"Your grant application is incomplete": the scam texts targeting students at the start of term

Back to the blog
8 October 202610 min read

« CROUS: your student social file is missing a document. Without regularisation before 12/10, this month's grant payment will be suspended. Complete it here: crous-dse-regularisation[.]fr »

Léa, 19, a first-year undergraduate in Lille, clicked while on the tram. She had just exchanged three emails with the Crous about proof of her parents' income. The site looked exactly like the one she had used in June: logo, typeface, cookie banner. She entered her username, her password, then her IBAN "to confirm the payment account". The following month, her grant went to someone else's account. It took six weeks and a police report before the payment was flowing in the right direction again.

We like to say young people were "born with a phone in their hand" and are therefore protected. The opposite is true. A first-year student is one of the most profitable targets of the autumn: in six weeks, they handle more new administrative procedures than an employee does in five years — grant, housing, housing benefit, health insurance, bank, transport, course registration, part-time jobs — and they have no history to help them tell a legitimate message from a fake one.

A delivery man in a red shirt hands a smartphone and a parcel to a woman touching the screen

Why the start of the academic year is the perfect window

Everything arrives at once, and it all comes by text

Between late August and mid-November, a student legitimately receives messages from their Crous, their bank, their family allowance office, their university, their mobile operator, their health insurer, a landlord, a transport network and sometimes a part-time employer. Most of these organisations send genuine texts with genuine links.

The result: the reflex "an official body will never send you a link by text" is factually false, and the fraudsters know it. Their message doesn't stand out; it slips into an already saturated stream.

Administrative urgency works better than fear

The scenarios that work best don't threaten a fine, they threaten the loss of money already promised:

  • a grant "suspended" for want of a supporting document;
  • housing benefit "awaiting validation of the rent certificate";
  • an "overpayment" to be refunded within 48 hours;
  • a place in university halls "released to another applicant";
  • driving licence aid or mobility aid "not claimed".

For someone living on €500 a month, the prospect of losing €180 of grant money triggers a far more actionable panic than the threat of a hypothetical fine.

The data they need is public or easy to guess

A fraudster doesn't need to know Léa's file. They need to know she's a student, and that's there for all to see:

  • Facebook groups and Discord mutual-aid servers by city and by course, where phone numbers circulate for car shares, book sales and flat shares;
  • housing-wanted ads posted with first name, city, school and phone number;
  • petitions, party sign-up forms, student society lists;
  • sales of lecture notes and second-hand textbooks on general marketplaces;
  • files resold after a leak at a housing, mobility or ticketing company.

The messages are then blasted out across blocks of numbers, with a success rate high enough to be profitable. In 2026, the Banque de France documented the steady rise of so-called "manipulation" fraud, where the victim carries out the transaction themselves: that is exactly the register of these campaigns.

The six scenarios actually in circulation in 2026

1. The fake Crous and the fake student social file

The most widespread. The message announces a missing document or a blocked payment, with a deadline four or five days away. The form asks for portal credentials, then a payment IBAN — the real objective. A more discreet variant steals nothing immediately: it only collects the username and password, later reused on the victim's email inbox and bank accounts (many students reuse the same password everywhere).

2. The fake flat and the vanished deposit

The text replies to an ad the student posted themselves: "Studio, 24 m², €420 all in, still available, I'm being relocated abroad, virtual viewing possible". The lease arrives as a clean PDF, sometimes with a genuine land registry plot number. One month's deposit is requested by bank transfer "to secure the property". Every autumn, the Crous and university housing services publish warnings about this pattern, which claims victim after victim because no physical viewing takes place.

3. The fake health insurer and the fake medical reimbursement

"Your student health cover file is incomplete, your direct-billing card will be deactivated". The form demands a social security number, date of birth and bank details. Worth remembering: Ameli never asks for your bank details by text, and the Carte Vitale is free.

4. The student job that turns the victim into a middleman

"Paid assignment, 2 hrs/day, €90 a day, receiving and forwarding parcels" or "banking services test: you receive a transfer, you forward it, you keep 10%". This is no longer data theft, it's money mule recruitment. The consequences are legal: bank account closed, registration on a Banque de France blacklist, sometimes a summons. Students looking for extra income are the first in the firing line.

5. The fake transport pass or platform subscription

Received just after a real purchase: "Your student pass could not be renewed, please update your payment method". Tiny amount, card captured, recurring debits thereafter. It's the same mould as fake streaming renewals.

6. The bank text followed by a phone call

The costliest of all. A text flags a suspicious transaction, then an adviser calls back within minutes, often from a number displayed as the branch's own. They ask you to approve a transaction in the app "in order to cancel it". The victim authorises the transfer themselves.

A simple rule to memorise and repeat: no bank adviser will ever ask you to approve, read out or dictate a code received by text. A code you receive confirms a transaction; dictating it means signing it.

How to spot these messages in ten seconds

SignalWhat it means
A 24 to 72-hour deadlineFrench administration never moves at that speed
A link that isn't on .gouv.fr or the official .fr of the Crous or universityDomain registered the previous week
A request for an IBAN "for verification"No organisation verifies an IBAN through an unsolicited web form
A hyphen or extra word in the domain (crous-dse-…, ameli-remboursement…)Textbook imitation
A message arriving in the evening or at the weekendCampaigns run outside office hours to prevent you checking
A payment of a few euros requestedA pretext to capture the card

The one reflex that replaces all the others: never enter an account via a link you received. Close the message, open the app or type the official address by hand. If the information is genuine, it's in your account. If it isn't there, it doesn't exist.

The settings to configure once, in ten minutes

On your phone

  • Turn on unknown sender filtering: on iOS, Settings → Messages → Filter Unknown Senders; on Android, Google Messages → Spam protection. In 2026, Google strengthened automatic scam detection in Messages in France: the option deserves to be left on.
  • Disable automatic link previews in lock-screen notifications.
  • Keep the operating system updated: some traps rely on pages exploiting older browsers.
  • For students who work a lot from their phone, a clip-on smartphone stand for the desk has nothing to do with security, but it helps you read a message calmly rather than standing in a corridor between two lectures — and that is exactly the situation in which people click.

On your accounts

  • Turn on two-factor authentication on your email inbox before anything else: that's the account that lets you reset all the others.
  • Use different passwords. A password manager is enough; for those who prefer paper, a password notebook kept at home is still infinitely better than reusing the same code everywhere.
  • Where it's offered, choose an authenticator app or a physical USB-C security key over SMS codes for sensitive accounts: a phone number can be hijacked, a key cannot.

On your money

  • Cap online payments and transfers from the banking app. A €500 transfer limit mechanically prevents disaster.
  • Turn on instant notifications for every transaction.
  • Separate the account that receives your grant from the one used for online purchases, where the bank allows it.

If it has already happened: the first few hours

  1. Call your bank's card-blocking line immediately (number on the back of the card or in the app), before you even work out what happened. Ask for pending transfers to be blocked.
  2. Change the password of the account concerned, then your email password, from another device.
  3. Check the registered IBAN on the Crous portal, the CAF and your online banking: it's the quietest and costliest change of all.
  4. Report the text to 33700 by forwarding it, then send the sender's number to the same shortcode. The scheme feeds operator-level blocking.
  5. File a police report at a police or gendarmerie station, with screenshots. The Cybermalveillance.gouv.fr platform provides step-by-step fact sheets and points you to the right procedures; Perceval (an online service of the Ministry of the Interior) lets you report bank card fraud.
  6. Contact the Crous social services or your institution's student life office: a diverted payment is a known incident, and emergency support exists for it (one-off specific assistance).

Article 133-18 of the French Monetary and Financial Code provides for the reimbursement of unauthorised transactions. The bank may refuse on grounds of gross negligence by the user; recent case law is nevertheless favourable to victims when the message imitated the bank's identity (spoofing). If refused, referring the case to the banking ombudsman is free and often effective.

What you can say to a student without putting their back up

Classic prevention campaigns work poorly on 18-25s because they're patronising. Three formulations land better:

  • "You're not naive, you're busy. Fraudsters don't target ignorance, they target speed."
  • "The weak point isn't you, it's the calendar: at the start of term, everyone is expecting a message from the administration."
  • "If you clicked, say so straight away. The first 24 hours change everything, and nobody will judge you."

It's silence that costs dearly. Many student victims wait several weeks out of shame, by which time the windows for stopping transactions have closed.

Key takeaways

  • The start of the academic year is the annual peak for fraudulent texts targeting 18-25s, because every administrative task arrives at once.
  • The most profitable scenarios don't frighten you: they threaten to take away money you're already expecting (grant, housing benefit, support payment).
  • No organisation asks for an IBAN, a social security number or a code received by text via an unsolicited link.
  • Never check from the message itself: close it, open the app or type the official site by hand.
  • Capping transfers and enabling two-factor authentication on your email inbox limits the damage before it even happens.
  • If you've clicked: block the card, change the password, check the registered IBAN, report to 33700, file a police report.

A fraudulent text is never proof of gullibility. It's a sign that someone invested time in imitating precisely the message you were waiting for. The only lasting advantage is knowing how it works before you meet it.

#smishing#arnaque#fraude#Sécurité#Vie privée#Conseil Sécurité#2026#Mobile#données personnelles

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS