"I don't get it, I never give my number to anyone."
That's the line you hear every single time someone complains about receiving three scam texts a week. And they mean it: they genuinely don't remember handing over their number. Except they did — at a shop checkout for a loyalty card, on an insurance quote form, in a listing to sell a bike, during an online order so they'd be notified about the delivery, when signing up for an account that required SMS verification.
A French mobile number is no longer just a way to be contacted. It has become a universal identifier: unique, stable for years, rarely changed, tied to a civil identity at the carrier. No other piece of personal data is worth as much to anyone who wants to reach you — a salesperson as much as a scammer.
The good news is that the volume of scam texts you receive isn't some kind of weather event you just have to endure. It depends directly on how exposed your number is. And that exposure can be reduced.

Where targeted numbers really come from
Contrary to popular belief, scammers don't buy all their numbers on underground marketplaces. The sources are far more mundane, and that's precisely what makes the problem so hard to contain.
Automatic generation
This is the simplest method and it doesn't require any leak at all. French mobile number ranges are public: ARCEP allocates blocks starting with 06 and 07 to carriers, and those blocks are documented. So a piece of software can generate millions of valid combinations and blast them out en masse.
This type of campaign explains the perfectly generic texts: "Your parcel is on hold," "Account blocked, please regularise." No personalisation, no name. The message is betting that one person in a hundred happens to be expecting a parcel that day.
Customer database leaks
The years 2023–2026 saw a string of massive breaches in France affecting carriers, health insurers, retail chains and health data management organisations. The CNIL has issued several formal notices and penalties on the matter, and advises those affected to be especially vigilant about the messages they receive.
Those leaks are what produce the unsettling texts: the ones that know your name, sometimes your town, sometimes the name of your health insurer. The content becomes believable because it's built on real data.
Lawful collection, then resold
This is the biggest and most underestimated source. Every time you tick — or forget to untick — a box allowing your data to be passed on "to our partners," your number enters a perfectly legal commercial chain. It's rented out, enriched, cross-referenced with other databases.
The GDPR regulates this practice, but regulating is all it does: it doesn't ban it. And a lawfully built database can later leak, be resold outside the intended framework, or end up with an operator who isn't too fussy. The path from "DIY store loyalty card" to "text from a fake bank adviser" is shorter than you'd imagine.
Scraping classified ads
Classified ad sites are a goldmine. Plenty of sellers put their number straight into the ad text to avoid the internal messaging system. Bots harvest those numbers continuously, with a bonus: they know the person is selling something, at what price, and in what town. That's exactly the fuel for fake-buyer scams.
A simple test to see where you stand
Before acting, it helps to measure. For two weeks, log every unsolicited text you receive in three columns:
| Type | Clue | What it tells you |
|---|---|---|
| Generic, no name | "Your parcel," "Your account" | Automatic generation — unavoidable |
| With your first or last name | "Hello Marie, your file…" | Your number is in a named database |
| With specific context | Name of your bank, your health insurer, a recent purchase | Targeted leak or qualified resale |
If most of your texts are generic, your exposure is normal and filtering measures will be enough. If you regularly receive messages using your name and context, your number is circulating in qualified databases — and the work to be done is different: it's about distribution, not just filters.
Reducing exposure: what actually works
Stop using a single number for everything
This is the most powerful and the simplest lever. The structural mistake is using the same number for the bank, the family, deliveries, classified ads and online sign-ups. Everything is mixed together, so everything is exposed at the level of the weakest link.
The answer isn't to change your number — that's ineffective, disruptive, and the new number will be exposed within eighteen months. The answer is to segment.
A second number dedicated to "public" uses (ads, marketing forms, sign-ups to non-essential services) makes the pollution on your main number collapse. Several options exist:
- a pay-as-you-go SIM card with no contract, topped up occasionally, often for just a few euros;
- a secondary eSIM, if your phone supports it, which avoids physically swapping anything;
- a dual-SIM smartphone, which lets you keep both lines active without a second device.
For those who don't want to change devices, a dual-SIM adapter remains a decent stopgap on older models, even if it's less smooth to manage than true dual SIM.

Stop giving your number when it isn't required
A simple legal principle, restated by the CNIL: a data controller may only collect the data necessary for the stated purpose. A mobile number is almost never necessary for a loyalty card, a newsletter or a brochure download.
In practice, in a shop, "I'd rather not give it" is enough in the vast majority of cases. The card gets created anyway. The number was asked for because the form asked for it, not because the service required it.
On online forms, the field is often marked mandatory out of lazy design. When the service is genuinely useful, it's not unreasonable to put your secondary number there.
Clean up existing ads
If you've published ads with your number in plain text, they're probably still indexed. Searching for your own number in quotation marks on a search engine sometimes turns up surprising results: second-hand listings, business accounts, old forums, association membership lists, meeting minutes published as PDFs.
Every result you find is a removal request to send. The GDPR gives you a right to erasure, which you can exercise with the site's controller, with the option of referring the matter to the CNIL if they refuse.
Exercise your right to object to marketing
The GDPR provides a right to object to direct marketing, which you can exercise without having to justify yourself. In concrete terms:
- for telephone cold calling, registering with Bloctel is still free and binding on businesses as far as calls are concerned;
- for legitimate marketing texts, sending the word STOP to the short code works and costs no more than the price of a text;
- for scam texts, STOP is counterproductive: it confirms the number is active and being read.
This distinction is crucial, and it's where a lot of people go wrong. A text from a well-known brand with a "STOP 36xxx" mention is a regulated commercial communication: replying STOP stops it. A scam text has no legal STOP mention — or fakes one. In that case, you don't reply; you forward it to 33700.
Filtering what gets through anyway
Reducing exposure takes months. In the meantime, filtering limits the day-to-day damage.
Built-in phone filters
Android and iOS both offer automatic sorting of unknown senders and junk message filtering, now reinforced by on-device analysis models that spot phrasing typical of smishing. These features are useful but rarely enabled by default on every device — it's worth checking the settings in your Messages app.
Their limitation is well known: they're poor at filtering messages that spoof a legitimate sender name and slip into an existing conversation thread.
Manual blocking, in moderation
Blocking each sending number is a natural reflex, but the returns are low: smishing campaigns change numbers with every batch. Blocking mainly offers a psychological benefit — never seeing the message again — and a real benefit in one case only: harassment from a stable sender.
Reporting to 33700
Forwarding to 33700 doesn't protect you individually, but it feeds the carrier scheme that cuts off abusive senders. It's free, doesn't count against your plan, and it's the only action with a measurable collective effect.
Protecting sensitive uses: the real issue
Cutting down on scam texts is nice. But the real goal lies elsewhere: making sure that a compromised number doesn't compromise your accounts.
Because today, a mobile number isn't just a receiving channel. It's often an account's recovery key: "Forgot your password? Get a code by text." That means whoever controls your number controls your accounts.
Get SMS out of authentication where you can
SMS remains the most widespread and the weakest authentication factor. ANSSI has advised against it for years in favour of more robust solutions. For important accounts — your main email, cloud storage, social networks, payment platforms — it's better to switch to an authenticator app that generates codes offline.
For truly critical accounts, a physical USB security key remains the highest level: even if an attacker gets your password and your SMS codes, they can do nothing without the physical object.

Lock down the SIM card itself
Line hijacking — obtaining a new SIM in your name to intercept your codes — is still rare but devastating. Two simple measures:
- keep an active PIN code on the SIM card, something other than 0000 or 1234, which many people disable for convenience;
- ask your carrier whether a password or two-step validation can be required for any SIM replacement request. Most offer it, few promote it.
Keep your passwords somewhere other than your texts
A common habit is texting sensitive information to yourself: a safe code, a login, a contract number. The message thread then becomes an open keyring, readable by anyone who picks up the phone for a few seconds.
An encrypted password manager solves the problem for digital credentials. For codes you don't want stored online anywhere, a paper password notebook kept at home remains, counterintuitively, a serious option: it isn't exposed to the internet and it doesn't disappear with the phone you left on the train.
The case of children and older people
Two groups deserve special treatment, for opposite reasons.
Teenagers hand out their number on a massive scale: game sign-ups, exchanges on platforms, prize draws. Their exposure is structurally high. Segmentation really comes into its own here: main line for family and school, secondary number for everything else.
Older people rarely give out their number but appear in old, well-filled databases: health insurers, pension funds, associations, carriers. Their scam texts are therefore more contextualised, and therefore more believable. The right approach isn't to overload them with settings, but to install a single, memorable rule: never click a link received by text, ever; call the organisation back on the number printed on a paper document.
For those who struggle with small screens, a large-button phone with a high-contrast display reduces handling errors, which are a widely underestimated cause of accidental clicks.
Key takeaways
The volume of scam texts you receive isn't random: it's a measure of how exposed your number is.
Three levels of action, in order of effectiveness:
- Segment — one number for sensitive uses, another for everything else. This is the highest-return measure.
- Limit distribution — don't give out your number when it isn't necessary, clean up what's lying around online, exercise your right to object.
- Decouple — make sure your number is no longer the recovery key for your important accounts.
Filtering and blocking come afterwards. They treat the symptom, not the cause. And if the cause fits in one sentence, here it is: we have allowed a unique, permanent, verified identifier to become the piece of data we hand out most readily.
To check that an organisation is using your data lawfully, the CNIL provides template letters for exercising your rights of access and objection on its website. To report a confirmed scam, the Cybermalveillance.gouv.fr platform points you to the appropriate steps, and filing a complaint at a police station or gendarmerie remains an option, with your screenshots in hand.



