"A €384 refund is waiting for you": the tax scam texts that resurface with every tax assessment

Back to the blog
30 September 202610 min read

"The text said I had an overpayment of €384.52. Down to the cents. I had just received my tax assessment ten days earlier, and I had indeed got a refund the year before. I filled in the form: name, date of birth, tax number, then my bank details 'for the transfer'. The next day, two €49 charges on a foreign website."

This account, heard almost word for word at a drop-in centre helping people with official paperwork, captures the essence of the mechanism. Unlike the fake parking-fine text, the fake tax message doesn't rely on raw panic. It relies on something far more effective: a calendar shared by 40 million households. Everyone knows that assessments arrive in the summer, that overpayment refunds land at the end of the summer, and that the withholding tax rate is recalculated at the end of the year.

The fraudster doesn't need to know anything about you. He just needs to know what month it is.

Young woman in a red dress checking her smartphone, seated at a table with a coffee cup

Why the tax angle works better than the others

A public calendar, therefore an exploitable one

Most smishing campaigns have to guess the context: your parcel, your bank, your health insurer. Taxation, by contrast, is nationally synchronised. The key periods are announced in advance by the Direction générale des Finances publiques (DGFiP) and picked up by the entire press:

  • spring: the income tax return season opens;
  • July–August: tax assessments are published online;
  • late July to early August: refund transfers for households that paid too much;
  • September: adjustment of the withholding tax rate;
  • autumn: property tax deadlines, then residence tax on second homes.

Sending 500,000 "refund available" texts in the first week of August amounts to betting on a coincidence with very high odds. A share of the recipients really is expecting a transfer.

Two emotions for the price of one

Tax smishing comes in two complementary families:

Type of messagePsychological leverReal objective
"Overpayment / refund pending"Gain, opportunity, short deadlineCapture bank details and card data
"Unpaid balance, surcharge, seizure notice"Fear of penalties, urgencyForce an immediate card payment
"Update your personal online account"Administrative routineSteal tax login credentials
"Adjustment of your withholding rate"Technical jargon, confusionCollect a complete identity file

The first type yields bank details that can be reused for months. The second yields an immediate payment. The third is the most dangerous in the long run: with a tax number and a password, a fraudster can view your situation, change the bank account used for refunds, and retrieve civil status documents usable to take out credit.

Vocabulary nobody really masters

"Overpayment", "declaratory status notice", "tax roll", "non-personalised rate", "current-year instalment": tax jargon is opaque enough that people don't dare to judge whether a message is plausible. When a sentence looks incomprehensible in a text from your bank, you get suspicious. When it looks incomprehensible in a text about tax, you assume that's normal.

What the DGFiP really sends by SMS

This is the most useful point to remember, and it is simple.

The tax authority does indeed use text messages, but within a very narrow scope, essentially for information:

  • deadline reminders for filing or payment, with no link to a data entry form;
  • one-time codes as part of the strengthened authentication of your personal online account;
  • confirmations of a procedure you have already completed yourself.

Here, on the other hand, is what it does not do:

The tax authority never asks for your bank details, your card number, your password or a copy of your ID by text message or email. An overpayment refund is paid automatically into the account already known to the administration, with no action required on your part.

That statement appears, in similar wording, on impots.gouv.fr and in communications from Cybermalveillance.gouv.fr. It is enough to rule out virtually every fraudulent message.

A second marker: there is no refund button. If you have overpaid, the transfer arrives. If it can't arrive because your bank details are out of date, you receive a cheque letter by post. Never a link.

The five signs that give away a fake tax text

1. An amount with cents

Counter-intuitive, but central. Fraudsters have worked out that a round figure ("€400") sounds fake, so they write "€384.52". It is precisely that level of precision, in an unsolicited text, that should raise the alarm: the tax office does not itemise a balance in a 160-character message.

2. A short, arbitrary deadline

"Within 48 hours", "before 3 October", "failing which your file will be closed". Tax law works with public due dates that are the same for everyone, not with personal countdowns sent by text.

3. The link address

Look at what comes immediately before the first /. Official services are hosted on .gouv.fr domains. Everything else — impots-remboursement.com, dgfip-service.net, impots.gouv.fr.secure-paiement.xyz — is fraudulent. The last example is the most devious: there, impots.gouv.fr is merely a subdomain of a third-party site.

4. The displayed sender

A text message can show a sender name, including a spoofed one: this is sender spoofing. The fact that a message appears in the same conversation thread as a legitimate text received months earlier therefore proves nothing. It is a structural weakness of SMS, not a bug in your phone.

5. A request for card payment

Taxes are paid by direct debit, bank transfer, or through the secure online account. A page asking for a 16-digit card number to settle a "€32 surcharge" is fake, without exception.

Hands holding a smartphone whose screen lights up the fingers in the dark

The right procedure, in three moves

Move 1: never start from the message

This is the only rule that holds up against every variant of the scam, present and future. A text may inform you that something is happening; it must never be your route of access. You close the message, you type the official site's address into your browser yourself, or you open the app installed from your phone's store.

If the information is genuine, it will be in your personal online account. If it isn't there, it's false. There is no third possibility.

Move 2: check from a comfortable device

Many mistakes come down to the device: on a six-inch screen, on the underground, a truncated address is unreadable. Doing the check on a computer, or on a tablet with an adjustable tablet stand that lets you read calmly, genuinely improves the quality of your judgement. This is not a minor detail: most victims say they clicked "while doing something else".

Move 3: report, then delete

Two useful, free channels:

  • 33700: forward the text to this number, then send the sender's number when prompted. This is the joint reporting scheme run by French mobile operators.
  • Cybermalveillance.gouv.fr and signal.conso.gouv.fr to document the campaign; Phishing Initiative to get the URL blacklisted.

Only then should you delete it. But if you have clicked, keep a screenshot: it will be useful when filing a complaint.

If you filled in the form

Speed matters more than precision. In order:

  1. Block your card through your bank's app or the interbank hotline (0 892 705 705). Also ask for any suspicious SEPA direct debit to be blocked.
  2. Change the password of your impots.gouv.fr personal account, and of every account that shared that password. If the task feels daunting, a password manager solves the problem once and for all.
  3. Check your bank details in your tax account: fraudulent access may have changed the refund account.
  4. File a complaint at a police station, with the gendarmerie, or by submitting an online pre-complaint. Banks often require this filing before processing a refund.
  5. Request reimbursement from your bank: French monetary and financial law provides for the refund of unauthorised payment transactions, except in cases of gross negligence. Simply entering details on a counterfeit site is not automatically gross negligence — a point on which consumer associations, including UFC-Que Choisir, regularly obtain favourable rulings.
  6. Watch out for identity theft for several months: you can exercise your right of access to the register of consumer credit repayment incidents held by the Banque de France.

One detail that helps: keep the paperwork for the whole process in a dedicated document filing wallet, together with printed screenshots, the date the card was blocked and a copy of the complaint. Well-organised files move noticeably faster through the claims department.

Reducing the attack surface upstream

Keeping official business separate from the rest

Tax campaigns reach everyone, but how effective they are depends on your noise level. If your number receives forty marketing messages a month, a fake tax text disappears into the crowd and looks legitimate. Two simple measures:

  • register your line with Bloctel to block cold calling;
  • reply STOP to legitimate marketing texts, which are legally required to include that mechanism.

Enabling strengthened authentication

The impots.gouv.fr personal account offers validation by a code sent to your phone or your email. Once enabled, it makes a stolen password far less usable. For the most sensitive accounts, a physical FIDO2 security key removes the point of phishing altogether: there is nothing to copy out, so nothing to steal remotely.

Installing updates

In 2026 Google strengthened the detection of fraudulent messages in the Messages app on Android in France, with certain suspicious texts automatically sorted out. Apple, for its part, offers filtering of unknown senders in the Messages settings. These filters are no substitute for vigilance, but they reduce the volume reaching your screen — provided the system is up to date.

Helping those who are less confident

The most exposed groups are not necessarily the oldest: they are the people who handle their paperwork in a hurry, often from a phone. A ten-minute conversation with someone close to you is worth more than any setting. For those who prefer print, a practical guide to online scams left next to the landline often has more impact than a verbal reminder.

Key takeaways

SituationWhat to do
Text announcing a refundNothing to do: an overpayment is paid out automatically
Text announcing a debt with a payment linkCheck only in your personal online account, never via the link
Request for bank details, card number or IDCertain fraud, whatever sender is displayed
Link that does not end in .gouv.fr before the /Fraud
You have clickedBlock the card, change the password, file a complaint, claim from the bank

Tax smishing is not going to disappear: it is too profitable and too easy to schedule around the calendar. But it rests entirely on a confusion that you can eliminate in one stroke. The tax authority informs you; it does not lead you by the hand. The moment you take back control of the route of access — your browser, your app, the address you type yourself — the fraudulent message loses its only weapon.

Useful sources: impots.gouv.fr (section "Attention aux tentatives d'escroquerie"), Cybermalveillance.gouv.fr, DGCCRF, the 33700 platform, Banque de France (incident registers), UFC-Que Choisir.

#smishing#arnaque#fraude#Sécurité#données personnelles#Conseil Sécurité#2026#SMS

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS