Introduction: The Illusion of Digital Trust
Imagine receiving a text from your pension fund, your bank, or the SNCF. You check the sender: the official name is displayed, or better yet, it's the exact phone number you have saved in your contacts. You click, fill out a form, and in a few seconds, your banking credentials are stolen. The trap has closed, yet you believed you were communicating with a legitimate entity.
This is where SMS spoofing, or identity theft, comes into play. Unlike classic smishing, where the hacker uses an unknown or foreign number to lure you in, spoofing involves manipulating transmission protocols to change the sender's identifier (the Sender ID). In 2026, this technique has reached an alarming level of sophistication, turning our natural reflex of trusting saved contacts into a critical vulnerability.

How Does SMS Spoofing Work Technically?
To understand how a hacker can make the name of the Health Insurance fund or Agirc-Arrco appear on your screen, you have to understand that the SMS network was not designed with security as the absolute priority when it was created in the 90s.
Manipulating the Sender ID
The SMS protocol allows for the use of an alphanumeric "Sender ID." This is what enables companies to send messages where "SNCF" or "BANK-INFO" appears instead of a number. The problem is that some professional SMS Gateways, often located in lax jurisdictions, allow the user to choose this name freely.
Insertion into Existing Thread
The most dangerous aspect of modern spoofing is its ability to insert itself into an existing conversation. If a hacker knows your bank's phone number and your own number, they can send a message using the bank's identifier. Your smartphone, recognizing the sender, will not create a new conversation but will instead add the fraudulent message to the sequence of legitimate messages you have already received.
This is precisely what was observed during recent waves of attacks targeting retirees via fake Agirc-Arrco SMS: the fraudulent message appeared in the same thread as official notifications, making detection nearly impossible for an unsuspecting user.
The Most Common Attack Scenarios in 2026
Cybercriminals do not strike at random. They use social engineering to create a sense of urgency or fear.
1. Impersonating Public and Social Agencies
The Health Insurance (Ameli) and pension funds are prime targets. In 2026, there is a resurgence of messages regarding "pending refunds" or "file updates." The danger is twofold:
- Data theft: You are asked to confirm your bank details.
- Identity theft: You are asked to scan your identity documents.
2. Hacking Payment Services (Example: Wero)
With the emergence of new payment standards like Wero, hackers are adapting their scripts. They mimic the service's security alerts to notify you of a "suspicious login attempt," pushing you to click a link to "secure your account." In reality, the link leads to a perfect replica of the payment interface.
3. "SMS Blaster" Attacks
More sophisticated, SMS Blaster type attacks use malware to turn thousands of smartphones into sending relays. Unlike gateway spoofing, here the message originates from a real device, which bypasses some of the operators' anti-spam filters.

Why Do Anti-Spam Filters Fail?
One might think that operators (Orange, SFR, Bouygues, Free) could block these messages. In reality, the fight is uneven for several reasons:
| Obstacle | Explanation |
|---|---|
| Massive Volume | Millions of messages are sent via hundreds of different gateways simultaneously. |
| Gateway Legality | Many SMS sending services are legitimate and used by businesses, making global blocking impossible. |
| Link Variability | Hackers use link shorteners or temporary domains that change every few hours. |
| The Human Factor | Spoofing plays on trust. Even with a "Suspicious message" warning, the user clicks if they believe their bank account is blocked. |
How to Effectively Protect Yourself from Spoofing?
Faced with technology that can lie about the sender's identity, the only reliable defense is behavioral vigilance. Here are the golden rules for 2026.
Never click on a link in an urgent SMS
This is the fundamental rule. No serious administration, bank, or transport service will ever ask for your secret codes, passwords, or bank details via an SMS link.
- The reflex to adopt: Close the SMS. Open your web browser, manually type the official address of the service (e.g.,
ameli.frorsncf-connect.com), or use the official app. If an action is actually required, it will appear in your secure customer area.
Be wary of requests for documents
Spoofing often serves as a gateway for identity theft. If an SMS asks you to send a photo of your ID card or passport, it is a fraud. Public agencies use secure upload portals (such as FranceConnect) and not file exchanges via SMS or email.
Use detection tools
Although built-in filters are imperfect, some third-party solutions and start-ups (such as the French company Riot) are developing algorithms capable of analyzing link structures and the real origin of messages to alert the user before they click.

What to Do if You Have Been a Victim of Spoofing?
If you have clicked a link or provided information, every minute counts to limit the damage.
- Immediate Block: Contact your bank to block your cards and online access if you entered banking details.
- Change Passwords: Update the passwords for your main accounts (email, bank, taxes) using strong and unique passwords.
- Official Reporting:
- Report the SMS to the 33700 platform (the official SMS spam fighting service in France).
- File a complaint on THESES or via the PHAROS platform (internet-signalement.gouv.fr).
- Account Monitoring: Check your bank statements and administrative access over the following weeks to detect any unusual activity.
Conclusion: Toward an Era of "Zero Trust"
SMS spoofing teaches us a brutal lesson in modern cybersecurity: the displayed identity is not proof of identity. In 2026, we must move from a model of implicit trust to a "Zero Trust" model on our mobile devices.
The most powerful tool to counter hackers is not software, but your critical thinking. By remaining skeptical of urgency and systematically prioritizing official and manual communication channels, you neutralize the primary weapon of spoofing: the illusion. The security of your data begins where your blind trust in your smartphone screen ends.


