"Hello, my name is Léa, I work for a partner recruitment agency. We've reviewed your profile. Remote assignment, 30 minutes a day, pay between €150 and €400. Interested? Reply YES."
Tens of thousands of people receive this message every week in France. It never lands at the right moment by chance: it arrives during a job search, after a layoff, at the end of a difficult month, or on the phone of a student looking for extra income. And unlike the fake delivery text, it asks for nothing right away. No link, no code, no payment. Just a "YES."
That is precisely what makes it effective. The fake recruitment scam isn't trying to make you click within seconds. It's trying to open a conversation. And a conversation can be worked on over several days.

A fraud that doesn't look like a fraud
Classic smishing campaigns — phishing by text message, as Cybermalveillance.gouv.fr defines it — rely on urgency: a parcel on hold, a fine to pay, a suspended account. They want immediate action before the brain catches up with the reflex.
Fake recruitment works the other way around. It builds a relationship.
The person replying to you is friendly, patient, available in the evening. They ask for your first name, your availability, sometimes your age. They explain that they're "forwarding your file to a training manager." You're moved onto an encrypted messaging app — usually WhatsApp or Telegram — on the pretext that "it's easier for sending documents."
That switch is the first genuine red flag, and the most underestimated one. No legitimate recruiter in France runs a hiring process exclusively through a personal messaging app, with never a professional email from a verifiable domain name, never a video interview, never an identifiable contractual document.
France Travail (formerly Pôle emploi) regularly warns about these impersonations: its name, its logo and sometimes even real advisers' phone numbers are hijacked in these campaigns. The DGCCRF (France's consumer protection and fraud authority) ranks fake work-from-home jobs among the most reported online scams, alongside bogus financial investments.
The four variants circulating in 2026
1. The "rating" or optimisation job
This is the most widespread version. You're given an absurdly simple task: liking videos, rating hotels, "boosting" product listings on a platform. You're genuinely credited €20 or €30 in an internal account. You withdraw it. It works.
Then come the "grouped missions": to unlock a more lucrative batch, you have to put money in first. €50, then €200, then €800. At each step the displayed balance climbs beautifully, and at each step an obstacle appears: a tax, a handling error that "freezes the account," a threshold to reach. You never get anything back.
This mechanism has a name in English-language policing literature: task scam. It exploits loss aversion — the more you've paid in, the more psychologically costly it becomes to stop.
2. Fake recruitment that harvests your identity
Here, no money is requested. You're simply asked, "to complete your file," for a copy of your ID, your bank details, a proof of address, sometimes a selfie holding your identity card.
That's the jackpot. This trio makes it possible to open online bank accounts, take out consumer loans, and set up mobile phone lines in your name. Identity theft is often discovered months later, through a debt collection letter.
3. The money mule disguised as a job
The role is called "transfer agent," "financial logistics officer," "treasury assistant." The mission: receive money in your personal account, withdraw part of it, transfer it elsewhere, keep a commission.
That's money laundering. The person recruited isn't just robbed: they become legally complicit. In France, money laundering is punished under Article 324-1 of the Penal Code by five years' imprisonment and a €375,000 fine. Victims end up with a closed bank account, a Banque de France blacklisting and a court summons.
4. The fake interview that installs software
A more technical and growing variant: you're invited to an "interview" via a video-conferencing app to be downloaded from a direct link. The app is spyware or a banking Trojan. On Android, installation outside the official store (sideloading) remains the main vector.
Why it catches intelligent people
One misconception needs clearing up: these scams don't target the gullible. They target people under pressure.
A jobseeker who has sent forty applications without a reply and finally receives a positive message doesn't react like a detached observer. A parent trying to make it to the end of a tough month misjudges a financial risk. A student who has never signed an employment contract doesn't know what a normal hiring process looks like.
On top of that come three well-documented social engineering levers:
- Proof through the small win. The first €20 actually paid out is worth a thousand arguments. It turns doubt into trust.
- Reciprocity. Someone devotes time to you, encourages you, congratulates you. Saying no becomes socially uncomfortable.
- The group. You're added to a group chat where other "colleagues" post their earnings and give thanks. These are accomplices or automated accounts.
One simple rule runs through every variant: in a real job, the employer pays you. Never the other way around. Any sum requested by a "recruiter," on any pretext whatsoever — application fees, training, starter kit, unlocking tax, equipment purchase — is a scam. Without exception.

Checking an offer in five minutes
Before you even reply, a handful of checks is enough to settle most cases.
The sender's number. A professional recruiter rarely writes from a personal mobile number, and even less from a foreign dialling code (+225, +44, +212...). Be careful, though: spoofing makes it possible to display a fake French number, so a correct number proves nothing. A foreign number disqualifies; a French number is no reassurance.
The company. Search for the name in the French business directory (annuaire-entreprises.data.gouv.fr) or the national register. A company recruiting on a massive scale but with no SIREN number, no address and no website with legal notices does not exist. Also compare the email domain name: recrutement@societe-rh-france.online is not the domain of an established group.
The offer itself. Can you find the same listing on France Travail, the APEC or the company's official website? If the offer exists nowhere else, it doesn't exist.
The wording. Clumsy phrasing, random capital letters, emojis in a professional message, and the complete absence of a precise job description are constant markers.
The reverse search. Copy a sentence from the message into a search engine. These campaigns run on a loop: you'll often land on accounts from people who received the exact same message word for word.
For anyone running a serious job search and receiving a lot of approaches, keeping an application tracker — even a simple lined paper notebook — helps enormously: you note who was contacted, when, and through which channel. A "recruiter" claiming to follow up on an application you never sent gives themselves away in three seconds.
Separating your channels: the most effective measure
Most victims have one thing in common: a single phone number for everything. Family and friends, the bank, classified ads, platform sign-ups, job applications.
Compartmentalising radically changes your exposure. Two approaches:
- A second number dedicated to "public" uses. A prepaid SIM card with no commitment, slipped into a spare phone or a dual-SIM device, serves for classified ads, sign-ups and any process where the number will be circulated. The main number, the one tied to your bank and sensitive accounts, stops moving around.
- A separate device. An entry-level Android phone is more than enough for this role: it receives codes for secondary services and isolates the risks from your main number.
This separation costs almost nothing and offers lasting protection. It also prevents a number posted in a Leboncoin ad from turning up three weeks later in a database resold to fraudulent campaign operators.
On the device itself, a few settings round out the protection:
- Turn on filtering of unknown senders in the messaging app (available on both iOS and Android).
- Systematically refuse to install apps from outside the App Store or Google Play.
- Regularly review the permissions granted to apps, particularly access to SMS and accessibility services — two permissions massively abused by banking Trojans.
- Keep the system updated: monthly security patches close actively exploited flaws.
For those helping a relative who isn't comfortable with technology, a printed digital security guide left next to the device is often more useful than a long lecture: you can write down the bank's number, the 33700 shortcode, and the three rules never to break.
You've already replied: what now?
The answer depends on what you handed over.
You only replied "YES" or exchanged a few messages. Little direct damage, but your number is now flagged as "active and responsive." Expect a rise in unsolicited approaches. Block the contact, report the conversation within WhatsApp or Telegram, and forward the original text to 33700, France's official reporting platform for unwanted texts and calls (free, from every operator).
You shared identity documents. Report the potential identity theft immediately. File a complaint or a police report (main courante) — that document is what will serve you if a loan is taken out in your name. Monitor your status with the Banque de France (right of access to the FICP and FCC registers). Also report the incident on cybermalveillance.gouv.fr, which will point you to the appropriate services.
You paid money. Contact your bank without delay to attempt a block or a recall of funds, especially if the payment is less than 24 to 48 hours old. Keep every screenshot, number and statement. File a complaint. If the payment went through a bank card, cancel the card and dispute the transaction. The info-escroqueries.gouv.fr website and the number 0 805 805 817 (free) support victims.
You installed an app. Uninstall it, change the passwords of sensitive accounts from another device, and consider a factory reset if any doubt remains. Back up your personal data first — a portable external hard drive prevents losing photos and documents in the process.
You received and forwarded money. Stop immediately, notify your bank on your own initiative and file a complaint. Coming forward yourself changes everything in how the case is judged.

The sorting table, worth keeping in mind
| Signal observed | Interpretation |
|---|---|
| Unsolicited message about a job you never applied for | Strong warning |
| Rapid switch to WhatsApp / Telegram | Strong warning |
| Pay bearing no relation to the task described | Strong warning |
| Request for an upfront payment, whatever the reason | Certain scam |
| Request for ID + bank details before any contract | Strong warning |
| No video interview, no identifiable written contract | Strong warning |
| Company not found in the register / no legal notices | Strong warning |
| Task consisting of receiving then forwarding money | Money laundering |
Three signals or more: cut off the conversation, with no explanation, no negotiation. Replying to "understand" or to give them a piece of your mind only confirms that the line is active.
What to remember
The fake recruitment text scam is a patient fraud. It plays not on fear but on hope, which makes it far harder to spot than a fake bank text. It doesn't take ten seconds of your attention: it takes a week of your trust.
Three sentences are enough to guard against it for good. An employer never asks for money. A serious recruitment process leaves a verifiable trail somewhere other than an instant messaging app. And a phone number that circulates everywhere always ends up coming back in bad company.
The rest — the checks, the compartmentalising of numbers, the reflexes when something goes wrong — is nothing more than the methodical application of those three obvious truths.



