# First phone: getting a teenager ready for scam texts before you hand it over

> Giving a child their first smartphone also opens the door to fraudulent texts, fake prizes and digital blackmail. A practical guide to preparing them, without intrusive surveillance.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-08-25/sms-frauduleux-enfants-adolescents-premier-telephone
- Published: 2026-08-25 (25 August 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, Smartphone, Guide, Carte SIM, France 2026, Protection des données

---
There's one conversation most families never have. We discuss the price of the device, the plan, screen time, sometimes bullying between classmates. And we systematically forget the most mundane entry point, the one scammers use most: text messaging.

That oversight isn't harmless. An adult who receives a fake message from their bank has a reserve of experience: they've seen attempts before, they roughly understand how a transfer works, they know an adviser never asks for a code over the phone. A twelve-year-old getting their first device has none of that. They have a brand-new number, complete trust in whatever appears on screen, and a strong incentive not to alert their parents when something goes wrong — because above all they're afraid the phone will be taken away.

That combination is what interests fraudsters. Not naivety: silence.

![Hand holding a smartphone showing a messaging inbox, blurred green plant in the background](/images/blog/2026-08-25-sms-frauduleux-enfants-adolescents-premier-telephone/hero.jpg)

## Why a "brand-new" number doesn't stay new for long

Many parents assume that a number never used anywhere will stay quiet. In practice, it enters circulation within a few weeks.

Smishing campaigns — phishing by text message, as Cybermalveillance.gouv.fr defines it — don't target individuals. They sweep across entire ranges of automatically generated numbers, including those just assigned by carriers. Receiving a fake delivery text on a line activated ten days ago is not unusual: it's the norm.

On top of that come the mechanisms specific to teenage habits:

- **Repeated sign-ups.** Mobile games, streaming platforms, photo-editing apps, social media contests. The number serves as an identifier everywhere, and every service is a potential leak point.
- **Open groups.** Chat servers, class group chats that keep expanding, conversations around an online game. A number circulating in a group of three hundred people is no longer private.
- **Data breaches.** The CNIL and Cybermalveillance.gouv.fr regularly document breaches affecting consumer platforms, including those with very young audiences. Exposed numbers end up resold in bulk.

In other words, the question isn't *whether* your teenager will receive a fraudulent text, but when — and above all, what frame of mind they'll be in when they read it.

## The scenarios that specifically target young people

SMS scams adapt to their target. The ones aimed at teenagers look nothing like those aimed at pensioners.

### The fake prize and the in-game "gift"

A message announces virtual currency, skins, a premium account, a concert ticket. A link leads to a page asking for the gaming account credentials, sometimes a card number "for age verification". The hijacked account is then resold — and for a teenager who has invested two years in it, the loss stings.

### The fake subscription to cancel

"Your subscription renews at €49.90 tonight. Cancel here." Nobody wants to see €49.90 disappear. The panic reflex is identical to an adult's, with one aggravating factor: the fear that parents will discover an unexplained charge.

### The fake recruiter and the summer job

From fifteen or sixteen onwards, offers of "paid gigs" arrive en masse by text or messaging app. Testing apps, posting reviews, receiving and forwarding parcels. That last variant, "muling", turns a young person into an unwitting accomplice in a fraud network, with real criminal consequences. The Ministry of the Interior and the Pharos platform regularly warn about this kind of recruitment.

### The request for money in a relative's name

The "Hi Mum, I broke my phone, here's my new number" variant works in both directions. A teenager can be approached in the name of a cousin, a friend, a grandparent. They rarely think to verify through another channel.

### Sextortion

The most serious, and the least talked about. A conversation that starts with a text or a private message, drifts towards exchanging images, then turns into a threat to share them. The e-Enfance association, which runs 3018 (the national helpline against digital violence, free and confidential), flags this scenario as one of the most common among minors. Shame does the rest: the victim pays or stays quiet.

## What's at stake even before the first SIM card

Preparation doesn't start on the day of purchase. It starts with choosing the device.

**The type of device matters.** Not every child needs a full smartphone at eleven. For a first line intended mainly for reaching parents at the school gates, a [simple mobile phone with physical buttons](https://www.amazon.co.uk/s?k=t%C3%A9l%C3%A9phone+portable+simple+grosses+touches&tag=ds0608-21) does the job without opening the inbox to every phishing campaign with clickable links. This isn't a reactionary stance: it's reducing the attack surface. The move to a smartphone comes later, once the instincts are in place.

**The type of plan matters too.** A [prepaid SIM card with no automatic top-up](https://www.amazon.co.uk/s?k=carte+SIM+pr%C3%A9pay%C3%A9e+sans+engagement&tag=ds0608-21) mechanically limits the damage of a fraudulent subscription or a premium-rate service. Many scams targeting young people rely on small recurring charges that go unnoticed on a family bill, but become instantly visible on a prepaid line.

**Physical protection matters as well, indirectly.** A broken device is one the teenager will want repaired discreetly, perhaps through a classified ad or a "repairer" found online — a classic route to data loss. A [reinforced protective case](https://www.amazon.co.uk/s?k=coque+de+protection+renforc%C3%A9e+smartphone&tag=ds0608-21) and a tempered glass screen protector cost a few euros and prevent that chain of events. It isn't cybersecurity, it's prevention from the ground up.

## The conversation worth more than any parental controls

Parental control tools filter sites, limit hours, block installations. None of them blocks a well-written scam text. The only protection that holds is the teenager's own instinct.

Three ideas to pass on, put simply.

**A message that puts pressure on you is a suspicious message.** A genuine company never demands action within two hours. Urgency is a manipulation tool, not a feature of legitimate services.

**You never click a link received by text.** No exceptions. If the message seems to come from a service you actually use, open the app or type the site's address by hand. This rule has the advantage of being absolute, and therefore memorable.

**A code received by text is never shared with anyone.** Not with a friend, not with "technical support", not with someone claiming to be a family member. It's the easiest rule to state and the most often broken.

And a fourth one, the most important of all:

> "If you get caught out, you won't be punished. We'll sort it out together."

That sentence, said in advance and honoured when the day comes, is worth more than any software. The entire mechanism of digital blackmail rests on the fraudster's certainty that the victim won't dare speak up. Removing that certainty defuses half the scenarios.

![Woman in a conical hat, seen from behind, looking at a smartphone in front of a field](/images/blog/2026-08-25-sms-frauduleux-enfants-adolescents-premier-telephone/body-1.jpg)

## The settings to configure together, on activation day

Half an hour, just once, and the essentials are in place. To be done **with** the teenager, not for them: the goal is that they understand why.

| Setting | Why | Where |
|---|---|---|
| SIM card PIN enabled | Prevents use of the line if the device is stolen | Settings → Security / SIM |
| Screen lock + biometrics | Protects content in case of loss | Settings → Lock screen |
| Notification previews hidden | An incoming code isn't displayed on a locked screen | Settings → Notifications |
| Filtering of unknown senders | Isolates texts from unsaved numbers | Messages → Options |
| Premium-rate service blocking | Cuts off SMS+ subscriptions | Carrier account area |
| App-based two-factor authentication | More robust than codes by text | Google / Apple accounts |
| Automatic updates | Patches exploited vulnerabilities | Settings → System |

Two points deserve a further word.

**Blocking premium-rate services** is free and can be requested directly from the carrier. It neutralises a whole family of scams based on SMS+ subscriptions signed up for in one click. Few parents know this option exists.

**App-based authentication** rather than SMS is worth setting up from the start on the accounts that matter (email, gaming accounts, social media). Getting into the habit right away avoids having to change later. For a household's most sensitive accounts, some parents go as far as a [physical FIDO2 security key](https://www.amazon.co.uk/s?k=cl%C3%A9+de+s%C3%A9curit%C3%A9+FIDO2+USB&tag=ds0608-21), which remains the most phishing-resistant standard.

## Learning to spot, not just to obey

A rule imposed without explanation holds until the first truly convincing message. Practice works better.

A simple exercise, five minutes once a month: open the texts received from unknown numbers together and analyse them out loud.

- **Who is supposedly writing?** A service you actually use, or a vaguely plausible name?
- **What is the message asking for?** Information, urgent action, a payment?
- **Where does the link lead?** Without clicking: does the address contain the real domain name, or a shortener, or an exotic extension?
- **What feels off?** Typos, unusual familiarity, machine-translated phrasing, no recipient name.

This method has one advantage: it turns a prohibition into a skill. Trials run in companies using French tools that simulate scam texts show that repeated exposure to fake messages, in a safe setting, sharply reduces click rates. The principle works just as well at home.

For families who want to go further, a [digital awareness guide for parents](https://www.amazon.co.uk/s?k=livre+%C3%A9ducation+num%C3%A9rique+enfants+parents&tag=ds0608-21) makes a good discussion prompt, especially when questions go beyond texts alone: online reputation, personal data, exposure on social media.

## When it happens anyway: what to do

A teenager clicked, entered their credentials, or passed on a code. It isn't a disaster, it's a short-lived emergency.

1. **Cut the device's connection** (airplane mode) if an unknown app has been installed.
2. **Change the passwords** of the affected accounts, from another device, starting with the main email address — that's the key to everything else.
3. **Check active sessions** in the accounts' security settings, and sign out unknown devices.
4. **Alert the bank** if card details were entered, and block the card. Reimbursement for an unauthorised transaction is provided for by the French monetary and financial code, provided you act quickly.
5. **Report the message** to 33700 (forward the text, then send the sender's number), the official French carriers' scheme against fraudulent texts.
6. **Report the content** on the Pharos platform if it is illegal content, and call 3018 in cases of sextortion or harassment.
7. **File a complaint** if there is financial harm. The Perceval service also allows you to report bank card fraud.

One point not to miss: in cases of sextortion, **you never pay**. Payment never ends the demands, it confirms them. 3018 supports families in getting content taken down, with fast-track procedures with the platforms.

## Staying reachable without exposing everything

There is a middle ground, often overlooked, between "giving out your number" and "not communicating at all".

For sign-ups to low-trust services — a game downloaded once, a contest, a platform discovered yesterday — the best approach is not to give a number at all. When a service genuinely requires one, a dedicated email address is better than a personal number: an address can be thrown away, a number is kept for years.

And for situations where you want to send a one-off message without involving your own line — notifying a club, contacting someone you met once, confirming an appointment — an online SMS-sending service with no registration comes in handy, as long as you know its limits: it's a one-off, traceable use, not an anonymity tool, and certainly not a way to send messages to someone who doesn't want them. This point deserves to be spelled out clearly to a teenager, because the line between joking around with friends and harassment gets crossed without you noticing, and it carries criminal penalties.

## The real goal: autonomy that doesn't depend on you

Parental controls stop at eighteen. Smishing campaigns don't. The point, then, isn't to build an enclosure, but to pass on an instinct that will outlast the moment when nobody is looking over their shoulder anymore.

That means accepting two uncomfortable things. The first is that a well-prepared teenager will still get caught out one day — just as highly competent adults get caught out regularly, because the scenarios are good and tiredness is real. The second is that the most effective measure isn't technical: it's the guarantee that they can talk about it without consequences.

A phone, a SIM card, a plan, a case. And one sentence, repeated often enough that it works on the day it matters: *when in doubt, don't click, talk about it.*

{/* image-sources: https://images.pexels.com/photos/5744250/pexels-photo-5744250.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/21407937/pexels-photo-21407937.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
