Travelling Abroad: The Scam Texts That Exploit Roaming and Your Local SIM Card

Back to the blog
28 September 202611 min read

"I had just landed in Istanbul. My phone buzzed four times in a row: welcome to the network, non-EU rates, then a message saying my travel add-on hadn't been activated and that I had to validate it online within two hours. I clicked while standing in the border police queue. I only realised what had happened that evening."

You hear some version of this story every time the holidays end. It isn't about being naive: it's about context. Abroad, your phone becomes chatty. It spontaneously sends messages you never receive at home, written in that stilted carrier-speak, from unfamiliar short codes, with amounts in foreign currencies. In all that legitimate noise, a fraudulent text goes almost unnoticed.

This guide sets out what your carrier really sends you when you cross a border, what it will never send you, and the right order of operations for preparing your line before departure — including when you buy a local SIM card or a tourist eSIM.

Person holding a smartphone in both hands in front of a keyboard resting on a wooden desk

Why crossing a border is a window of risk

Your phone starts talking on its own

As soon as your mobile latches onto a foreign network, several mechanisms fire off one after another. This is perfectly normal, and that's exactly the problem: within minutes you receive a string of messages you never asked for.

  • The network welcome text, sent by the visited carrier or by your own, setting out the applicable rates.
  • Data spending cap alerts, mandatory within the European Union and often replicated outside it: a warning at 80% and then at 100% of the spending cap.
  • Messages from the local carrier offering tourist packages, sometimes in English, sometimes in the local language.
  • Possibly notifications from your bank flagging a login from a new country.

Four to six messages in ten minutes, all unusual, all legitimate. A seventh, fraudulent message slipped into the batch doesn't stand out. It benefits from what social engineering specialists call a carrier context: the victim is already expecting administrative information about their line.

You're in an unfavourable state of mind

Smishing works when verification is expensive. On arrival at an airport, it's very expensive indeed:

  • you don't yet have a stable data connection to go and check your carrier's official website;
  • you're in a hurry, tired, sometimes jet-lagged;
  • you have a genuine fear of out-of-plan charges, still the nightmare of many travellers;
  • calling customer service from abroad feels complicated and costly.

The scammer doesn't need a very convincing message. A plausible message at the wrong moment is enough.

What your carrier really sends you — and what it never sends

Genuine messages

French carriers (Orange, SFR, Bouygues Telecom, Free Mobile and the virtual operators) follow a framework set by the European roaming regulation and by Arcep's information obligations. In practice, a legitimate message:

  • informs you of a rate, a threshold reached, an included add-on;
  • never asks for a bank card number by text;
  • never asks for your customer account credentials within the message itself;
  • does not impose a two-hour deadline on pain of disconnection;
  • when it does contain a link, points to the carrier's official domain — not to a URL shortener.
What you receiveLegitimate?Signal to check
"Welcome to Turkey. Calls: €X/min, data: €Y/MB"Yes, typicalNo link, no action requested
"You have reached 80% of your data cap"Yes, mandatory in the EUNo payment requested
"Activate your travel add-on: link, within 2 hrs"NoUrgency + link + action
"Settle €1.99 to keep your line active"NoSmall amount = card harvesting
"Your bill is unpaid, line suspended abroad"NoThreat + link

The small amount is a signature. A scammer asking for €1.99 or €2.50 isn't after that sum: they're after the sixteen digits of your card, its expiry date and the security code, plus the 3-D Secure confirmation they'll obtain by calling you afterwards. The real debit arrives later, in several instalments, often from a foreign merchant.

Legitimate doubt: sender numbers

Abroad, senders become unreadable. You may receive a message from a five-digit short code, from an unknown international number, or from an alphanumeric sender name. That variety is normal: the visited carrier doesn't use the same conventions as yours.

Practical consequence: the sender number tells you nothing when you're abroad. Neither one way nor the other. A sender name displaying "Orange" can be spoofed — that's the principle of sender spoofing, extensively documented by the French government platform Cybermalveillance.gouv.fr. An odd-looking number can be entirely legitimate.

The only thing that matters is what the message asks you to do.

The special case of eSIMs and tourist SIM cards

Why they blur your bearings

Travel eSIMs have become mainstream. They're convenient, often cheap, and they avoid out-of-plan charges. But they introduce a complication: you end up with two active numbers on the same device, one of them a foreign number you don't know by heart.

The result:

  • you no longer know which line a text arrived on;
  • your banking codes keep arriving on the French line, which may have data switched off;
  • messages from the local carrier, in a language you don't master, become impossible to sort;
  • the eSIM provider itself sends you notifications by text and email, creating a message template that scammers imitate.

How to limit the confusion

A few habits are enough to restore clarity:

  1. Name your lines in the phone's settings: "France — banking" and "Travel — data". Most systems then display the line name above each conversation.
  2. Keep the French line on receive-only: data roaming off, but calls and texts active, so you continue to receive verification codes.
  3. Write down your local number somewhere other than your phone. A simple hardcover travel notebook tucked into your bag saves you digging through settings every time someone asks for that number.
  4. Never use the local number as the recovery number for an important account: it will be recycled a few weeks after you get home.

Man wearing a turban sitting on a bed reading a text message on his smartphone, laptop on his knees

The most common travel smishing scenarios

1. The fake roaming add-on activation

The most widespread. A message received within an hour of landing, using the carrier's name, announcing that the travel add-on hasn't been activated. The link leads to a payment page that copies the customer account interface.

The tell: a carrier never makes you pay for an add-on after your arrival, under time pressure, via a link in a text message.

2. The fake overage billing notice

"Your out-of-plan usage has reached €148. To avoid suspension, settle immediately." The amount is calibrated to frighten without seeming absurd. The payment page asks for the card, then for a code received by text — which the victim hands over themselves.

3. The fake accommodation booking

You've booked a place to stay. A text announces that the payment has failed and that you must "reconfirm" within 24 hours or the booking will be cancelled. This scenario requires a data leak or broad targeting, but it works very well because it hits a genuine source of anxiety. The rule: you never pay again from a link in a text; you go back into the platform's app or website.

4. The fake support desk after a phone theft

The traveller reports their device stolen, buys a stopgap phone, inserts a new SIM. They then receive a message claiming to be from their carrier's support team or from the device-tracking service, asking for account credentials to "unlock the search". This is one of the most effective variants, documented by several European police forces: the victim is expecting precisely that kind of contact.

5. Fake visa fees or entry taxes

Some countries require an electronic travel authorisation. Text campaigns piggyback on these schemes to demand extra fees after arrival. No country ever asks for an entry tax by text message after you've crossed the border.

Getting your line ready before departure: the checklist that matters

One week before

  • Check what's included in your plan for your destination, and write it down. A screenshot of your carrier's pricing page, stored offline, is worth any amount of later verification.
  • Activate the spending cap in your customer account. It turns fear of the bill — the main lever behind these scams — into a non-issue.
  • Save the customer service number reachable from abroad. It's on the back of your SIM card holder or on the official website.
  • Move your sensitive accounts to text-independent authentication: an authenticator app, or better still, a physical FIDO2 security key that works without a network and is immune to smishing.

The day before

  • Make a full backup of your phone. If the device disappears, you won't have to improvise.
  • Check that device location tracking is enabled and that you know the password for the associated account — not just the unlock code.
  • Pack a self-contained power source. A dead phone means you can't check a message, block a card or receive a code. A 10,000 mAh power bank covers two days of normal use.

While you're there

  • Don't deal with any financial message on a public airport or hotel Wi-Fi network without protection. If you need to check your bank, use mobile data.
  • Read sensitive messages away from prying eyes: on a train or in a crowded concourse, a smartphone privacy screen filter stops anyone reading your codes from the side.
  • Keep the second-channel reflex: a message announces a problem? You check via the official app or by calling back the official number, never via the link or number supplied in the message.

What to do if you clicked while abroad

Distance complicates your response, but it doesn't change the order of priorities.

  1. Switch off data and Wi-Fi for a few minutes, long enough to think without new notifications.
  2. Block the bank card from your bank's app. A temporary block is immediate and reversible; it requires no phone call.
  3. Change the password of the account concerned, from another device if possible.
  4. Don't confirm any code you receive afterwards. A scammer often calls back within minutes, posing as the anti-fraud department.
  5. Report the message to 33700 as soon as you're back on the French network: the service doesn't work from a foreign line. You can also report it on the Cybermalveillance.gouv.fr platform, accessible from anywhere.
  6. File a complaint on your return if money was taken. The European payment services directive, transposed into French law, provides for the reimbursement of unauthorised transactions; the institution must demonstrate gross negligence in order to refuse.

Man with glasses looking suspicious as he reads a message on his smartphone indoors

On your return: clearing up behind you

Once the trip is over, two or three simple steps will prevent a second wave a few weeks later.

  • Delete the tourist eSIM from your device. As long as it remains installed, it can keep receiving messages on a number that no longer belongs to you.
  • Check your subscriptions: some travel scams end in a premium-rate subscription that only shows up on the next bill. Read the "purchases charged to your carrier bill" line carefully.
  • Re-enable any security options you may have switched off during your stay.
  • Review your bank statements over three months. Fraudulent debits from a card stolen while travelling often arrive with a delay.
  • If you used public charging points, note that France's ANSSI recommends avoiding unknown USB sockets: a USB data blocker adapter lets only the current through and makes that risk theoretical.

Key takeaways

Travel doesn't create new scams: it disables your usual bearings. You no longer recognise senders, you're expecting administrative messages, you're afraid of a bill, and checking becomes expensive.

The defence comes down to three simple ideas. First, cap your spending before you leave, to strip the scammer of their main argument. Second, never pay or log in from a link received by text, however credible the sender. And finally, take your critical accounts off text-based authentication, because abroad, your French line is precisely the weakest link.

One last rule of thumb, worth passing on to less confident travellers: a carrier, a bank or a government body writing to you abroad will never give you a two-hour deadline. Urgency, whether you're roaming or at home, remains the most reliable signature of a scam.

#smishing#arnaque#Opérateurs#Vie privée#Mobile#2026#Conseil Sécurité#données personnelles

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS