Everyone knows the reflex: a suspicious text arrives, you forward it to 33700, delete it and move on. The gesture is useful — but it leaves hanging a question nobody ever asks: and then what? Where does that report go? Who reads it? Does it lead to anything concrete, or does it vanish into a bottomless pit?
This article isn't about recognising a fraudulent text message, a subject already covered at length. It focuses on what comes next: the French administrative architecture of reporting, the channels that actually exist, what they do, and above all the part victims discover far too late — the bank refund procedure, its legal deadlines, and the remedies available when the institution drags its feet. Because under French law, a victim of payment fraud has far more leverage than they imagine.

33700: what really becomes of your forwarded message
33700 is a scheme run by the French mobile operators (Orange, SFR, Bouygues Telecom, Free) under the auspices of the Fédération française des télécoms, with public-sector backing. It is free, including from a capped prepaid plan.
The official procedure has two stages, and it's the second one that many people forget:
- Forward the suspicious message to 33700.
- Wait for the automatic reply, then send back the sender's number (the one that appeared as the originator of the fraudulent message).
Without that second step, the report is largely unusable: the platform receives a piece of text, but not its source. This is the most common mistake, and it explains part of the futility users feel.
Once the message-plus-number pairing has been received, the data is aggregated. Operators can then:
- cut off the originating line when it belongs to the French network;
- block messages containing certain identified URLs upstream, at network level;
- pass the material on to judicial authorities as part of investigations.
33700 is a tool of collective defence, not individual redress. It protects the next recipients, not you. That is precisely why it never removes the need for the other steps.
A word on the technical reality: a growing share of the smishing campaigns spotted since 2025 by teams such as Palo Alto Networks' Unit 42 no longer use French SIM cards at all. Messages are sent via international gateways, rotating virtual numbers, or transmission equipment driven around in a car. Cutting off a line then becomes a game of whack-a-mole. That doesn't make reporting pointless, but it does explain why it isn't enough on its own.
The other official channels, and which one to choose
France has multiplied its platforms to the point where victims no longer know which one to turn to. Here is how responsibilities are actually divided.
| Platform | What it handles | What it doesn't do |
|---|---|---|
| 33700 | Unwanted texts and calls, voice spam | Won't refund you, won't take a criminal complaint |
| Cybermalveillance.gouv.fr | Diagnosis, referral to a service provider, quick-reference guides | Doesn't investigate, doesn't prosecute |
| PHAROS (internet-signalement.gouv.fr) | Illegal online content, fraudulent websites | Doesn't handle individual financial loss |
| Perceval (service-public.fr) | Fraudulent use of a bank card, outside a formal complaint | Doesn't replace the steps taken with your bank |
| THESEE | Online complaint filing for internet scams | Doesn't cover every type of offence |
| Signal Conso | Disputes with a business, aggressive cold calling | Doesn't handle criminal fraud |
The right move depends on what you have lost.
If you entered nothing
Forward to 33700, delete the message, and that's it. There's no point filing a complaint over a text you merely received: no loss has occurred. That said, if the messages come in on a massive scale, keep a few screenshots — they may feed into a later case file.
If you entered login credentials
Change the passwords concerned immediately, switch on two-factor authentication wherever possible, then file a report on Cybermalveillance.gouv.fr, which provides a personalised assistance pathway. For anyone juggling a dozen or so sensitive accounts, a paper password notebook kept out of sight remains, paradoxically, a sturdier solution than a text file on the desktop — provided it never leaves the house.
If you handed over banking details
Here, the order of operations matters, and every hour counts.
The banking procedure: what the law actually says
This is the least understood point, and the most favourable to victims. The principle is set out in the French monetary and financial code, at articles L.133-18 et seq., transposing the European payment services directive (PSD2).
The basic rule is clear-cut: in the event of an unauthorised payment transaction, the bank refunds the payer immediately, and at the latest by the end of the first business day following the report. This is not a commercial goodwill gesture, it is a legal obligation.
The nuances worth knowing:
- The €50 excess provided for in cases of loss or theft does not apply when the details were siphoned off remotely without the card ever leaving your possession.
- The bank can only refuse by demonstrating gross negligence on your part. The burden of proof lies with the bank — and the Cour de cassation has repeatedly held that simply passing on a code received by text, obtained through a sophisticated fraudulent scheme, does not automatically amount to such negligence.
- The window for disputing a transaction is 13 months from the debit date (70 days if the provider is located outside the European Economic Area).
In practical terms, here's what to do:
- Block the card without delay (banking app, interbank card-blocking line on 0 892 705 705).
- Dispute in writing, by registered letter with acknowledgement of receipt, listing the transactions, dates and amounts. It is the written notice that starts the legal clock — a phone call leaves no trace you can rely on.
- File a Perceval declaration if the card was used without being physically stolen. The receipt forms part of your case file.
- File a complaint at a police station or gendarmerie, or via THESEE where the facts amount to online fraud.

When the bank refuses: the remedies that work
Refusals are common, and often justified with the catch-all line: "you validated the transaction with your strong authentication device." That is not, in itself, a valid rejection.
Step 1 — The complaints department
Every institution has a complaints department separate from your branch. Write to it directly, citing article L.133-18 and requesting the technical evidence justifying the disputed authentication. Response times are regulated: fifteen business days as a rule, two months at most in complex cases.
Step 2 — The banking ombudsman
Free, independent, and reachable online. Its opinions are not binding, but they are followed in the vast majority of cases. You must have exhausted the internal complaints route first. Contact details must appear on account statements and in the general terms and conditions.
Step 3 — The supervisory authorities
The ACPR (Autorité de contrôle prudentiel et de résolution), attached to the Banque de France, does not settle individual disputes but collects reports and sanctions institutions' improper practices. Large volumes of reports about the same behaviour do produce effects — several banks tightened their refund procedures after coordinated dispute campaigns publicised by consumer associations (UFC-Que Choisir, CLCV).
Step 4 — The courts
Before the tribunal judiciaire, the small claims procedure remains accessible without a lawyer below certain thresholds. Rulings published in recent years have mostly favoured victims of bank spoofing, provided the scheme was credible and the bank fails to demonstrate serious fault on the customer's part.
A winning case is a dated case. Time-stamped screenshots, registered letters, complaint receipts, annotated statements. The quality of your record-keeping counts for more than the eloquence of your letter.
Building a case that holds up
Many appeals fail not for lack of legal grounds, but for lack of usable evidence. A few practical principles.
Delete nothing before archiving it. The fraudulent text is itself an exhibit: it shows the displayed sender, the time and the content. Photograph the screen rather than settling for a screenshot, since a photo sometimes carries useful metadata.
Document the timeline. A simple three-column table — time, event, associated evidence — beats a narrative account. Complaints departments handle hundreds of files; the one that can be read in two minutes is the one that moves forward.
Keep the originals off the device. If the phone has been compromised, it may be wiped, seized, or simply fail. An encrypted USB stick kept separately, or an external hard drive dedicated to sensitive documents, prevents you losing everything at the worst possible moment. The cloud isn't a bad idea, provided the associated account wasn't itself caught up in the fraud.
Have the device examined if an app was installed. A provider listed by Cybermalveillance.gouv.fr can produce a technical report. That carries real weight with an insurer or a judge.
The insurance angle, often overlooked
Many premium banking packages, as well as certain multi-risk home insurance policies and "legal protection" cover, include a cyber-protection component. Depending on the policy, the cover may extend to help restoring accounts, identity-theft monitoring, and even payment of legal costs.
Reread your terms and conditions before paying anything to a private provider. The deadline for notifying your insurer is generally short — five business days in many policies — and it runs from the discovery of the facts, not from the fraud itself.
What to do beforehand to make everything easier
The best case file is the one you never have to build. Three habits change everything.
Compartmentalise your usage. A virtual bank card with a low ceiling for online purchases mechanically caps the damage. Most banks offer one free of charge; you just have to activate it.
Filter upstream. Recent operating systems offer automatic sorting of unknown senders. On older devices, or for less confident users, an unwanted-SMS filtering app installed from the official store noticeably reduces the volume that actually reaches the user.
Secure physical access. A phone with a cracked screen often ends up at a repair shop with its data intact, and a handset that dies from a flat battery won't let you block your card in time. A tempered glass screen protector and a compact power bank are less about gadgetry than about staying operational on the day you need to act fast.
Finally, in households where someone supports an elderly relative, experience shows that knowing the procedures beats being afraid. A practical cybersecurity guide for private individuals left within reach, read at leisure, builds more lasting reflexes than warnings repeated in a panic.
In summary
| Situation | Priority action | Deadline to respect |
|---|---|---|
| Text received, not clicked | 33700 (message + number) | Immediately |
| Credentials entered | Change passwords, Cybermalveillance.gouv.fr | Within the hour |
| Banking details handed over | Block the card, written dispute, Perceval, complaint | 13 months maximum to dispute |
| Bank refusing to refund | Complaints department → ombudsman → ACPR → courts | 15 days to 2 months per step |
| App installed | Isolate the device, expert examination, complaint | Immediately |
Reporting a scam text means taking part in a collective effort. Asserting your rights is something else: an individual, written, documented process — and far more effective than people believe. French and European law protects payment fraud victims far better than those first customer service refusals suggest. You just need to know where to knock, and in what order.
And when you need to warn a relative quickly that a fake text campaign is circulating in the name of a delivery company or a bank, a short message sent from a browser, without installing anything, remains the most direct way to get the word out — especially if the device in question is precisely the one you have doubts about.



