quickly as possible: the first few hours are decisive.
If the bank refuses: free referral to the institution's banking ombudsman, and then possibly to ABE IS.
Filing a complaint: at a police station, a gendarmerie, or online via the pre-complaint platform. Filing a complaint is a right; a service cannot refuse it.
Identity theft: if you have handed over an identity document, report it, monitor your banking situation and consider the right of access provided for by the GDPR to find out what data is held about you. A practical guide to personal data protection written for a general audience helps you understand which levers genuinely exist, beyond generic advice.
Reducing your attack surface after a first fraud
You can't erase your number from the lists in circulation. What you can do is make subsequent attempts less effective.
Separate your uses. Many repeat victims use the same number for everything: banking, classified ads, commercial sign-ups, deliveries. A second line — via a prepaid SIM card with no commitment — reserved for ads and non-essential sign-ups limits the contamination of your main line.
Lock down the second factor. If your verification codes arrive by text message, they are vulnerable to line hijacking. Switching sensitive accounts to an authenticator app, or even to a physical FIDO2 security key, removes that vector entirely.
Secure the device itself. After a fraud, the question "has my phone been compromised?" always comes up. Update the operating system, remove any apps installed outside the official store, and check accessibility permissions — that's the route used by Android malware that reads text messages.
Deliberately slow down. The recovery scam relies on the idea that you must act fast. Adopt the opposite rule: no financial decision within the 24 hours following an unsolicited message. A pocket-sized notebook, in which you write down the date, the time, the content and your reaction before deciding anything, turns an impulse into a case file.
The psychological dimension that's never discussed enough
It has to be said plainly: shame is the fraudster's best ally. A victim who tells no one is a victim who decides alone, under pressure, facing a professional manipulator.
Victim support associations — France Victimes and its national number 116 006, free and available seven days a week — exist precisely for that. They don't judge, they guide. Talking to a third party before paying anything remains the most effective protective measure on this entire list, and the least technical.
Some people also find it useful to understand the mechanisms themselves rather than merely endure them: a book on manipulation and social engineering explains how these scripts are built, and reading it once provides lasting immunity. You recognise a technique far more easily once you've seen it described in the cold light of day.
Key takeaways
- Receiving an offer to recover funds after a fraud isn't a stroke of luck: it's a sign that you appear on a resold victim list.
- No legitimate organisation asks for advance payment to return your money. The "processing fees" are the scam itself.
- Gift cards, crypto, transfers abroad: three payment methods that give the scam away.
- Always verify through a channel you have chosen yourself — never the number provided in the message.
- Report to 33700, file a complaint, and refer your case free of charge to the banking ombudsman if your bank refuses.
- 116 006 (France Victimes) and 34 14 (ABE IS) are free. Fraudsters are not.
If you have already lost money, the good news is modest but real: avenues of recourse do exist, they are free, and they run through institutions you can contact yourself. Anything that arrives unprompted by text message with a promise of restitution deserves, in 2026, exactly the same treatment as a fake parcel delivery text — deletion.



