# Holiday text message scams: fake rental, toll and boarding pass alerts

> Cancelled rental, unpaid toll, delayed flight: when you're travelling, fake text messages exploit your lowered guard. A breakdown of the seasonal scenarios and the habits that genuinely protect you.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-08-23/arnaques-sms-vacances-hotel-location-voyage
- Published: 2026-08-23 (23 August 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, SMS, Guide, France 2026, Protection des données, Smartphone

---
There's a time of year when scammers don't even need to be good: they just need to show up at the right moment. That moment is the start of the holidays, the weekend you travel home, the half-term break, the peak changeover week. Not because holidaymakers are more gullible, but because they're in a very particular state of mind: they're expecting messages, lots of messages, from people they don't know.

A rental confirmation. An access code for a key safe. A reminder from an airline. A text from the car hire company. A tracking link for the shuttle. In everyday life, a message from an unknown number asking you to click sets off alarm bells. When you're travelling, it has become routine. It is precisely this normalisation that smishing — phishing by text message, as defined by Cybermalveillance.gouv.fr — exploits during holiday periods.

![Smartphone lying on a wooden table displaying a fraudulent text message notification claiming to come from a bank](/images/blog/2026-08-23-arnaques-sms-vacances-hotel-location-voyage/hero.jpg)

## Why travel disarms your vigilance

Fraudulent text message campaigns work on a simple principle: send a plausible scenario to hundreds of thousands of numbers and wait for chance to line the message up with the recipient's actual situation. During the holidays, that chance becomes a near certainty.

Four factors combine.

**You really are expecting messages from strangers.** An Airbnb host, an estate agency, a campsite, an airport car park: all legitimate contacts writing to you from numbers you've never seen before. The mental filter of "I don't know this number" no longer works.

**Time is short.** A text announcing a booking problem three days before departure leaves no room for delay. The urgency doesn't even need to be manufactured: it's already in your calendar.

**Reading conditions are poor.** Standing in a boarding queue, at a motorway service area, with sun on the screen and a child tugging at your sleeve. Nobody checks the spelling of a domain name in those conditions.

**Your phone is compromised.** Low battery, patchy coverage in rural areas, shared hotel wifi. A smartphone at 8% pushes you to act fast, to click rather than check, to tell yourself "I'll look at it properly later".

That's also why a [travel power bank](https://www.amazon.co.uk/s?k=batterie+externe+voyage+20000+mAh&tag=ds0608-21) isn't a convenience gadget but a genuine security tool: a charged phone is a phone you can use to take the time to call the hotel's real number rather than clicking the link you received.

## The five most common seasonal scenarios

### 1. The booking that "wasn't validated"

The message arrives a few days before arrival: *"Your booking of 12/08 could not be confirmed, the payment was declined. Settle within 24 hrs to avoid cancellation."* The link points to a page that faithfully imitates a well-known booking platform.

The trap is twofold. First, the fear of losing accommodation booked months earlier. Then the small amount: you're not asked for €800, you're asked to "re-validate" your card, or to pay a €50 deposit. The DGCCRF and the platforms themselves regularly restate one unbreakable rule: **no legitimate payment ever takes place outside the booking platform**. A host who insists on a direct bank transfer, a payment link sent by text or settlement by gift card is, in almost every case, a fraudster.

### 2. The fake unpaid toll notice

This scenario took off with the spread of free-flow tolling, the barrier-free system where you pay afterwards on an official site. The message is short: *"Unpaid journey on 09/08 on the A79. Amount: €4.20. Settle within 72 hrs before a surcharge applies."*

Everything is calibrated: the amount is realistic, the motorway exists, the deadline is plausible. Many drivers simply don't know whether or not they've paid for their journey. The rule: **never settle a free-flow toll from a link received by text message**. You type the address of the relevant motorway operator's official site yourself, or go through your electronic toll tag's app. The same goes for fake penalty notices: the official site of the national agency for automated processing of traffic offences is the only entry point, and it will never send you a text message with a payment link.

### 3. The changed flight and the fake boarding pass

*"Your flight AF1234 has been changed. View your new boarding pass."* The link asks for your booking reference, your name, sometimes your passport and your bank card for "reissue fees".

Here, it isn't only money that's targeted, it's identity data. A complete travel file — name, date of birth, passport number, address — is resold and then used to open accounts or take out loans. The right reflex: open the airline's official app, or check the departure board. A genuine flight change always appears in your booking, never only in a text message.

### 4. The key safe and the access code

More discreet, more insidious. The day before arrival you receive a message: *"Hello, last-minute change for the key handover, please confirm your identity here."* The link collects a scanned ID document, sometimes bank details "for returning the deposit".

The warning sign: a change of channel. If the entire conversation has taken place in the platform's messaging system and it suddenly shifts to text message, that's a red flag. Scammers harvest public listings and contact travellers blind, hoping to hit someone who has actually booked.

### 5. Bank "support" while you're away

This is the costliest variant. After an initial alert text ("attempted payment abroad of €749"), a call follows immediately, often from a number displayed as your bank's thanks to spoofing. A calm voice asks you to "block the transaction" by dictating your codes or approving a notification in your app.

The rule restated by the Fédération bancaire française and by the banks themselves is absolute: **an adviser will never ask you to approve a transaction, to pass on a code received by text message or to install remote-access software**. You hang up and call back the number on the back of your card.

![Man in a blue jacket holding a smartphone in an orange case, against a light background](/images/blog/2026-08-23-arnaques-sms-vacances-hotel-location-voyage/body-1.jpg)

## The ten-second sorting table

When a message arrives and you have neither the time nor the calm to investigate, this triage is enough in the vast majority of cases.

| What the message says | Legitimate response | Risky response |
| --- | --- | --- |
| A payment has failed | Open the relevant app yourself | Click the link provided |
| An amount is due within 24-72 hrs | Type the official address by hand | Pay via the link |
| You're asked for an ID document | Go through the platform's messaging | Send a scan by text message |
| An adviser calls after a text message | Hang up, call the number on the card | Stay on the line and approve |
| The link contains an odd brand name | Ignore and delete | "Just look at" the page |

One technical point that is often misunderstood: **the address shown on a shortened link means nothing**. Campaigns make heavy use of link shorteners and domain names that include the legitimate brand as a subdomain. An address such as `secure-colissimo.paiement-xyz.top` has nothing to do with the service it imitates: what matters is what comes immediately before the extension, not what appears at the start.

## Getting your phone ready before you leave

The best protection while travelling is put in place the day before departure, calmly, at home.

**Take stock of official channels.** Save your bank's number, your insurer's and your accommodation's in your contacts. A number already stored shows up with a name: if a supposedly bank-related call comes from an unidentified number, doubt is immediate.

**Lock down notification previews.** One-time verification codes appear on the lock screen by default. On a train, in a queue or in a shared room, that's enough to compromise an account. The setting is in your notification preferences, under "Previews" or "Show content". In the same spirit, a [privacy filter for smartphone screens](https://www.amazon.co.uk/s?k=filtre+de+confidentialit%C3%A9+%C3%A9cran+smartphone&tag=ds0608-21) makes the screen unreadable from an angle — useful on a plane as well as on a café terrace.

**Take enough power to avoid public charging points.** Open USB charging stations in airports and stations pose a real problem: an uncontrolled data port can, in certain configurations, be misused. A simple USB power adapter with its wall plug, or a [charge-only cable with no data transfer](https://www.amazon.co.uk/s?k=c%C3%A2ble+USB+charge+seule+sans+donn%C3%A9es&tag=ds0608-21), removes the question entirely. It isn't paranoia, it's the same logic as not plugging in a USB stick you found on the ground.

**Back up before you go.** A phone lost or stolen on holiday means potential access to your messages, emails and banking apps. An up-to-date backup and enabled remote location completely change the outcome. Also plan how to protect the device physically: sand, salt water and beach bags do more damage than people think, and a [waterproof smartphone case](https://www.amazon.co.uk/s?k=pochette+%C3%A9tanche+smartphone+plage&tag=ds0608-21) costs less than a replacement screen.

## Hotel wifi, public networks and fake portals

Free wifi at the campsite or in the hotel lobby deserves a mention of its own. The main risk today is no longer really data interception — most sites and apps encrypt their traffic — but the **fake captive portal**: the page that opens asking you to "sign in" before accessing the network, and that sometimes demands an email address, a password, or even a bank card "for verification".

Three rules are enough:

- A legitimate captive portal never asks for your email password or your card number.
- Check the exact network name with reception. A network called "Hotel_Wifi_Free" sitting next to the real "Hotel-Wifi" is a classic trap.
- For sensitive operations — banking, tax, purchases — use your mobile data instead. Tethering from your own plan is safer than an open network, and a local prepaid SIM card remains a good option for long stays outside Europe.

![Close-up of the hands of a woman in a beige coat holding and looking at a smartphone outdoors](/images/blog/2026-08-23-arnaques-sms-vacances-hotel-location-voyage/body-2.jpg)

## If the message has already been opened

Opening a fraudulent text message is not dangerous in itself. The risk begins with the click, and becomes serious when you enter information.

1. **You only clicked without entering anything.** Close the page, don't go back to it, don't fill anything in. Check that no app has installed itself without your knowledge, particularly on Android where installation from an external source remains possible.
2. **You entered banking details.** Block your card immediately via your banking app or the number on the back of the card. From abroad, that number is still reachable. Keep the screenshots.
3. **You sent an ID document.** Report it and watch for any account opened in your name. Filing a complaint, even remotely, is a useful piece of evidence.
4. **Report the message.** In France, the number **33700** receives reports of fraudulent text messages: forward the message to 33700, then send the sender's number when prompted. The service is free. You can also file a report on the official platform **Cybermalveillance.gouv.fr**, which points you to the appropriate steps, and on **internet-signalement.gouv.fr** (PHAROS) for illegal content.
5. **Warn the people around you.** Campaigns target entire blocks of numbers. If you received it, the friends and family who set off at the same time as you probably received it too.

## The particular case of older travellers

Older people often go on holiday with less solid digital reference points and, above all, with a fear of "doing something stupid" that pushes them to comply rather than check. Three simple arrangements help a great deal.

Agree before departure on a **trusted contact** who can be reached in case of doubt: a thirty-second call to a child or a neighbour defuses any scam. Write the real numbers of the bank and the insurer on a piece of paper tucked into the wallet, because under stress nobody goes rummaging through a phone. And for those who don't need a smartphone while travelling, a [mobile phone with large buttons](https://www.amazon.co.uk/s?k=t%C3%A9l%C3%A9phone+portable+senior+grosses+touches&tag=ds0608-21) mechanically limits the attack surface: no browser, no clickable link, no banking app.

> One rule fits in a single sentence and covers 95% of situations: **never pay and never identify yourself from a link you received, whatever sender is displayed.** Always go back to the channel you chose yourself.

## Key takeaways

Holiday text message scams are no more sophisticated than any others. They're simply better synchronised with your life. The remedy isn't to become a cybersecurity expert, but to reintroduce a tiny delay between reading and acting: open the app yourself, type the address yourself, call the official number back yourself.

That delay costs thirty seconds. And that is precisely what scammers cannot afford to give you.

{/* image-sources: https://images.pexels.com/photos/7821750/pexels-photo-7821750.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/5745183/pexels-photo-5745183.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/6084224/pexels-photo-6084224.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
