Your Number Is on Your Quote, Your Van and Google: The Scam Texts Targeting Tradespeople and the Self-Employed

Back to the blog
6 October 202611 min read

« Hello, this is Mr Lemoine, I got your number from your Google listing. I have an urgent job, a complete bathroom, and I'm abroad until the 20th. I can pay a deposit straight away if you send me a quote. »

The plumber who shared this exchange with us replied within fourteen minutes. It was a Friday at the end of the month, the order book was thin, the message was polite, detailed, written in flawless French. Three days later, he had handed over his bank details, a copy of his ID "for payment compliance purposes", and confirmed a six-digit code received by text "to authenticate the international payment". The transfer never arrived. His online email account, on the other hand, had changed hands.

Articles about fraudulent texts almost always focus on the private individual: the fake parcel, the fake tax demand, the fake doctor. We overlook a far more exposed and far less protected group: the self-employed, tradespeople, shopkeepers and professionals in private practice, whose mobile number is public out of professional necessity. They cannot follow the number-one piece of prevention advice — "don't share your number" — because sharing their number is their job.

Seated person reading a message on their smartphone, surrounded by other attendees

Why a business line receives far more fraudulent texts

A number that can be harvested in two clicks

A self-employed worker's mobile number can be found, effortlessly and legally, in at least eight different places:

  • the Google Business Profile and review directories (Pages Jaunes, lead-generation platforms);
  • the Insee SIRENE register, which holds company identification data, and the sites that copy it;
  • the quotes and invoices sent to dozens of clients a year, often forwarded by email to third parties;
  • the recruitment ads or second-hand equipment listings published in their name;
  • the signage on the vehicle, photographed in the street;
  • the site boards, the business cards left in shops;
  • the online quote platforms, which resell or share contact details with partners;
  • the data breaches at management, point-of-sale or appointment-booking software providers.

None of these sources involves hacking. Put end to end, they turn a business number into public data, stable over ten or fifteen years, and linked to an identified trade. That last piece of information changes everything: the scammer isn't writing to you at random, they know you're a roofer, a self-employed nurse or a mechanic.

Trade-based targeting makes the fake message believable

A text saying "your parcel is on hold" triggers suspicion because it doesn't match anything specific. A text saying "your URSSAF compliance certificate is about to expire, your client will no longer be able to pay you" lands on an administrative reality the tradesperson knows, dreads and doesn't fully control. Social engineering works when a message looks like an overdue task.

The levers used are nearly always the same:

LeverTypical wordingWhy it works
Cash flow"€2,480 transfer rejected, update your bank details"Unpaid invoices are the structural anxiety of the self-employed
Compliance"Compliance certificate expired", "Kbis update"Fear of losing a contract or a major client
Opportunity"Urgent job, immediate deposit"A thin order book lowers your guard
Work tool"Your invoicing account will be suspended"Total dependence on a piece of software or a platform
Mobility"Unpaid fine on a business vehicle"Fleet, parking, low-emission zones

The five scenarios circulating in 2026

1. The rushed, generous fake client

The oldest and the most effective. The prospect arrives by text, never by phone — they're "abroad", "travelling", "deaf", "in a meeting". They ask for a quote, accept it without haggling, offer a large deposit. Then the complication appears: a payment "by money order", a surplus to be passed on to a "haulier", an unfamiliar payment platform to approve.

The most reliable red flag isn't the vocabulary, now impeccable thanks to automated writing tools. It's the persistent refusal to talk on the phone combined with an anomaly in the payment chain. A client who won't speak to you but wants to send you money fast is a warning sign, not a lucky break.

2. The fake social security or tax body

Waves of fake texts attributed to URSSAF, to the Direction générale des Finances publiques or to supplementary pension bodies have been documented for several years; the DGFiP and URSSAF regularly remind visitors on their websites that they never ask for bank details by text or via a link. For the self-employed, the most dangerous variant is the contribution refund: a plausible overpayment, a credible amount, a form demanding an IBAN and proof of identity.

The habit to build once and for all: no organisation can be verified from within its own message. Leave the text, open the app or the online account through a saved bookmark, and check whether the request actually exists there.

3. Supplier fraud, text message edition

Traditionally sent by email, it is migrating to text because the mobile is checked between two jobs, with no computer, often with dirty hands and three minutes of attention. The message announces a change of bank details for a materials supplier, a subcontractor, a plant-hire firm. It may quote a genuine order number, obtained through a data breach or a compromised mailbox.

The defence is organisational, not technical: any change of IBAN is confirmed by calling back the number you already had, never the one given in the message. Many self-employed workers keep their reference supplier contacts in a professional logbook stored in the van, precisely so as not to depend on a phone that can lie.

4. Hijacking the email or invoicing account

Here the text isn't the destination but the tool. The scammer tries to reset access to your business mailbox, your invoicing software or your business listing. The legitimate system sends you a genuine one-time code — and a fake "technical support" team asks you for it within the minute, by text or by phone.

What the attacker gains is worth far more than the money from one job: client history, quotes, bank details, and the ability to write to your customers in your name. On a business line, two-factor authentication through a dedicated app, or even a physical FIDO2 security key, is a clear upgrade on the text code, which remains interceptable and, above all, extortable.

5. Reverse recruitment fraud

A recent variant: the tradesperson looking for an apprentice or a temp receives applications by text, with a link to an "online CV" or a "hiring subsidy application file". The link installs a data-harvesting form, sometimes an app from outside the official store on Android. A recruitment process that starts with a file to open rather than a conversation can wait until Monday morning.

Separating your channels: the single measure that changes the most

A public number doesn't have to be your personal number

Best practice fits in one sentence: the number displayed publicly must not be the one that receives your banking codes. In practice, three set-ups work:

  • Two lines on a dual-SIM compatible phone: a "shop window" line, published everywhere, and a "safe" line, known to your bank, your accountant and nobody else. Most recent smartphones accept an eSIM alongside the physical SIM.
  • Two phones: the solution for high-exposure trades (emergency call-outs, delivery, healthcare), with a simple secondary handset left at the office or at home.
  • A virtual switchboard number that forwards to the mobile: the public face becomes a geographic landline number, more credible for clients and less exposed to mobile-number harvesting.

This separation doesn't eliminate fraudulent texts. It concentrates them on the line where they can do almost nothing: a scammer writing to your shop-window number cannot intercept a banking confirmation code, since that code arrives somewhere else.

The phone settings that genuinely help

In order of real-world effectiveness:

  1. Unknown sender filtering enabled (iOS: Settings → Apps → Messages → Filter Unknown Senders; Android/Messages: spam protection). Unsolicited messages go into a separate tab, viewable but outside your main thread.
  2. Blocking app installation from outside the official store, and checking that Play Protect or its equivalent is active. Almost all mobile banking trojans come in this way.
  3. Message previews hidden on the lock screen: a phone left on a counter or a dashboard should not display your codes.
  4. Two-factor authentication via an authenticator app, not by text, on your email, your invoicing software and your bank.
  5. System updates accepted within the week, rather than postponed for six months "because the phone is a work tool".

Worth noting: during 2026 Google strengthened automatic scam detection in the Messages app in France, with contextual alerts on certain conversation patterns. It's a useful extra safety net, but in no way a reason to lower your guard — automatic detection remains blind to the fake-client scenario, which contains neither a link nor a suspicious word.

Back up, because a business line also loses evidence

A self-employed worker who loses their phone loses contractual exchanges: quote approvals by text, job modifications, agreements on a deadline. An automatic encrypted backup of the phone, backed up by an external hard drive for annual archives, is as much a matter of good management as of security. In a dispute as much as in a fraud case, it's what lets you export a complete, time-stamped thread.

What to do once the message has arrived — or has already been opened

The three-question verification habit

Is this message asking me for urgent action? Is it steering me towards a link or a new payment channel? Can I verify the same information through a route I've chosen myself?

If the first two answers are yes and the third is no, treat the message as fraudulent by default.

The reporting channels that actually exist

  • Forward the text to 33700, the official service for reporting spam and text-message fraud in France (free of charge, then you supply the sender's number).
  • File a report on the Cybermalveillance.gouv.fr platform, which directs you according to the type of incident and offers a dedicated pathway for very small businesses.
  • Report a fraudulent website via Phishing Initiative or the Pharos system for illegal content.
  • Tell your bank immediately if you've passed on a code or a login: the Banque de France has highlighted across several reports the sharp rise in manipulation-based fraud, where the victim approves the transaction themselves. The faster you report it, the better the chances of recalling the funds.
  • File a police report, even when there's no financial loss: the report feeds investigations and is often a precondition for claims with your professional insurer.

Warning your clients, an underrated move

If your email account or your business listing has been compromised, your clients will receive messages in your name. A preventive text or email sent the same day — "our bank details have not changed, any message claiming otherwise is fraudulent" — limits the knock-on damage and protects your reputation, which is your single biggest asset.

Making prevention part of how you run the business

Two habits cost little and head off almost everything:

  • A line stating "our bank details never change by message" on your quotes and invoices, a single line at the foot of the document. Scammers impersonating a supplier lose most of their power against a forewarned client.
  • A ten-minute annual review with your accountant or insurer on cyberfraud. Many commercial multi-risk policies now include cover, often conditional on basic measures — two-factor authentication, backups, a transfer approval procedure. A practical guide to cybersecurity for very small businesses is enough to frame the conversation, and some trade bodies distribute them free of charge.

The underlying message is simple: for a self-employed worker, text message security isn't a question of digital comfort, it's a question of cash flow. A public number is a commercial asset; it becomes a risk the day it also serves as the key to your accounts. Separating the two uses remains, in 2026, the most profitable step you can take in a single afternoon.

#smishing#arnaque#fraude#Sécurité#Vie privée#2026#Conseil Sécurité#Mobile

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS