"You've won 5,000 V-Bucks": the scam texts targeting teenagers in 2026

Back to the blog
18 September 202610 min read

"Dad, I messed up."

Théo is 14. He received a text telling him he'd been drawn at random to receive 5,000 units of virtual currency on his favourite game. A link, a form, his username, his password, then a six-digit code sent by text that he was asked to "confirm". Forty minutes later, his account — three years of progress and €400 of accumulated purchases — was being resold on a forum. And since he used the same password for his email address, the scammer kept going.

His parents found out because he eventually spoke up. Many teenagers don't. That silence is precisely what most of the scams targeting them rely on.

Close-up of a person's hands using a smartphone resting on a wooden table

Why teenagers are a target of their own

We tend to assume that young people, "born with a phone in their hand", must be naturally immune. Reports filed with the 33700 platform and cases handled by Cybermalveillance.gouv.fr tell the opposite story: their technical ease doesn't protect them, it exposes them differently.

Four factors are at play.

Response speed. An adult will let a suspicious text sit for an hour. A teenager replies in under two minutes, often without leaving the app they were already using. The pause for thought, which is the best defence against smishing, simply disappears.

The real value of gaming accounts. A well-stocked Fortnite, Roblox or Steam account resells for anywhere between €50 and several hundred euros on grey markets. The scammer doesn't need a bank card: the account is the merchandise.

Shame. This is the decisive lever. A teenager trapped by an intimate-photo scam, or who has lost the account their parents paid for, first calculates the risk of having their phone taken away. They pay, they negotiate, they keep quiet.

Little exposure to prevention campaigns. Official messaging about banking fraud or fake tax-office texts doesn't feel relevant to them. Nobody has explained what smishing calibrated for them actually looks like.

The six scenarios that come up most often

1. The fake virtual currency giveaway

The great classic. "Congratulations, your account has been selected", "free generator", "free creator code". The link leads to a very convincing copy of the official login page. The victim enters their credentials; the site then asks for the one-time verification code received by text, supposedly to "validate delivery". In reality it's the two-factor authentication code the official site has just sent because the scammer is in the middle of logging in.

The signal to remember: no game publisher gives away virtual currency by text, and none will ever ask for a code received by text on any site other than its own.

2. The fake side job

"Hello, we're looking for people to test apps, €40 per task, 15 minutes a day." These campaigns primarily target 16- to 22-year-olds, often during school holidays. Two variants:

  • The task scam: the first "missions" really do pay €5 or €10, transferred quickly. Then a deposit is requested to "unlock premium tasks". The money never comes back.
  • The money mule: the young person is offered a transfer into their account, told to keep 10% and send the rest back in cash or cryptocurrency. This is money laundering. The minor or young adult is legally liable and risks a banking ban, criminal prosecution and closure of their account. The Fédération bancaire française regularly warns secondary schools about this trend.

3. Sextortion

The scenario is brutal. A warm first contact on a social network, a quick move to text or a messaging app, an exchange of images, then the blackmail: "send €200 in gift cards or I'll share everything with your contact list". Scammers sometimes show screenshots of the friends list to prove they can do damage.

The absolute rule, hammered home by the association e-Enfance and its 3018 helpline: never pay, delete nothing, screenshot everything, and talk to an adult. Paying only opens a second round of demands. 3018 has a fast-track reporting procedure with the platforms to get content taken down quickly.

4. The hacked messaging account

"Hey it's me, I'm in a contest, can you vote for me?" The message genuinely comes from a friend's account, because that friend was caught out first. The link harvests the credentials, and the cycle starts again with their own contact list. It's the most effective propagation mechanism: trust is pre-installed.

5. The fake streaming subscription or fake platform fine

Rarer but on the rise: "Your subscription has been suspended, settle €1.99". The trivial amount defuses suspicion. The goal isn't the €1.99, it's the bank card number — often a parent's, saved on the phone.

6. The "wrong number" text

An innocuous message, a conversation that builds over several days, then a cryptocurrency investment proposal. This scenario, known as pig butchering, originally targeted adults only. It is now reaching 17- to 20-year-olds, with return promises scaled to small amounts.

Hand holding a smartphone showing a folder of social media apps on the home screen

Where do scammers get a schoolkid's phone number?

Parents ask this every time. The sources are mundane.

SourceMechanism
Data breaches at gaming platforms or appsNumbers resold in bulk on forums
Sign-ups for contests, quizzes, "personality tests"Consent buried in terms and conditions
Resold mailing listsBulk purchase from data brokers
Random diallingAutomatic generation of French mobile number ranges
Contacts harvested from a hacked accountA classmate's address book

In other words: receiving a fraudulent text doesn't mean the teenager "did something stupid". That's an important thing to say at home, because anticipated guilt is exactly what stops them from coming forward.

What actually protects them, in order of effectiveness

App-based two-factor authentication, not SMS

This is the highest-return measure. On gaming accounts, social networks and email, enable two-factor authentication through a dedicated app (Google Authenticator, Authy, or the platform's own app) rather than by text. A code sent by SMS can be extracted through social engineering or a SIM swap; a locally generated code, far less easily.

For a young adult's most sensitive accounts — main email, banking — a physical FIDO2 security key makes phishing almost inoperative: the key refuses to authenticate on a fake domain, even if the user is taken in.

Passwords that aren't recycled

The real damage in Théo's story isn't the loss of the gaming account: it's the password reused on the email address. Installing a password manager on the teenager's phone, and setting it up together, takes twenty minutes and removes an entire category of risk. Both the CNIL and ANSSI recommend this approach in their consumer guides.

The phone's built-in filtering

Android and iOS can now sort unknown senders and flag suspicious messages — Google in fact extended its SMS scam detection to the French market in 2026. On iPhone: Settings → Messages → Filter Unknown Senders. On Android Messages: spam protection in the settings. It isn't foolproof, but it removes a large share of the noise from view.

The 33700 habit

Forward the suspicious text free of charge to 33700 (the official SMS spam reporting service, run by the Association française du multimédia mobile together with the carriers). The service replies asking for the sender's number, which you simply send back. Doing it once together with your teen is worth any number of lectures: it turns an anxiety-inducing message into a concrete action.

For content involving a minor: 3018 (e-Enfance, free, 7 days a week) and the Interior Ministry's PHAROS platform for illegal content.

Hardware, where it makes sense

A few pieces of equipment change things without turning the home into a checkpoint. A router with built-in parental controls lets you set time windows and DNS filtering for the whole household, without spyware-style apps on the child's phone. For younger children, a simplified mobile phone with no internet browser remains a reasonable stepping stone before a full smartphone. And for families who want to approach the subject as something other than a list of bans, a prevention book on teenagers' digital habits often opens conversations that spoken advice never triggers.

Hand holding a black smartphone with the screen off, thumb resting on the display, against a white background

How to talk about it without triggering silence

This is the hardest part, and the most decisive.

State the rule before the incident. The sentence to lay down, calmly, once: "whatever happens, if you get caught out, you won't lose your phone because you came and told me". That explicit guarantee is the difference between a victim who speaks up within the hour and a victim who keeps paying for three weeks.

Tell stories, not rules. "Don't click on links" achieves nothing. "A boy in your class lost his account because he gave out the six-digit code he got by text" creates a reflex.

Give one single, memorable criterion. The one that works best: a code received by text is never given out, to anyone, ever, not even to someone claiming to be official support. One well-anchored criterion beats ten forgotten tips.

Don't monopolise the checking. Teach the teenager to open the official app themselves rather than clicking the link. It's a skill, not surveillance.

What to do within the hour of being caught

Three actions, in order, no debate: cut off access, document, report.

  1. Change the password of the account concerned — and of every account that shared the same password. From another device if possible.
  2. Log out all active sessions in the account's security settings.
  3. Capture the exchanges, the sender's number, the link URL, before deleting anything. These are the evidence for a future police complaint.
  4. Alert the bank immediately if banking details have circulated: cancel the card and request a block. The right to reimbursement for unauthorised transactions is set out in the French monetary and financial code (articles L133-18 onwards) — but you have to report quickly.
  5. Report it: 33700 for the text, 3018 if a minor is involved, PHAROS for illegal content, and file a complaint at the police station or via the online pre-complaint service.
  6. Warn the contacts if the account was being used to spread the message: a simple "my account was hacked, don't click" breaks the chain.

The blind spot: accounts opened before the age of 15

Since the law of 7 July 2023 establishing a digital age of majority, registering a child under 15 on a social network requires, in principle, the consent of those holding parental authority. In practice, verification remains largely self-declared. The result: many teenagers have accounts their parents don't know about, tied to a mobile number and an email address sometimes created for the occasion.

This isn't solved by searching their phone. It's solved by an inventory done together, once a year, simply listing: which accounts exist, which email is attached, which ones have two-factor authentication switched on. The exercise takes half an hour and almost always uncovers two or three forgotten accounts, still active, with an old password.

Key takeaways

The scam texts aimed at teenagers aren't watered-down versions of the ones aimed at adults. They exploit different levers: the value of a gaming account, the appeal of fast money, fear of judgement, speed of reaction.

Technical protection matters — non-SMS two-factor authentication, unique passwords, filtering of unknown senders. But it only counts if the line of communication stays open. A teenager who knows they can come forward saying "I messed up" without losing their phone will report in an hour what shame would have dragged out for a month.

That is, by far, the most effective security measure in the household.

#smishing#arnaque#fraude#Sécurité#Vie privée#Conseil Sécurité#2026#Mobile#données personnelles

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS