"Never share this code with anyone": why scammers call you right after making you receive a text message

Back to the blog
3 October 202612 min read

"I got a text message: your verification code is 842 319, do not share it with anyone. I hadn't asked for anything. Thirty seconds later, a call: 'Hello, this is your bank's security department, we've blocked a login attempt from Lille, can you confirm the code you've just received so we can cancel the transaction?' I read out the code. There was a second text, and I read out the second code too. My transfer to a foreign account went through that very evening. €4,200."

This sequence — an unsolicited code, then a call within the minute — is currently one of the most effective scam mechanics in France. It relies on no technical hacking: no interception, no spyware, no network flaw. The scammer doesn't steal the code, they get you to say it. And they get you to say it because the victim believes, in good faith, that they are protecting their account.

The Banque de France, in its work on payment fraud, describes this family under the name manipulation fraud: the victim personally carries out the act that dispossesses them. This is precisely the category showing a sharp rise in recent months, while "classic" stolen-card fraud is declining.

Hands holding a smartphone displaying a text message conversation in dim light

What a six-digit code really contains

It isn't a verification code, it's a signature

The vocabulary misleads us. We talk about a "verification code", a "confirmation code", a "security code" — all phrasings that suggest some administrative box to tick. In reality, that code is the transaction.

When your bank sends you a code to validate a transfer, the code doesn't accompany the transfer: it triggers it. When WhatsApp sends you a code during installation, that code transfers your account, along with your groups and your identity, to whichever phone enters it. When your mobile operator sends you a code for a SIM change, that code moves your line.

A one-time code carries the same legal and practical weight as a signature at the bottom of a contract. Reading it out loud means signing without seeing what you're signing.

Three main families of codes, three levels of damage

Type of codeWhat it authorisesConsequence if dictated
Banking code (3-D Secure, transfer validation)A specific payment or transferImmediate debit, often irreversible
Messaging code (WhatsApp, Signal, Telegram)Migration of the account to another deviceImpersonation of your identity with all your contacts
Operator / number-porting / eSIM codeTransfer of your phone numberLoss of the line, then cascading resets of all your accounts

The third case is the most serious and the least well known. If your number goes, the scammer receives all your future codes: bank, tax authority, email, social media. In the jargon, this is called SIM swapping. In France, operators have tightened their procedures, but the human link — you, on the phone — remains the point of entry.

Why the call comes within the minute

The code has a five-minute lifespan

That's the whole secret behind the timing. A one-time code generally expires between 2 and 10 minutes after being sent. So the scammer has no choice: they must reach you immediately, before the code dies and before you have time to think.

This technical constraint creates the impression of responsiveness that makes the scam credible. You receive a strange text message, and within seconds someone calls to talk to you about it. The brain draws a natural conclusion: "they really are monitoring my account in real time, so this must be my bank."

It's the opposite. The call is fast because the scammer is in a hurry, not because they are vigilant.

The order of operations is the reverse of your intuition

In your mental picture, the call comes first and the code second: an adviser contacts you, then sends you a code. In the scam, it is strictly the reverse:

  1. The scammer already has your phone number and some data (name, bank, sometimes the last four digits of your card).
  2. They enter your number on the real login page of your real bank, or initiate a genuine transfer request.
  3. The bank's genuine system sends you a genuine text message.
  4. They call you to collect the code while it is still valid.

That's why the text message is authentic, why it shows the correct sender name, and why the phrase "do not share this code with anyone" really is there. The message hasn't been faked. It has been triggered.

The number displayed proves nothing

Two techniques make the call look visually flawless.

Caller ID spoofing makes your screen show the official customer service number, the one printed on the back of your bank card. Since 2023, French law has required operators to implement a number-authentication mechanism to limit this practice, and blocks are indeed in place for calls from abroad displaying a French number. The filter isn't watertight.

Hijacking the text message thread makes the fake message appear in the same conversation as the genuine ones, because the scammer reuses the same alphanumeric sender name. The legitimate earlier messages then act as a guarantee for the fraudulent one. Recent campaigns targeting supplementary pension funds worked on exactly this principle.

Practical conclusion: neither the number displayed, nor the position of the text message in your history constitutes proof of identity.

The sentence that settles everything

There is a single rule, with no exceptions, that renders this attack entirely useless:

No bank adviser, no public service agent, no mobile operator technician, no security department will ever ask you to read, dictate, type or pass on a code received by text message. Ever. Under no circumstances. Including "to cancel a fraudulent transaction".

This rule has an enormous advantage: it requires no technical skill. You don't have to work out whether the call is legitimate, whether the number is authentic, whether the situation is plausible. The request itself is the warning sign. If someone asks you for a code, it's a scam — full stop.

It's also the sentence to pass on to an elderly relative, a teenager or an employee: a single, memorable instruction that isn't up for negotiation. Prevention associations recommend writing it down in black and white. A simple magnetic notepad on the fridge, with the sentence and the real customer service number copied out by hand, often works better than a long explanation.

Hand holding a smartphone showing the message inbox, with a blurred green plant in the background

The variants you don't see coming

"To prove you really are the seller"

On classified-ad platforms, a fake buyer explains that they're going to send you a code to "check that the listing really is yours" or "secure the transaction". The code is actually one for creating a WhatsApp account or a payment wallet in your name. No serious platform works that way: verification always happens inside the app, never by dictation.

"Your parcel — confirm the collection code"

Parcel collection codes genuinely exist at pickup points. Scammers latch onto them: a text message announces a delivery problem, a call asks for the "collection code", which is in fact a banking code. The confusion in vocabulary does all the work.

The code read out by a synthetic voice

Some campaigns no longer use a human operator: an automated voice system, with a neutral voice and hold music, asks you to type the code on your phone's keypad. The absence of a person on the line is paradoxically reassuring: you don't feel like you're talking to a scammer. The DTMF tones are decoded instantly at the other end.

The double code

A two-step transfer requires two codes. The scammer asks for one, then explains that "the first one didn't go through" and asks for a second. The first served to add a payee, the second to execute the transfer. If you're asked for a second code, you're not correcting a mistake: you're authorising a second transaction.

The settings that reduce the attack surface

Turn off code previews on the lock screen

If message previews appear on your lock screen, anyone holding your phone for a few seconds — on public transport, in a waiting room, after a snatch theft — can read your codes without unlocking it.

  • Android: Settings → Notifications → Notifications on lock screen → hide sensitive content.
  • iPhone: Settings → Notifications → Show Previews → "When Unlocked".

Along the same lines, a privacy screen protector for smartphones limits side-angle viewing of your screen in public places — especially useful for anyone who checks their bank account on the train.

Choose an authenticator app over text messages

Whenever a service offers it, replace code delivery by text message with an authenticator app (codes generated locally) or, better still, a physical security key. The code then becomes impossible to pass on over the phone without a physical action on the device. For genuinely critical accounts — your main email, your bank account, your identity provider — a FIDO2 security key simply removes any possibility of dictating anything at all.

Lock down number porting and your SIM card

Two little-known but highly effective settings:

  • Enable the SIM card PIN (and change it: default codes like 0000 or 1234 are still around). Without a PIN, a SIM taken out of a stolen phone will receive your codes in any device.
  • Ask your mobile operator, via your online account, to block number-porting or eSIM requests without enhanced verification. The arrangements vary from one operator to another; it's a question worth putting to customer service.

Keep the real numbers off your phone

The most useful reflex is also the simplest: hang up and call back yourself. Not by calling back the incoming number (it can be spoofed), but by dialling the number shown on the back of your bank card, on a paper statement or in the official app.

For an elderly parent, a paper phone directory with the real numbers — bank, health insurer, doctor, pension fund — written down once and for all avoids having to search in a panic. It's also what makes "I'll call you back" possible without stress.

Man sitting holding a smartphone in his hands and reading a text message conversation on the screen

You've dictated a code: the first thirty minutes

The order matters, and so does the time.

  1. Hang up, even mid-sentence. Don't negotiate, don't explain.
  2. Call your bank's card-blocking number (the one on the back of the card) or use the blocking feature in the official app. For cards, the interbank blocking service is available 24/7 on 0 892 705 705.
  3. Stop the transfer if it hasn't been executed: some instant transfers can no longer be recovered, but a standard transfer can sometimes be halted.
  4. Change the password for the account concerned from another device, and log out of all active sessions.
  5. Check the registered payees on your bank account, as well as email forwarding rules and recovery phone numbers: a scammer often installs a back door before leaving.
  6. Report the text message by forwarding it to 33700 (a free service run by French operators) and file a complaint online or at a police station. On the cybersecurity side, Cybermalveillance.gouv.fr points you to the right contacts, and Info Escroqueries can be reached on 0 805 805 817.

On the legal front, recent case law from the Cour de cassation has tightened the screws on banks: the mere fact that a victim passed on a code is not automatically enough to establish the gross negligence that would justify refusing reimbursement, especially when the fraud involved a convincing spoof of the bank's number. So it's essential to document everything: screenshots of the text messages, the exact time of the call, the number displayed, the content of the exchange. A notebook kept next to the phone, in which you write the date, time and number as soon as a suspicious call ends, carries far more weight than a memory reconstructed three weeks later.

What's changing in 2026

Two developments are working in users' favour.

Mobile operating systems now include on-device detection of fraudulent messages: content analysis on the device, quarantining of unknown senders, explicit warnings about suspicious links. Google has extended these features to France, and third-party developers offer anti-smishing filters on iPhone via the message filtering API. These tools reduce the noise, but they can do nothing against the attack described here: the text message is authentic, it's the call that lies.

In parallel, the fight against caller ID spoofing is making progress, with the number-authentication mechanism imposed on operators. Here again, the filter remains partial — particularly for mobile calls from abroad.

So the last line of defence remains human, and it's very simple. A code received by text message is never dictated, never typed on a phone keypad, never sent via WhatsApp, never copied into a form opened from a link. It is entered only in the app or on the site you opened yourself, for a transaction you have just initiated. If you haven't initiated anything, that code belongs nowhere but in your bin.

And if you receive a code you didn't ask for, it isn't a glitch: it's someone trying to get into one of your accounts, right at that moment. The right reflex isn't to wait for the call. It's to go and change the password for the service concerned.

#smishing#Sécurité#arnaque#fraude#données personnelles#Mobile#2026#Conseil Sécurité#piratage

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS