SMS Scams Targeting Sellers: How Fake Buyers on Leboncoin and Vinted Trap You

Confidentialité

Back to the blog
L'équipe Envoyer SMS Gratuit22 August 202612 min read
Filed underConfidentialité

There's one category of victims that gets far less attention than the others: sellers. For years, buyers have been told to beware of listings that look too good, of deposits requested up front, of sellers in a hurry. But when you're the one selling your old bike, a games console or a coat that no longer fits, your guard drops. After all, what could anyone take from you? You've got nothing to pay.

That is precisely the reasoning fraudsters exploit. For several years now, Cybermalveillance.gouv.fr and the DGCCRF have been warning about a scam that specifically targets private individuals who have posted a listing: the fake buyer. It almost always begins with a text message, and in the worst cases it ends with a drained bank account or a consumer loan taken out in your name.

Smartphone lying on a wooden table displaying a text message alert about banking fraud

Why the seller has become the ideal target

The reversal comes down to three very concrete developments.

Platforms have secured the purchase, not the exit from the conversation. Vinted, Leboncoin, Rakuten and the rest have introduced integrated payments, escrow systems and supervised returns. As long as the exchange stays inside the app, fraud is difficult. So the scammer has only one goal left: getting you out of the internal messaging system. The text message is the exit route.

Your number is often visible or easy to obtain. On many listings, sellers still display their phone number to "speed things up". When they don't, a first message through the platform's messaging system is usually enough: "Could you give me your number? I'm quicker to reply by text." Nine sellers out of ten agree, because they want to sell.

Your own motivation works against you. A potential buyer means money coming in. A listing that's been up for three weeks with no response, then suddenly an enthusiastic message: the brain registers "good news" before it registers "caution". Social engineering isn't trying to scare you here — it's trying to please you. That's far more effective.

The mechanics, step by step

The scenario is remarkably standardised. Once you've seen it play out once, you never fall for it again.

1. Contact off the platform

The first text arrives from an ordinary mobile number, sometimes from a foreign one. The tone is warm, slightly clumsy, often with a faintly off-key turn of phrase:

"Hello, I am interested in your item is it still available? I can pay right away I am in a hurry to leave on a trip."

Three warning signs are already there: urgency, the complete absence of questions about the item itself (condition, dimensions, flaws), and the move off the platform.

2. The price accepted without haggling

The scammer never negotiates. A genuine private buyer almost always tries to knock ten or twenty euros off. The fake buyer accepts the asking price — sometimes even offers more "to reserve it". They have no intention of paying, so the amount is irrelevant to them.

3. The delivery pretext

Then comes the centrepiece of the scheme: they can't come in person. A soldier on deployment, a nurse on shift, an expat buying for their mother, someone with reduced mobility. The pretext varies, the consequence is always the same: the item has to be shipped, which means going through a "secure payment service".

That's when the scammer offers to handle the shipping themselves, via a courier they know well, and tells you a link is on its way.

4. The booby-trapped link

The next text contains a web address. It mimics the name of a well-known service: a classified ads platform, a payment provider, a courier. The domain names are cobbled together but convincing at first glance: an extra hyphen, an exotic extension, an added word ("-secure", "-payment", "-delivery").

The page that loads is a polished copy. Logo, colours, legal notices, sometimes even a fake support chat. And a reassuring message: "The buyer's payment has been validated. Enter your bank details to receive the funds."

Hooded man wearing glasses using a smartphone in front of computer screens in a dark room

5. The form that takes everything

The form asks for the full card number, the expiry date and the three-digit security code. Sometimes it also asks for online banking credentials, a date of birth, or ID documents "for anti-money-laundering verification".

Take careful note of this point, because it's the heart of the reasoning to remember: you never receive money by handing over your security code. The three digits on the back of the card exist solely to authorise a debit. To receive a transfer, an IBAN is enough — and an IBAN alone cannot empty an account.

6. The confirmation call

A few minutes later, your phone rings. Your bank's name sometimes appears on screen, thanks to caller ID spoofing. A calm, professional voice explains that a suspicious transaction has been detected and that you need to approve — or on the contrary cancel — the operation in your banking app.

In reality, the scammer is in the middle of paying with your card, or adding your card to a mobile wallet on their own phone, and they need you to complete the strong authentication step. Without your tap in the app, nothing goes through. With your tap, the bank considers the transaction to have been authorised by you, which makes reimbursement considerably harder.

The variants circulating in 2026

Fake-buyer fraud isn't static. Several offshoots have taken hold.

VariantText message pretextWhat the scammer is after
Overpayment"I made a mistake, I sent €800 instead of €80, please refund the difference"A genuine transfer from you, in exchange for a fake receipt
Delivery fees to advance"The courier is asking for €45, which you'll be reimbursed"A small immediate payment, repeated across dozens of sellers
Identity verification"The platform requires ID to release the funds"Your documents, resold or used to open a line of credit
Fake customer service"Your listing has been reported, resolve this within 24h"Your account credentials, to post fraudulent listings in your name
Confirmation code"I'm sending you a code, send it back to prove it's really you"The one-time code received by text, the key to your account

That last row deserves particular attention. A code received by text from a service you didn't request is never passed on, to anyone, under any pretext. It's the simplest and most universal rule in mobile security.

The signals that should stop you in your tracks

Here's the list you can review before every sale. A single item is enough to justify ending the conversation.

  • The buyer wants to leave the platform's messaging system from the very first exchanges.
  • They ask no specific questions about the item.
  • They accept the price without haggling, or offer more.
  • They can't come in person, for a touching reason.
  • They send a link to "receive" or "release" your money.
  • The form asks for the card security code, a password or a code received by text.
  • The wording is correct but slightly stilted, with machine-translation phrasing.
  • Time pressure is constant: "quickly", "before tonight", "I'm leaving tomorrow".

These aren't conclusive on their own, but their accumulation leaves no room for doubt. An honest buyer never ticks four boxes out of eight.

Selling without exposing yourself: best practices

Keep the conversation where it started

As long as the exchange stays inside the app, the platform keeps a record, can suspend an account and sometimes step in if there's a dispute. The moment the discussion moves to text messages or an outside messaging service, you lose that safety net.

If you really want to switch to text messages — to agree on a meeting time, for instance — avoid publishing your main number in the body of the listing, where bots harvest it. An online text-sending service can, incidentally, help you confirm a meeting time without exposing your personal line.

Favour handing the item over in person

For items of any real value, an in-person handover remains the safest method. Choose a public, busy location, in daylight. Some police stations offer designated meeting points for transactions between private individuals; check what's available locally.

Count the cash, or better still: use an instant bank transfer that you verify in your banking app before handing over the item. A confirmation text, a screenshot or an email proves nothing at all: those can be faked in three minutes.

Document what you're selling

Before shipping, photograph the item from every angle, the sealed packaging and the shipping label. If a dispute arises over its condition or over whether it was actually sent, that file makes all the difference. For fragile or valuable items, bubble wrap and sturdy shipping boxes cost a few euros and save weeks of argument. A kitchen parcel scale or an electronic luggage scale also lets you declare the right weight and avoid courier surcharges.

Compartmentalise your money

This is the most effective measure and the least practised. Most banks and neobanks now offer single-use virtual cards or a spending limit you can adjust in two taps. Lowering your main card's limit to a few hundred euros, raising it occasionally when needed, mechanically caps the scale of any fraud.

In the same spirit, don't keep all your savings in the account linked to your card. A separate savings account with no card attached is a simple, free barrier.

Young girl sitting on a sofa, holding a blue smartphone in her hands, with plants in the background

Secure the device itself

Some of these frauds succeed because the phone is poorly protected: screen lock disabled, updates put off for months, apps installed outside official stores. Turn on automatic updates, lock the device with a PIN or biometrics, and be wary of parcel-tracking apps downloaded outside the Play Store or App Store.

For in-person handovers where you pull out your phone in the middle of the street, an anti-theft phone holder or simply a case with a wrist strap reduces the risk of a snatch theft — a far more mundane scenario than banking fraud, and just as costly when your entire digital life sits inside the device. A reinforced shockproof case also protects the screen during travel and handling.

What to do if you've already handed over your details

The order matters. The first few minutes determine a large part of what you'll get back.

  1. Block your card immediately. From your banking app if the feature exists, otherwise by phone. In France, the inter-bank card blocking service can be reached on 0 892 705 705.
  2. Change the passwords involved. Platform account, associated email, online banking. Use unique credentials; a password manager saves you from having to memorise them.
  3. Check recent transactions and report every unauthorised debit to your bank in writing.
  4. File a complaint, at a police station or via the French Interior Ministry's online pre-complaint platform. The receipt is essential for everything that follows.
  5. Report the text message to 33700 by forwarding it, then sending the sender's number when the service asks for it. The service is free and feeds into the blocking carried out by mobile operators.
  6. Report the fraudulent address to Phishing Initiative and the profile to the platform concerned.
  7. If your identity has been used fraudulently, contact the Perceval platform (service-public.fr) for bank card fraud, and check with the Banque de France whether a line of credit has been opened in your name.

Legally, the French monetary and financial code provides for the reimbursement of unauthorised transactions. A bank can refuse by invoking gross negligence, but the Cour de cassation has repeatedly stressed that the sophistication of the fraud — particularly the spoofing of the bank's own phone number — carries weight in that assessment. Never treat an initial refusal as final: referring the case to the banking ombudsman is free.

Three sentences to keep in mind

If you only take away three ideas from this article:

  • You never give out your card security code to receive money. An IBAN is all it takes to be paid by transfer.
  • A code received by text is never passed on to anyone, not even someone claiming to be your bank or the platform.
  • A link sent by a buyer is never a way of getting paid. Payment, when it's real, lands in your account without you having to click on anything.

The rest — the touching pretexts, the soldiers on deployment, the nurses on shift — is just decoration around those three mechanisms. Once you've understood them, the scam becomes almost transparent. And selling your old bike goes back to being what it should be: an ordinary transaction between two people.

To go further, the practical guides from Cybermalveillance.gouv.fr on phishing and the DGCCRF's guides on transactions between private individuals are free, regularly updated and written in accessible language. For relatives who are less comfortable with technology, a printed beginner's guide to smartphones is often more effective than a long explanation over the phone.

Free SMS · No sign-up · To France

Envoyez votre SMS gratuit en quelques secondes

Pas de compte à créer, pas de publicité, pas de limite : écrivez votre message, indiquez le mobile, et envoyez-le gratuitement depuis votre navigateur.

Envoyer un SMS gratuit