"Hi, it's Patrick. I smashed my phone, I'm texting you from my daughter's mobile. Can you make the transfer to the kit supplier today? The invoice is attached in your inbox, it has to go out before 5pm or we lose the order for the tournament. Thanks, I'll explain later."
Patrick really is the club's chairman. The treasurer, a retired volunteer of eleven years, recognised the tone, the first-name familiarity, the usual start-of-season urgency. He paid out €2,340 from the association's account. The real Patrick, reached by phone that evening, had never written that message.
There is plenty of talk about smishing aimed at private individuals and, more recently, at the self-employed. A third target remains almost invisible: the voluntary sector. Around 1.5 million active associations in France, the vast majority of which operate with no paid staff, relying on volunteers who manage a real bank account from their personal phone. No IT department, no written procedures, and mobile numbers displayed everywhere — on tournament posters, bingo night flyers, the town hall's website.

Why an association is an ideal target
Officers' phone numbers are public by design
An association exists to be reachable. The number of the chairman, the secretary or the registrations officer can be found with no hacking at all:
- on the back-to-club season poster and the village fête leaflets;
- in the local council's directory of associations, often copied word for word onto the town hall website;
- on the club's Facebook page, in pinned posts and comments;
- in minutes of general meetings published online as PDFs, sometimes listing the entire committee;
- in WhatsApp meeting notices forwarded from group to group until they travel well beyond the membership;
- in the Journal officiel des associations (JOAFE), for registered contact details.
A scammer therefore needs no data breach. They need an afternoon and a search engine. They know who the chairman is, who the treasurer is, and often when the next general meeting is due.
There is money, and it moves in bursts
Contrary to the stereotype of the penniless club, a mid-sized sports association takes in several tens of thousands of euros a year: membership fees, grants, refreshment bar, bingo nights, local sponsors, merchandise. These flows are not steady — they arrive in September, then with each event. An unusual €2,000 transfer in the middle of the new season raises no eyebrows.
Governance rests on trust, not on process
In a company, a transfer goes through an approval chain. In an association, it often goes through a message: "you can pay it, I approve". Volunteering runs on personal relationships. That is exactly what social engineering exploits: the scammer doesn't attack an IT system, they borrow a relationship of trust.
The four scenarios that come up most often
1. The fake chairman (CEO fraud, text message edition)
This is the scenario in the message above. A text from an unknown number, in the name of the chairman or a committee member, with three almost invariable markers:
- a justified change of number ("broken phone", "lost my SIM card", "I'm abroad");
- a deadline-driven urgency (before 5pm, before the market closes, before an order deadline);
- a credible, verifiable pretext: kit, hall rental, coach deposit, competition entry fees.
The request is never "send me money". It is always "pay this supplier", which shifts responsibility and puts the victim at ease.
2. The fake supplier and the change of bank details
A colder but devastatingly effective variant: a text or email claiming to come from the caterer, the printer, the minibus hire firm or the coach company, announcing a change of bank details. The wording is professional, sometimes accompanied by a fake document with the correct letterhead. The association pays a genuine invoice… into the wrong account.
In its reports from the Observatoire de la sécurité des moyens de paiement, the Banque de France has for several years highlighted the growth of manipulation-based fraud — cases where the victim makes the payment themselves. Associations fall squarely into this category, and it is the hardest kind of loss to get refunded.
3. The fake member and data harvesting
Another angle: the text message sent not to the committee but to families, posing as the club. "Licence adjustment: €18 is outstanding on your file, please settle before Sunday so your child remains insured." The link leads to a payment page imitating a well-known platform. The amount is small, the emotional stakes high (the child's insurance cover), and the club finds out weeks later.
For this scenario to work, the scammer needs the list of parents' numbers. It circulates more than people realise: open WhatsApp groups, Excel files emailed as attachments to the whole committee, a spreadsheet shared with public read access, a former secretary who keeps the list on their personal phone.
4. The fake grant and the fake agency
A final classic, and one on the rise: the text announcing an approved grant application, in the name of a "national sports agency", a "fund for the development of the voluntary sector" or a corporate foundation. How to recognise it: documents are requested (statutes, bank details, the chairman's ID), then "processing fees". No French public scheme charges a fee to pay out a grant, and none announces one by text message to a personal number.
A filtering rule that works in almost every case: a text message never calls for a financial decision. It may inform, remind, confirm. The moment it asks you to act, its status changes: it is a lead to be verified, not an instruction.
What makes a volunteer more vulnerable than an employee
Three factors compound one another, and none is a matter of intelligence.
| Factor | Practical consequence |
|---|---|
| The phone is personal | No corporate filtering, no MDM; club messages arrive between two family messages |
| Time is short | Club business gets handled in the evening, tired, between two other tasks — exactly the state in which urgency works best |
| Roles rotate | A new treasurer elected in September doesn't yet know the chairman's actual habits |
| Mistakes feel personal | The fear of having committed other people's money pushes people to say nothing, and so to delay reporting |
That last point is the most costly. In the cases we have been able to document, the average delay between the fraudulent transfer and the alert to the bank often exceeds 48 hours — precisely because the volunteer first tries to work out what happened, then hesitates to tell the committee.
Seven measures that fit into a single committee meeting
The goal isn't to bureaucratise a boules club. It's to introduce a little friction in the right places.
1. The call-back-on-the-known-number rule
Any request for a payment, a change of bank details or an urgent transfer received by text, WhatsApp or email must be verified with an outgoing call to the number saved in your contacts — never to the number that sent the message, never via a call-back you receive. A single sentence to record in the minutes of the general meeting, and it neutralises CEO fraud.
2. Dual authorisation above a threshold
Set a ceiling (say €500) above which two committee members must approve. Most banks offer dual authorisation on association accounts; failing that, approval can be documented by a confirmation email from the chairman. The scammer, for their part, cannot be two people at once.
3. A cash book that doesn't live only on a phone
The best-organised clubs we've met always keep a paper duplicate: a simple columnar accounting ledger kept in the clubhouse, in which every receipt and every expense is written down by hand the same day. This isn't nostalgia: in the event of a dispute, it's a record independent of the phone and the online account, and it makes an unusual payment immediately visible.
4. Treat the membership list as a sensitive file
A list of 200 parents' phone numbers is a personal data file within the meaning of the GDPR, and the association is the data controller. In practical terms:
- one designated holder only, with a handover to their successor at every change of committee;
- no emailing it as an attachment to the whole committee "for information";
- for group messaging, use the broadcast function that hides recipients rather than a group in which everyone can see everyone's number;
- an encrypted medium for backups — a secure USB drive with hardware encryption costs a few tens of euros and keeps a membership file from lingering in a former secretary's personal cloud storage.
The CNIL publishes practical guidance specifically for associations on managing membership files: it is the up-to-date reference whenever you're in doubt.
5. A club number separate from personal numbers
This is the measure that changes the most over time. A dedicated line — a prepaid SIM in a basic mobile phone, or a second number on a dual-SIM device — becomes the club's public point of contact. It passes to the next committee, it absorbs the spam, and it makes it possible to tell at a glance the difference between "a message from the club" and "a message claiming to come from the club" on a private line. For a treasurer, it's also a guarantee that their personal number won't end up on a poster.
6. Turn on your phone's spam filters, then report
On Android, the Messages app's protection against fraudulent messages was strengthened in France in 2026 and detects some malicious links. On iPhone, filtering unknown senders separates messages from non-contacts into a distinct tab. These tools don't replace rule no. 1, but they do reduce the volume.
Any fraudulent text can then be reported to 33700 (the official free service for reporting SMS spam) by forwarding the message, then the sender's number. Attempts that result in actual loss should be reported on the Cybermalveillance.gouv.fr platform and, on the criminal side, by filing a complaint with the police. The Perceval scheme covers fraudulent bank card use, not transfers you authorised yourself.
7. Ten minutes of training at every change of committee
No need for a seminar. The four scenarios above, read aloud at a meeting, are enough to immunise most volunteers. Associations that deal with the public or look after minors may find it useful to keep a practical cybersecurity guide in the clubhouse, so the new secretary doesn't have to search the internet on a night of panic.
If the transfer has already gone out
The first few hours matter more than everything else put together.
- Call the bank immediately, by phone, and ask them to attempt a recall of the transfer. A standard SEPA transfer can sometimes be stopped if it hasn't yet been executed or if the funds are still in the recipient's account. An instant transfer is irrevocable, but reporting it is still worthwhile.
- Tell the chairman and the committee without delay, even if the decision was taken alone. The loss belongs to the association, not to the volunteer.
- File a complaint, with screenshots of the text message, the sender's number, the payment instruction and the bank statements. Keep the original message on the phone: a full, timestamped screenshot is better than a forwarded copy.
- Notify the association's insurer: some multi-risk association policies include a "fraud" or "misappropriation" cover that often goes unnoticed.
- Warn the members if their data may have circulated and, in the event of a personal data breach, consider notifying the CNIL within 72 hours.
Key takeaways
Scammers haven't "discovered" associations: they simply offer the best ratio between easy access to phone numbers and the real presence of money. Against that, no technology can replace two governance reflexes: you never decide on a payment on the basis of a message, and you always call back on the number you already know.
An association that writes these two sentences into its internal rules, dedicates one number to its public contacts and protects its membership list like a sensitive file becomes a markedly less profitable target. And the volunteer regains the right to read a text message without wondering whether it will cost their club €2,000.



