"The text said I had an overpayment of €384.52. Down to the cents. I had just received my tax assessment ten days earlier, and I had indeed got a refund the year before. I filled in the form: name, date of birth, tax number, then my bank details 'for the transfer'. The next day, two €49 charges on a foreign website."
This account, heard almost word for word at a drop-in centre helping people with official paperwork, captures the essence of the mechanism. Unlike the fake parking-fine text, the fake tax message doesn't rely on raw panic. It relies on something far more effective: a calendar shared by 40 million households. Everyone knows that assessments arrive in the summer, that overpayment refunds land at the end of the summer, and that the withholding tax rate is recalculated at the end of the year.
The fraudster doesn't need to know anything about you. He just needs to know what month it is.

Why the tax angle works better than the others
A public calendar, therefore an exploitable one
Most smishing campaigns have to guess the context: your parcel, your bank, your health insurer. Taxation, by contrast, is nationally synchronised. The key periods are announced in advance by the Direction générale des Finances publiques (DGFiP) and picked up by the entire press:
- spring: the income tax return season opens;
- July–August: tax assessments are published online;
- late July to early August: refund transfers for households that paid too much;
- September: adjustment of the withholding tax rate;
- autumn: property tax deadlines, then residence tax on second homes.
Sending 500,000 "refund available" texts in the first week of August amounts to betting on a coincidence with very high odds. A share of the recipients really is expecting a transfer.
Two emotions for the price of one
Tax smishing comes in two complementary families:
| Type of message | Psychological lever | Real objective |
|---|---|---|
| "Overpayment / refund pending" | Gain, opportunity, short deadline | Capture bank details and card data |
| "Unpaid balance, surcharge, seizure notice" | Fear of penalties, urgency | Force an immediate card payment |
| "Update your personal online account" | Administrative routine | Steal tax login credentials |
| "Adjustment of your withholding rate" | Technical jargon, confusion | Collect a complete identity file |
The first type yields bank details that can be reused for months. The second yields an immediate payment. The third is the most dangerous in the long run: with a tax number and a password, a fraudster can view your situation, change the bank account used for refunds, and retrieve civil status documents usable to take out credit.
Vocabulary nobody really masters
"Overpayment", "declaratory status notice", "tax roll", "non-personalised rate", "current-year instalment": tax jargon is opaque enough that people don't dare to judge whether a message is plausible. When a sentence looks incomprehensible in a text from your bank, you get suspicious. When it looks incomprehensible in a text about tax, you assume that's normal.
What the DGFiP really sends by SMS
This is the most useful point to remember, and it is simple.
The tax authority does indeed use text messages, but within a very narrow scope, essentially for information:
- deadline reminders for filing or payment, with no link to a data entry form;
- one-time codes as part of the strengthened authentication of your personal online account;
- confirmations of a procedure you have already completed yourself.
Here, on the other hand, is what it does not do:
The tax authority never asks for your bank details, your card number, your password or a copy of your ID by text message or email. An overpayment refund is paid automatically into the account already known to the administration, with no action required on your part.
That statement appears, in similar wording, on impots.gouv.fr and in communications from Cybermalveillance.gouv.fr. It is enough to rule out virtually every fraudulent message.
A second marker: there is no refund button. If you have overpaid, the transfer arrives. If it can't arrive because your bank details are out of date, you receive a cheque letter by post. Never a link.
The five signs that give away a fake tax text
1. An amount with cents
Counter-intuitive, but central. Fraudsters have worked out that a round figure ("€400") sounds fake, so they write "€384.52". It is precisely that level of precision, in an unsolicited text, that should raise the alarm: the tax office does not itemise a balance in a 160-character message.
2. A short, arbitrary deadline
"Within 48 hours", "before 3 October", "failing which your file will be closed". Tax law works with public due dates that are the same for everyone, not with personal countdowns sent by text.
3. The link address
Look at what comes immediately before the first /. Official services are hosted on .gouv.fr domains. Everything else — impots-remboursement.com, dgfip-service.net, impots.gouv.fr.secure-paiement.xyz — is fraudulent. The last example is the most devious: there, impots.gouv.fr is merely a subdomain of a third-party site.
4. The displayed sender
A text message can show a sender name, including a spoofed one: this is sender spoofing. The fact that a message appears in the same conversation thread as a legitimate text received months earlier therefore proves nothing. It is a structural weakness of SMS, not a bug in your phone.
5. A request for card payment
Taxes are paid by direct debit, bank transfer, or through the secure online account. A page asking for a 16-digit card number to settle a "€32 surcharge" is fake, without exception.

The right procedure, in three moves
Move 1: never start from the message
This is the only rule that holds up against every variant of the scam, present and future. A text may inform you that something is happening; it must never be your route of access. You close the message, you type the official site's address into your browser yourself, or you open the app installed from your phone's store.
If the information is genuine, it will be in your personal online account. If it isn't there, it's false. There is no third possibility.
Move 2: check from a comfortable device
Many mistakes come down to the device: on a six-inch screen, on the underground, a truncated address is unreadable. Doing the check on a computer, or on a tablet with an adjustable tablet stand that lets you read calmly, genuinely improves the quality of your judgement. This is not a minor detail: most victims say they clicked "while doing something else".
Move 3: report, then delete
Two useful, free channels:
- 33700: forward the text to this number, then send the sender's number when prompted. This is the joint reporting scheme run by French mobile operators.
- Cybermalveillance.gouv.fr and signal.conso.gouv.fr to document the campaign; Phishing Initiative to get the URL blacklisted.
Only then should you delete it. But if you have clicked, keep a screenshot: it will be useful when filing a complaint.
If you filled in the form
Speed matters more than precision. In order:
- Block your card through your bank's app or the interbank hotline (0 892 705 705). Also ask for any suspicious SEPA direct debit to be blocked.
- Change the password of your impots.gouv.fr personal account, and of every account that shared that password. If the task feels daunting, a password manager solves the problem once and for all.
- Check your bank details in your tax account: fraudulent access may have changed the refund account.
- File a complaint at a police station, with the gendarmerie, or by submitting an online pre-complaint. Banks often require this filing before processing a refund.
- Request reimbursement from your bank: French monetary and financial law provides for the refund of unauthorised payment transactions, except in cases of gross negligence. Simply entering details on a counterfeit site is not automatically gross negligence — a point on which consumer associations, including UFC-Que Choisir, regularly obtain favourable rulings.
- Watch out for identity theft for several months: you can exercise your right of access to the register of consumer credit repayment incidents held by the Banque de France.
One detail that helps: keep the paperwork for the whole process in a dedicated document filing wallet, together with printed screenshots, the date the card was blocked and a copy of the complaint. Well-organised files move noticeably faster through the claims department.
Reducing the attack surface upstream
Keeping official business separate from the rest
Tax campaigns reach everyone, but how effective they are depends on your noise level. If your number receives forty marketing messages a month, a fake tax text disappears into the crowd and looks legitimate. Two simple measures:
- register your line with Bloctel to block cold calling;
- reply STOP to legitimate marketing texts, which are legally required to include that mechanism.
Enabling strengthened authentication
The impots.gouv.fr personal account offers validation by a code sent to your phone or your email. Once enabled, it makes a stolen password far less usable. For the most sensitive accounts, a physical FIDO2 security key removes the point of phishing altogether: there is nothing to copy out, so nothing to steal remotely.
Installing updates
In 2026 Google strengthened the detection of fraudulent messages in the Messages app on Android in France, with certain suspicious texts automatically sorted out. Apple, for its part, offers filtering of unknown senders in the Messages settings. These filters are no substitute for vigilance, but they reduce the volume reaching your screen — provided the system is up to date.
Helping those who are less confident
The most exposed groups are not necessarily the oldest: they are the people who handle their paperwork in a hurry, often from a phone. A ten-minute conversation with someone close to you is worth more than any setting. For those who prefer print, a practical guide to online scams left next to the landline often has more impact than a verbal reminder.
Key takeaways
| Situation | What to do |
|---|---|
| Text announcing a refund | Nothing to do: an overpayment is paid out automatically |
| Text announcing a debt with a payment link | Check only in your personal online account, never via the link |
| Request for bank details, card number or ID | Certain fraud, whatever sender is displayed |
Link that does not end in .gouv.fr before the / | Fraud |
| You have clicked | Block the card, change the password, file a complaint, claim from the bank |
Tax smishing is not going to disappear: it is too profitable and too easy to schedule around the calendar. But it rests entirely on a confusion that you can eliminate in one stroke. The tax authority informs you; it does not lead you by the hand. The moment you take back control of the route of access — your browser, your app, the address you type yourself — the fraudulent message loses its only weapon.
Useful sources: impots.gouv.fr (section "Attention aux tentatives d'escroquerie"), Cybermalveillance.gouv.fr, DGCCRF, the 33700 platform, Banque de France (incident registers), UFC-Que Choisir.



