"Your meter must be brought into compliance": the energy scam texts that surge every autumn

Back to the blog
1 October 202611 min read

"The text said: annual adjustment, outstanding balance of €128.40, disconnection scheduled within 48 hours. It was 6 October, and I had just received a letter from my supplier the week before about a change to my monthly payment. I paid by card on the page indicated. Two days later, €900 was gone in three transactions on an online gambling site."

This account, near-identical from one public help desk to the next, comes back every year at exactly the same time. Fake texts about electricity and gas are not the most numerous of the year — parcel delivery scams still hold that record — but they are among the most profitable for fraudsters, because they land at the precise moment when the subject is already on people's minds.

In early October, three things happen at once in millions of households: the heating goes back on, suppliers carry out their annual bill adjustments, and the press is full of energy prices. The scammer invents nothing. He simply steps into a slot that is already warm.

Woman sitting outdoors reading a message on her smartphone, looking worried, with blurred greenery in the background

Why energy is ideal terrain for smishing

Nobody really knows how much they owe

Ask the people around you the exact amount of their last electricity bill. Almost nobody knows. It is precisely that vagueness that makes the scam possible.

With a bank, you have a rough idea: you more or less know what is in your account. With an energy supplier, the amount depends on an estimated monthly instalment, an actual meter reading, a catch-up charge, sometimes a change in the regulated tariff. A "balance of €128.40" shocks no one. Neither does an "overpayment of €74". The scam works in both directions: debt and refund.

A fragmented market, impossible to keep straight

Since the market opened to competition, a French household may have:

  • an electricity supplier (EDF, Engie, TotalEnergies, Octopus, Ekwateur, Mint, etc.);
  • a gas supplier, sometimes a different one;
  • a network operator — Enedis for electricity, GRDF for gas — which is not the supplier and never sends a bill;
  • possibly a public scheme: the energy voucher (chèque énergie), MaPrimeRénov'.

Few people know who does what. A text signed "ENEDIS" announcing an unpaid bill is an administrative absurdity — Enedis does not bill households — but it goes unnoticed nine times out of ten.

A public, predictable calendar

As with tax season, the key dates are known to everyone:

PeriodReal-world eventAssociated smishing scenario
September–OctoberHeating switched back on, annual bill adjustmentsUnpaid bill, disconnection within 48 hours
October–NovemberEnergy voucher mail-out campaign"Voucher to be unlocked online"
November–FebruaryConsumption peaks, tariff news"New tariff, confirm your bank details"
All year roundRollout and maintenance of smart meters"Mandatory Linky compliance check"
SpringEnergy-efficiency renovation, public grants"Your MaPrimeRénov' grant has been approved"

Sending 400,000 "bill adjustment" texts in the first half of October is a bet on a highly likely coincidence: some of the recipients really are expecting an adjustment.

The five scenarios you'll come across this winter

1. The unpaid bill with a disconnection threat

The great classic. A precise amount down to the cents, a short deadline, an administrative tone. It plays on a concrete, seasonal fear: being left without heating.

What you need to know: in France, disconnection for unpaid electricity or gas bills is strictly regulated. It is preceded by letters and a statutory notice period, and it is prohibited during the winter truce, from 1 November to 31 March, for a primary residence. A supplier never cuts you off "within 48 hours" on the basis of a text message alone.

That single fact is enough to disqualify half the messages received between November and March.

2. The energy voucher "to be unlocked"

The chèque énergie is a genuine public scheme, paid out subject to income conditions. Since the reform of how it is awarded, some households have to submit an application — which has considerably muddied people's bearings.

The fake texts exploit that confusion: "Your €194 energy voucher is available, complete your file before…". The page asks for personal details, tax number, then bank details "for payment". The real portal is the government one; no energy voucher is ever claimed through a link in a text message.

3. The bogus meter intervention

"Your Linky meter requires a compliance check, confirm your appointment slot". Variant: "GRDF technician, mandatory inspection of your gas installation".

These messages have two possible aims. The first is standard: stealing data or extracting payment for non-existent "intervention fees" — network operator interventions listed in the basic catalogue are free of charge for the user. The second is rarer but more serious: setting up a home visit. A fake technician turns up, scopes out the premises, gets a document signed or pushes for a contract.

One good habit costs almost nothing: post the official phone numbers of your supplier and your network operator near the front door, on a simple magnetic fridge notepad or a memo board. That saves you from hunting for a number online in a hurry — and landing on a booby-trapped page.

4. The "new tariff" that asks for your bank details

Lower-key, and more dangerous. The message announces a tariff change — even a reduction — and invites you to "update your bank details". No urgency, no threat: the reader drops their guard.

The goal is the direct debit mandate. With your bank details and a forged authorisation, the fraudster can set up debits. You then have 13 months to dispute an unauthorised direct debit with your bank, and 8 weeks for an authorised but contested one — provided you actually look at your statements.

Man sitting in an armchair checking a text message on his smartphone in a brightly lit living room

5. The fake "cheaper energy" broker

This one is not always illegal, which makes it trickier. A text offers to "cut your bill by 30%", followed by a phone call. At the end of it, either abusive cold-selling or a genuine contract switch signed remotely without your having grasped the terms.

A useful reminder: cold calling about energy-efficiency renovation is banned in France, and commercial cold calling is restricted to set time slots and governed by registration on Bloctel. A text followed by a call on this subject is, at the very least, the sign of an operator who ignores the law.

The technical giveaways that expose the message

The sender proves nothing

This is the point most victims discover too late: the name displayed as the sender of a text message can be faked. The technique, known as sender ID spoofing, makes it possible to display "EDF", "ENEDIS" or "Service-Public".

Worse: on most phones, a text spoofing a sender name already present in your history is filed in the same conversation thread as legitimate messages. You see your genuine June bill reminder, and right underneath it, the scam. That is the mechanism that caught out thousands of people during the campaigns targeting pension funds in 2026.

Since then, a system for filtering texts with spoofed sender IDs (MAN, the number authentication mechanism) has been rolled out by French operators for calls, and work is continuing on the messaging side. Useful, but not foolproof: never treat the sender's name as proof.

The link, the only genuinely observable element

Fake addresses revolve around a handful of patterns:

  • a misleading subdomain: edf.facture-client.xyz — what matters is what comes immediately before the .xyz, not the word "edf";
  • a URL shortener (bit.ly, tinyurl) that hides the destination;
  • an unexpected extension: .top, .icu, .click, .shop;
  • one hyphen too many: service-edf-client.com.

As for the real sites: EDF uses edf.fr, Engie engie.fr, Enedis enedis.fr, GRDF grdf.fr, and the energy voucher goes through the official government portal. Everything else deserves suspicion.

The payment method requested tells you everything

An energy supplier never asks for payment by gift card, cryptocurrency, instant transfer to a personal account or money transfer app. If the payment method is exotic, the case is closed.

The three-step reflex

Do nothing from within the text message

The rule fits in one sentence: don't click, don't call back, don't reply. Not even "STOP": on a fraudulent message, replying simply confirms that the number is live.

Verify through a channel you chose yourself

Open your supplier's official app, or type the address into the browser yourself, or call the number printed on an old paper bill. A real unpaid balance always shows up in your online account. A real meter intervention appears in your Enedis or GRDF tracking.

For households that keep few records, storing twelve months of bills in an A4 expanding file folder makes a big difference: it is often the only place where the genuine customer service number appears, out of reach of a search engine polluted by fake ads.

Report it, even when you weren't a victim

Two actions, thirty seconds:

  • forward the text to 33700, the official reporting platform run with the operators, then send the sender's number when the automatic reply asks for it;
  • report the fraudulent address on Phishing Initiative or via the Cybermalveillance.gouv.fr platform, which also publishes free how-to fact sheets.

If you have suffered a financial loss, add: immediately contacting your bank to block the card, filing a police complaint, and reporting on Perceval (the government service for bank card fraud).

Young woman with curly hair looking at her smartphone with a worried expression in the street

Shrinking the attack surface before winter

Limit leaks of your phone number

Energy campaigns often target purchased lists: online comparison sites, renovation quote forms, prize draws. Every bill simulation filled in on the fly feeds a database.

Two simple measures:

  • reserve your main number for family, friends and essential organisations, and use a second number (a pay-as-you-go SIM card or a secondary app-based number) for commercial forms;
  • exercise your right to object under the GDPR with the companies that cold-call you: they must stop processing your data, and the CNIL can be called in if they refuse.

Lock down what you can on the phone

Built-in filtering is improving: Android is strengthening its detection of fraudulent messages in France, and iOS lets you sort unknown senders into a separate tab. Turn on:

  • filtering of unknown senders (Settings → Messages on iPhone);
  • protection against dangerous links in your browser;
  • block + report rather than simply deleting, which teaches the system nothing.

For households with older devices, a USB mains charger with surge protection or a decent power bank at least prevents the flat-battery panic that pushes people to answer in a rush, without thinking, before the screen goes dark.

Talk about energy as a family, once, before December

Older people are over-exposed: more of them fear being cut off, more of them have an old, poorly identified contract, more of them pay by cheque or payment slip and are therefore less used to paying online.

A ten-minute conversation is often enough. Three sentences to remember:

  1. No supplier ever cuts off your energy via a text message.
  2. No public body ever asks for your bank details through a link in a text.
  3. If in doubt, do nothing and call someone you trust.

For those who like having something in writing, a practical guide to digital scams left on the living room table is often consulted more than a spoken explanation — and it gives you a pretext to raise the subject again.

What changes in 2026, and what doesn't

Three developments are real: operators and manufacturers are stepping up automatic detection, anti-smishing filters are appearing, including from third-party vendors, and awareness campaigns are multiplying — the Banque de France, for its part, notes an increase in manipulation-based fraud, where the victim carries out the transaction themselves.

What doesn't change is the underlying logic: fraud does not target your technology, it targets your context. An energy text sent in July works badly. The same one, sent on 8 October after an article about rising tariffs, works very well.

Hence the only truly robust reflex, the one that survives every change of scenario: when a message talks about money, switch channels. Close the text, open the app or pull out the paper bill, and check elsewhere. Thirty seconds against several hundred euros — and a distinctly more peaceful winter evening.

#smishing#arnaque#fraude#Sécurité#Conseil Sécurité#SMS#données personnelles#2026

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS