SMS Blaster: the fake cell towers flooding your phone with booby-trapped messages

Confidentialité

Back to the blog
L'équipe Envoyer SMS Gratuit21 August 202611 min read
Filed underConfidentialité

You already know the classic scam text: it leaves a bulk-messaging platform, travels across operator networks, and finally lands on your screen after passing through several filters. The SMS Blaster short-circuits all of that. It needs no phone number, no contact list, no insider at a mobile operator. All it needs is to be physically close to you.

Since 2025, French and European authorities have been reporting these devices turning up in major cities, often carried in a car boot, a backpack or a wheeled suitcase. The principle is brutally simple: the device poses as a cell tower, captures the phones passing within its radius and pushes a message to them. In just a few hours of driving around a dense neighbourhood, tens of thousands of handsets can be hit.

Young girl sitting on a sofa reading a message on her blue mobile phone

A rogue cell tower in a car boot

Technically, an SMS Blaster is a cousin of the IMSI catcher, the surveillance hardware that simulates a mobile base station. The difference lies in the purpose: whereas the IMSI catcher is designed primarily to identify or intercept, the Blaster is designed to broadcast.

The scenario plays out in three stages.

  1. The device emits a very powerful signal. Your phone, built to latch onto the strongest cell available, drops its operator's legitimate tower and connects to the box instead.
  2. It forces a fallback to 2G. Recent generations (4G, 5G) require mutual authentication: the network proves its identity to the phone. 2G, on the other hand, only asks the phone to authenticate itself, not the other way round. By jamming or refusing 4G/5G connections, the device pushes the handset back onto this much more permissive legacy standard.
  3. It pushes the message. Once the phone is attached, the device injects a text message with any sender name it likes: "Ameli", "La Poste", "Chronopost", a bank's name or even a credible ten-digit number.

The message never travelled through a French operator. It was never seen by an anti-spam filter, a blocklist or a smishing detection system. It simply appears on the screen, often in the very same conversation thread as genuine messages from the impersonated organisation — a well-known side effect of grouping by sender name, which we covered in detail in our article on SMS spoofing.

An SMS Blaster doesn't hack your phone. It exploits a basic rule of mobile networks: a handset trusts the nearest, strongest tower.

Why fraudsters find this technique so appealing

Traditional scam texting costs money and leaves traces. You have to buy number databases, rent messaging gateways, get around operator blocks, and accept that a good share of the messages will be filtered out before they even arrive. French schemes such as 33700 (the reporting platform for spam calls and texts, operated by the Association Française du Multimédia Mobile) have significantly eroded the profitability of that model.

The Blaster bypasses the entire chain:

CriterionClassic scam textSMS Blaster
Numbers targetedBought, leaked, generatedNone needed: physical proximity
Routed via an operatorYesNo
Anti-spam filtering possibleYesVirtually none
Sender traceabilityPartialVery poor
ReachGlobalA few hundred metres
ConstraintBudget, blocksHaving to be physically present

The trade-off is the physical risk for the crook: they have to move around with their equipment. That is also what makes arrests possible. Several cases in Asia and Europe have led to arrests thanks to triangulation of abnormal signals detected by operators.

Where the risk is concentrated

A Blaster pays off wherever the density of mobile phones is highest. The most exposed locations are therefore fairly predictable:

  • Railway stations and major metro stations, where thousands of people linger for a few minutes.
  • Shopping districts and pedestrian streets at peak times.
  • Areas around stadiums, concert halls and major events, where the crowd is captive and distracted.
  • Congested roads, since an equipped vehicle can simply crawl along in traffic.
  • Weekend markets, fairs and flea markets.

One important point: the operating radius remains limited, from a few dozen to a few hundred metres depending on the environment and the power of the hardware. You are not permanently exposed, but occasionally, in specific situations.

How to tell something is off

No single sign is conclusive on its own, but a cluster of clues should put you on alert.

The message doesn't match your situation

That's the first instinct to have, and it remains the best one. An SMS Blaster targets no one in particular: it sprays. So you'll get a parcel-tracking message when you haven't ordered anything, an alert from a "bank" you don't hold an account with, or a reminder about a training account that matches no application you've made.

Your phone has oddly switched to 2G

On Android, the network icon sometimes shows "E", "G" or "2G" instead of 4G/5G. On iPhone the display is less explicit, but the switch shows up as a sudden collapse in speed, with mobile internet loading nothing at all even though the signal bars look full. If this happens in a city centre, in an area that's usually well covered, it's abnormal.

The message lands in an official conversation thread

Because the sender name can be freely altered on 2G, the message sometimes slips in under the same header as genuine texts from an organisation. That's the most unsettling part, and it's exactly the intended effect: your legitimate message history vouches for the fake one.

Several people around you receive the same thing

On a train at the platform, in an open-plan office or in a queue, simultaneity is a very strong indicator. If the person next to you gets the same "parcel awaiting customs fees" message at the same second, it's no coincidence.

Close-up of a person's hands holding a smartphone in a purple case to read a text message

The protective measures that genuinely work

Disable 2G where possible

This is the most direct countermeasure, and it's available on a good proportion of recent Android smartphones: in the mobile network settings, an option lets you refuse 2G connections outright. The phone can then no longer attach to a device that forces this fallback.

On Android, look under Settings → Mobile networks → Allow 2G (the wording varies by manufacturer). On iPhone, Lockdown Mode also restricts certain connections, but there is no equally explicit dedicated 2G option.

One common-sense caveat: 2G remains the safety net for voice calls in some poorly covered rural areas, and it is used as a last resort for emergency calls. If you live in or travel through a not-spot, weigh the decision carefully. For most urban use, turning it off makes no difference day to day. And if you find that your device is an older model without this option, that's also one of the few concrete technical arguments for considering a recent Android smartphone, whose network layers still receive security patches.

Keep the system up to date

Monthly security patches regularly fix flaws in the lower network layers (the baseband). A phone that hasn't received updates for two or three years accumulates vulnerabilities. Check the date of the last installed patch in the "About phone" settings.

Never open a link received by text message

This advice applies to all messages, but here it's the only truly decisive barrier. An SMS Blaster can do nothing more than display text to you: it's your click that sets the fraud in motion. The habit to build: open the app yourself, or type the official address by hand. Ameli, La Poste, Chronopost, banks and the Assurance Maladie all point this out systematically in their communications — none of these organisations ever asks for banking details by text message.

Lock down payments and sensitive data

If a link has been opened and information entered, speed is everything. Block the card from your banking app, contact the card-cancellation service, and report the message by forwarding it to 33700. Cybermalveillance.gouv.fr offers a free assistance pathway and a streamlined way to file a complaint via the THESEE platform.

Look after your phone's battery life and availability

This may sound off-topic, but your ability to react quickly depends on having a usable handset. A phone that dies at the wrong moment stops you calling your bank or cancelling a card. A compact power bank in your bag is, for that reason, as much a safety accessory as a convenience one — especially since a forced 2G fallback, or the constant network searching that follows a Blaster's passage, drives up battery consumption.

What operators and authorities are doing

French mobile networks are not standing idly by. Operators have probes capable of detecting signalling anomalies: a cell appearing where no tower is registered, handsets detaching en masse from a legitimate site, statistically abnormal 2G fallbacks. These signals make it possible to map the presence of a rogue transmitter and guide investigators.

Legally, the picture is clear. Possessing and using unauthorised radio equipment that disrupts networks falls under the French Postal and Electronic Communications Code. On top of that come organised-gang fraud, identity theft and unauthorised access to an automated data processing system. The penalties run to years in prison and fines in the hundreds of thousands of euros.

ARCEP, the telecoms regulator, and the ANFR (the national frequencies agency), responsible for spectrum monitoring, have field teams able to pinpoint an illegal transmission source. The ANFR regularly runs campaigns to detect jammers, and that expertise transfers directly to fake base stations.

The underlying trend is also on our side: the gradual switch-off of 2G. Several French operators have begun shutting down their legacy GSM networks, a move already completed in several European countries. The day no handset can fall back to 2G any more, the SMS Blaster as it exists today will lose its main lever.

A woman's hand typing a message on the keyboard of a smartphone lying on a white sheet

Should you equip yourself with detection tools?

The question comes up often, and the answer deserves some nuance.

There are Android apps that monitor the parameters of the cell your phone is attached to and raise an alert in case of suspicious behaviour (forced 2G fallback, unknown cell ID, encryption disabled). They generally require access to network diagnostics and don't work on every model. They're genuinely useful for the curious and for exposed professionals, but they're no substitute for simply switching 2G off.

For those who really want to understand the mechanisms at play, an accessible book on cybersecurity often does more for everyday vigilance than a stack of apps. Understanding why a network trusts a tower makes the scam instantly legible.

Finally, for sensitive use cases — business travel, journalists, exposed individuals — some people adopt a dedicated second device, sometimes a basic mobile phone with no browser and no apps. A handset that can't display a clickable link can't serve as a gateway for smishing. It isn't a universal solution, but it's a coherent answer for anyone wanting a clean separation between communication and web browsing.

In summary: three rules to remember

  • The SMS Blaster doesn't know you. It has no idea of your name, your bank, or what you've ordered. Any message claiming otherwise should be verified elsewhere.
  • The danger isn't the message, it's the link. No device can take money from you: only a click followed by data entry can do that.
  • 2G is the weak point. Disabling it when your phone allows is the single most worthwhile technical step in 2026.

Text messaging remains a remarkably reliable and universal channel — it's precisely because it's everywhere and read by everyone that it attracts fraudsters. That trust deserves to be protected, not abandoned: a short, direct message, sent from a browser in a matter of seconds with Envoyer SMS Gratuit, remains one of the simplest ways to reach someone in France. Provided you know how to tell a real message from a fake one.

Going further

  • 33700: the official platform for reporting unwanted texts and calls (forwarding the message is free).
  • Cybermalveillance.gouv.fr: diagnosis, advice and referrals to local service providers.
  • THESEE: online complaint filing for online fraud.
  • ANFR: radio spectrum monitoring and detection of illegal transmitters.
  • ARCEP: regulation of electronic communications and oversight of the 2G/3G network switch-off.
Free SMS · No sign-up · To France

Envoyez votre SMS gratuit en quelques secondes

Pas de compte à créer, pas de publicité, pas de limite : écrivez votre message, indiquez le mobile, et envoyez-le gratuitement depuis votre navigateur.

Envoyer un SMS gratuit