"The text landed in my bank's conversation thread. Right below the message that had confirmed my transfer the week before. Same sender name, same thread, same everything. I thought: if it's filed there, it comes from them. I clicked the link, I entered my credentials to 'lift the suspension'. Forty minutes later, three transfers left my account."
That detail — the fake message slipping into the genuine conversation thread — is what makes this type of scam so formidable. The most common piece of advice, "check the sender", becomes useless: the displayed sender is your bank's. And because our phones automatically group text messages by sender name, the fraudulent message inherits the credibility of every legitimate message that came before it.
The technique has a name: sender address spoofing, or simply spoofing. It has been widely documented in France during waves of fake texts attributed to organisations such as Agirc-Arrco, Assurance Maladie or the major banking networks. This is not a hack of the organisation concerned, nor a leak from your phone: it is a structural weakness in the way the sender name of a business text message is carried across networks.

Why a sender name is not proof
The "OADC": a text field, not a verified identity
When a company sends you a business text message, it doesn't send it from a phone. It goes through a bulk messaging platform, which injects the message into the network with a custom sender field. In telecom jargon, this is the OADC (Originating Address) or alphanumeric Sender ID.
That field accepts text: "MyBank", "AMELI", "CHRONOPOST". Historically, no technical control required that text to match the real entity paying for the send. An unscrupulous aggregator, a fourth-tier reseller in a chain, a platform hosted outside Europe: at every link, the ability to write any name at all in that field existed.
The result is counter-intuitive for users:
| What you think you're checking | What you're actually checking |
|---|---|
| The sender's identity | A self-declared string of characters |
| A secure official channel | A field filled in freely by the sender |
| That your bank is talking to you | That someone typed the bank's name |
Automatic grouping does the rest of the work
Both Android and iOS sort messages by sender. If two messages carry the same Sender ID, they appear in the same conversation — the phone has no way of telling the real origin apart. A properly spoofed fake text therefore ends up filed alongside the genuine ones, with the full history sitting above it.
This is a design flaw in convenience, not in security. And it is exactly the psychological lever the scammer exploits: they don't need to convince you, the context does it for them.
What France has put in place since 2025
The number authentication mechanism
The so-called Naegelen law of 24 July 2020, aimed at regulating telephone canvassing and fighting fraudulent calls, gave rise to an authentication system overseen by Arcep: operators must now cut off calls and messages whose originating number cannot be authenticated, particularly when they come from abroad while displaying a French number. This mechanism (MAN) came into force in stages from October 2024 for calls, then was extended to text-message-related uses.
The effects are real: a significant share of fraudulent campaigns sent from abroad with a spoofed French number is now filtered out before it reaches your screen.
Why fake texts keep coming through
Three reasons explain why the problem isn't solved.
- Alphanumeric names are harder to authenticate than a number. A Sender ID is not tied to a phone line; its legitimacy rests on contractual declarations between the advertiser, the aggregator and the operator. Registries of protected Sender IDs are making progress, but coverage is not complete.
- Scammers work around it by switching channels. Rather than spoofing "MyBank", they send from an ordinary mobile number (06, 07) a message that claims to come from the bank. The text then doesn't file itself into the right thread — but it gets through the filters.
- Rogue base stations exist. IMSI-catcher or "SMS blaster" type equipment makes it possible to inject messages locally without going through the operator's network, and therefore with no authentication check at all. Several European countries have reported seizures of this kind of hardware transported in a vehicle or a backpack.

The only check that stands up to spoofing
If the sender name isn't reliable, what's left? One simple rule, and only one: never verify a piece of information inside the message that gave it to you.
The separate channel rule
A text tells you about a suspicious debit, a suspended account, a pending refund? Close the message. Open, yourself:
- the official app of the organisation, installed from the store;
- or the official website, typing the address by hand;
- or the phone number printed on the back of your bank card or on a paper letter you received previously.
If the alert is genuine, it will appear in your customer account. No serious French organisation relies on a text message link to reach you about a serious matter: your bank, Assurance Maladie (Ameli) and the DGFiP all point out that they never ask for credentials, full bank details or a validation code by message.
The warning signs that still apply
Even when spoofed, a fraudulent text leaves traces.
- The link. Hover over it without clicking (a long press on iOS/Android shows the full URL). A domain that looks close but isn't exact — superfluous hyphens, an unexpected suffix, a subdomain imitating the brand — is disqualifying.
- The deadline pressure. "Within 24 hours", "before tonight", "your file will be closed": artificial urgency is the signature of manipulation.
- The unusual request. A payment of a few cents "for validation", entering a code received elsewhere, installing an "assistance" app: three markers of a scam.
- The generic wording. "Dear customer", the absence of your name, or conversely a correct name but nothing that only the organisation could know.
A useful principle to remember: the more a message pushes you to act fast, the less it deserves to be believed fast.
Reducing your attack surface, concretely
You can't stop a scammer from writing your bank's name. You can, however, limit the number of messages that reach you and the fallout from a mistake.
On the phone side
- Turn on built-in filtering. On Android, Google Messages' scam protection was strengthened in France in 2026: it relies on local analysis of text patterns and flags suspicious messages without sending their content anywhere. On iOS, "Filter Unknown Senders" isolates messages from people not in your address book in a separate tab.
- Update the operating system. Anti-smishing protections arrive through updates. A phone stuck on an old version doesn't benefit from them.
- Lock the SIM card. An active SIM PIN code stops a stolen phone from becoming a receiver for your validation texts. For sensitive lines, a backup microSD card or a simple paper password notebook kept outside your bag lets you keep a record of your logins without storing everything on the device.
On the account side
- Favour app-based authentication over text messages wherever the organisation allows it. A physical FIDO2 security key for your most critical accounts — main email, password manager — makes any code interception pointless, since there is no longer a code to intercept.
- Centralise your passwords. A reputable password manager will refuse to fill in your credentials on a domain that doesn't match: it's a barrier that works even when your vigilance slips, and one of the few automatic safeguards against phishing.
- Set low limits on transfers and online payments, adjustable on a one-off basis from the app. A €500 cap turns a disaster into an incident.
On the family side
The people most targeted by campaigns impersonating a pension fund or Assurance Maladie are often the oldest. Going through the settings with a relative beats a long lecture. For seniors using a large-button phone, many of which have no filtering at all, the separate channel rule — hang up and call back yourself — should be written on a piece of paper stuck near the handset, along with the bank's real number. Some practical French-language guides to scam prevention do this educational work very well and are easy to read together.

What to do if you receive a spoofed text
Immediate steps
- Don't click, don't reply. A reply, even "STOP", confirms to a fraudulent campaign that a human is reading the line (not to be confused with the legitimate STOP of a regulated commercial marketing message).
- Forward the message to 33700, the national reporting scheme for unwanted text messages run by the Signal Spam association and the operators. A return text will ask you for the sender's number: send it on.
- Report the phishing site on the Phishing Initiative platform or via cybermalveillance.gouv.fr, which also directs you to the appropriate support.
- Warn the impersonated organisation. Most banks and government bodies have a dedicated address for impersonation attempts. It is this reporting that gets the fraudulent Sender ID taken down.
If you clicked, or entered something
The order matters.
- Call your bank immediately on the number on the back of your card and have the card blocked. The blocking service is reachable 24/7.
- Change the password concerned, from another device if possible, and check that no phone number or recovery address has been added to your account.
- File a complaint at a police station or gendarmerie: it is an essential document for disputing the transactions.
- Dispute the debits in writing. The French monetary and financial code (articles L.133-18 onwards) provides for reimbursement of unauthorised transactions, except in cases of gross negligence on your part — a notion assessed case by case, and on which recent Cour de cassation case law has shown attentiveness to situations where the scammer presented a convincing appearance of the bank. Sender name spoofing is a point to raise in your claim.
- Keep the evidence. Screenshots of the text, timestamps, the sender's number, statements. A tidy file carries more weight than a spoken account.
Key takeaways
Sender spoofing shifts the problem: it is no longer about spotting a badly written message from a strange number, but about refusing to let a message — however well presented — serve as its own proof of legitimacy.
- The displayed name of a business text message sender is self-declared, not certified.
- The grouping of conversations on your phone has no authentication value whatsoever.
- France's number authentication mechanism filters a great deal, but doesn't cover every channel.
- The only reliable defence is the separate channel: close the message, open the app yourself or call the number on the back of your card.
- Low limits, app-based or physical-key authentication and a password manager limit the damage when your attention lapses — which happens to everyone.
A good reflex fits in one sentence: a message can look like your bank, it cannot look like your app. That is where an alert is verified, and nowhere else.



