"URGENT — Our teams are on the ground. Every €10 donation provides 3 days of clean water for a family. Support us: don-solidarite-urgence[.]org — Thank you for your generosity."
No threat. No 48-hour deadline. No late fee. Just a sentence that puts you on the right side of the story, and a link promising to turn your vague guilt into a concrete gesture.
That is precisely what makes this text message so dangerous. Every smishing campaign we learn to recognise — the unpaid fine, the held parcel, the suspended bank account — relies on fear. The brain eventually associates "unexpected text + stress" with "scam". The fake donation appeal bypasses that reflex entirely: it doesn't frighten you, it pleases you. And a reader who feels generous doesn't feel at risk.

A fraud that shadows the news cycle
Fake donation campaigns aren't continuous: they are event-driven. They appear within 24 to 72 hours of a major news event, when media coverage is at its peak and verification is hardest.
The classic triggers:
- a widely reported natural disaster (earthquake, flooding, wildfires);
- a conflict or humanitarian crisis dominating the evening news;
- a heavily discussed local tragedy (an accident, a disappearance, a fundraiser for a family);
- the high points of the French charity calendar: the winter appeals from organisations helping the most vulnerable, the Téléthon, year-end food drives, the December tax-deduction window.
That last point is underrated. In December, millions of French households genuinely make a donation to claim the tax reduction provided for under Article 200 of the General Tax Code. A donation text received on 20 December is nothing out of the ordinary: many legitimate charities really do reach out at that time. The scammer slips into an existing flow, which is always the best position a fraudster can occupy.
Cybermalveillance.gouv.fr, the French public service that assists victims of cybercrime, regularly points out that phishing by text message — smishing — is among the threats most reported by private individuals, and that fraudsters systematically tailor their pretexts to current events. Charity is simply one of the easiest costumes to put on: it requires neither a complex official logo nor a credible case reference number.
What the scammer is really after
We tend to assume the goal is to pocket your €20 donation. That is the least profitable scenario for them, and yet the most reassuring one for you. The reality is often broader.
The diverted one-off donation
The simplest version: the payment page takes the money, thanks you warmly, and sometimes even sends a fake tax receipt as a PDF. The victim notices nothing for months — until tax return time, when the authorities don't recognise the organisation.
Harvesting card details
The "donation" form asks for the card number, the expiry date and the security code. Once those three elements are obtained, the amount actually charged bears no relation to the €10 announced. Some pages take the trickery further by pre-ticking a "monthly donation" box, which makes the recurring debit look perfectly legitimate to the bank.
The hijacked authentication approval
This is the costliest variant. You enter your card details, a genuine confirmation code arrives from your bank, and you approve it in your banking app believing you are confirming a donation. Except the transaction you are authenticating is not the one shown on screen. Because you approved it yourself in your app, disputing it afterwards becomes considerably harder.
Profiling you
Even without a payment, simply clicking and starting to fill in the form signals that your number is active, that you are receptive to humanitarian causes, and often that you belong to a particular age bracket. That profile gets resold. This is how someone who clicked once then starts receiving three charity texts a week, followed by phone calls from unknown "foundations".
A simple rule: clicking a fraudulent link doesn't only cost you what you pay that day. It also costs you the place your number will now occupy in the files traded between scammers.
The signs that give away a fake donation appeal
The message is short, polite, with no glaring spelling mistakes. The era of badly translated text is largely over. So you have to look elsewhere.
The domain name. This is checkpoint number one. Major French charities use short, stable domains: croix-rouge.fr, restosducoeur.org, secourspopulaire.fr, unicef.fr, medecinsdumonde.org, fondation-abbe-pierre.fr. A link along the lines of don-croixrouge-urgence.net, soutien-restos2026.info or secours-populaire-france.help is a fake, however plausible it may look. Scammers exploit added hyphens, exotic extensions and misleading subdomains.
The absence of an alternative channel. A genuine fundraising campaign always leaves you several doors: the official website, a phone number, a paper form, a donation by cheque. A text that offers only its link, never mentioning the charity's main website, is suspect by design.
Hyper-specific emotional urgency. "Only 4 hours left to fund the blankets." Serious charities communicate about programmes, not about countdowns measured to the hour.
The payment method. No recognised charity asks for a donation via instant transfer to a private individual's IBAN, by gift card, in cryptocurrency, or through a peer-to-peer payment link. That is an immediate deal-breaker.
The displayed sender. The name shown at the top of your screen proves absolutely nothing. Spoofing — faking the sender ID — makes it possible to display "CROIX-ROUGE" or "UNICEF" instead of a number. Worse still: the fraudulent message sometimes lands in the very same conversation thread as the organisation's genuine texts, which gives it maximum credibility.
The three-minute check, stress-free
The good news is that a donation is never urgent. Nobody loses out by giving thirty minutes later. That available time is your best weapon.
- Don't touch the link. Not even to "have a look". Some pages trigger redirects or try to install an app.
- Open the charity's website yourself, by typing its name into your browser. If the campaign announced by text exists, it will be on the homepage. If it isn't there, you have your answer.
- Check that the organisation is authorised to issue a tax receipt. The charity's website states this, and the tax authorities set out the conditions for the donation tax reduction on impots.gouv.fr.
- Consult the Comité de la Charte / Don en confiance, the French voluntary accreditation body for charities that appeal to public generosity. Its online directory lists accredited organisations. It isn't an absolute guarantee — plenty of honest charities aren't accredited — but it's a useful benchmark.
- Give through the channel you chose, never through the one offered to you.
For those who prefer a paper trail, keeping an A5 notebook within reach to record donations made, the date and the organisation avoids duplicates and makes the spring tax return far easier.
The special case of legitimate SMS donations
Genuine text-message donation campaigns do exist in France, governed by the telecom operators. They follow a very recognisable pattern: you are asked to send a keyword to a five-digit short code (typically 92xxx), and a fixed amount is charged to your phone bill or prepaid credit.
The differences from fraud are clear-cut:
| Legitimate SMS donation | Fake donation appeal |
|---|---|
| You send the message, you take the initiative | You receive an unsolicited message |
| 5-digit short code, publicly announced | Web link to an unknown domain |
| Fixed, stated amount (€5, €10…) | Open amount, bank card form |
| No banking details requested | Card, security code, sometimes ID document |
| Campaign publicised on TV, radio and posters | Campaign known only to you, by text |
Remember the most important line: a legitimate SMS donation never asks for your bank card in a web form opened from a link you received.
Why older relatives are especially exposed
It isn't a matter of gullibility, it's a matter of the sociology of giving. Studies of generosity in France consistently show that regular donors are predominantly people over 60, often loyal to two or three charities for decades. They are used to being solicited — by post, by phone, by email — and that constant stream makes one extra request feel perfectly ordinary.
There's also a practical factor: reading a full web address on a smartphone screen, with its hyphens and its extension, requires visual acuity and technical ease that can't be taken for granted. Many users see "croix-rouge" in the URL and stop there. On this point, increasing the phone's font size in the accessibility settings changes more than any software ever will: larger text makes the fraudulent domain visible. An LED lighted magnifier kept on the living-room table does the same job for paper mail, which remains the main channel for charity appeals.
For relatives equipped with a device that overwhelms them, a big-button mobile phone mechanically shrinks the attack surface: no modern browser, no payment form, no app installation. The fraudulent text still arrives, but it leads nowhere.
Ultimately, the conversation matters more than the equipment. Agreeing on a simple family rule — "we never give from a link, we always give from the website or by cheque" — protects better than a list of warning signs to memorise. A practical guide to online scams left beside the phone acts as a discreet reminder, without feeling like surveillance.
What to do if you have already given
The most important reflex is the first one: don't waste time feeling ashamed.
- Contact your bank immediately to block the card used. The card-blocking service is reachable 24/7. Explicitly ask for the card to be blocked and the transactions disputed.
- Stop approving any notifications from your banking app in the hours that follow. If an approval request appears without you having initiated anything, refuse it.
- Report the text to 33700, the national reporting service for unwanted texts and calls: forward the message to 33700, then reply with the sender's number when prompted. The service is free.
- Report the fraudulent address on Phishing Initiative (phishing-initiative.fr) and file a report on the official THESEE platform, accessible from service-public.fr, dedicated to online fraud.
- File a complaint at a police station or gendarmerie. This is often essential in order to obtain a refund.
- Warn the impersonated charity. Major organisations have dedicated teams and file complaints of their own; your report feeds into their efforts.
On refunds, Article L133-18 of the French Monetary and Financial Code sets out the principle: in the event of an unauthorised payment transaction, the bank must immediately refund the payer. The sticking point is "gross negligence" — hence the importance of documenting precisely what you entered and approved. Keep screenshots of the text, the payment page and your exchanges with the bank. A portable external hard drive or a simple archived folder lets you keep this evidence off the phone, in case it gets reset.
Giving is still a good idea
It would be absurd to conclude that we should stop giving. French charities have in fact observed an unpleasant side effect of these frauds: general distrust ends up eroding legitimate donations, including those made through perfectly safe channels.
The right stance isn't suspicion, it's controlling the channel. Choose two or three causes yourself, go to their websites, set up a regular donation or note down their contact details, and assume by default that any unexpected incoming approach — text, email, call, message on a chat app — is nothing more than an invitation to go and check elsewhere.
A scammer needs you to click within their frame. The moment you decide that the giving will happen within yours, the scam loses all traction. And your generosity reaches its destination.



