"Hello, we tried to reach you regarding your file. Please call back on 0 899 XX XX XX."
No link. No form. No imitation bank logo. None of the things you've been taught to spot in a fraudulent text message. Just a neutral sentence and a ten-digit number that looks perfectly ordinary.
That is precisely where this family of scams draws its strength: it never asks for your credentials. It only asks you to dial a number. The theft doesn't happen on a website, it happens on your phone bill — and sometimes it amounts to just a few euros, just enough to slip under the radar of your vigilance.

Wangiri: "one ring and cut", in Japanese
The word comes from the Japanese wangiri, literally "one ring, then hang up". The principle is disarmingly simple: an automated system dials thousands of numbers and hangs up after a single ring. All that's left on your screen is a missed call, often from an exotic international dialling code.
Curiosity does the rest. You call back, land on hold music, a synthetic voice asking you to wait, a message announcing that "your correspondent is about to be connected". Every second spent waiting is billed at a premium rate, and part of that money flows back to the fraudster via the operator running the number range.
The variants have grown more sophisticated. The plain missed call is now often paired with — or replaced by — a text message, which is more persuasive:
- "You have received a new voicemail. Listen to it on 0 8XX…"
- "Your parcel could not be delivered, contact our service on…"
- "A relative tried to reach you urgently. Call this number back."
- "Your pension file requires adjustment. Dedicated service: 0 8XX…"
The message asks for nothing illegal, contains no suspicious link, and therefore slips past a good many anti-spam filters that hunt for malicious URLs. It's smishing without a visible hook.
How to spot a number that will cost you dearly
In France, the pricing of special-rate numbers is regulated by Arcep (the regulatory authority for electronic communications, postal services and press distribution). The system, known as "SVA" (value-added services), relies on a theoretical colour code and on prefixes that are well worth memorising.
| Prefix | Type | What it costs |
|---|---|---|
| 0 800 to 0 805 | Freephone number | Free from landlines and mobiles |
| 0 806 to 0 809 | "Grey" number | Cost of a standard call, deducted from your plan |
| 0 810 to 0 811 | Moderately premium | Call charge + up to €0.06/min |
| 0 899 / 0 897 / 0 890 | Highly premium | Up to €3 per call + €0.80/min |
| 118 XYZ | Directory enquiries | Often more than €2.50 per call |
| Dialling codes +225, +371, +252… | International | Outside your plan, sometimes several euros a minute |
A legitimate public service will never charge you a premium-rate call to process your file. Under French consumer law, government bodies and after-sales services are required to offer a non-premium number for following up ongoing cases. In other words: if you're asked to call back a 0 899 number to "sort out" anything at all, it's a fraud, without exception.
The international trap is trickier. A missed call starting with +225 (Ivory Coast), +216 (Tunisia), +371 (Latvia) or +252 (Somalia) can look legitimate if you have family abroad. Fraudsters exploit these ranges precisely because they look like ordinary numbers and because revenue sharing on call termination there is particularly lucrative.
The quiet cousin: the premium-rate SMS subscription
There is a second mechanism, even more insidious, which doesn't even require you to pick up the phone: subscription-based SMS+ services.
The typical scenario: you receive a message offering a personality test, a horoscope, a "prize to claim", or access to some kind of content. You reply "YES" or "STOP" — sometimes even just "OK" — and you have just approved a subscription billed at several euros a week, straight onto your operator's invoice.
The system isn't illegal in itself: SMS+ is an official payment method, regulated by the Association française du multimédia mobile. The problem is its misuse. Fraudulent subscriptions rely on consent obtained through confusion, on landing pages with pre-ticked boxes, or on booby-trapped texts that present the reply as an opt-out when it is in fact an opt-in.
The warning sign is always the same: an unfamiliar line on your itemised bill, labelled "multimedia purchase", "SVA service" or "partner content". Many subscribers never look at their itemised bill. That is exactly what the fraudsters are counting on: €4.99 a week goes unnoticed for months.
The official site infosva.org, run by industry players under Arcep's supervision, lets you identify free of charge the provider behind any special-rate number or SMS short code. A reflex worth having before you call anything back.

Why this scam holds up so well
Wangiri has survived for more than fifteen years while other frauds have run out of steam. Three reasons explain its longevity.
The amount is calibrated to stay below the complaint threshold. Losing €6 doesn't trigger legal action. You shrug, promise yourself you'll be more careful, and move on. Multiplied by tens of thousands of victims every month, the business model is excellent — and carries virtually no immediate criminal risk for the operator hosting the number abroad.
The chain of responsibility is diluted. Between the fraudster, the operator leasing them the number range, the transit operator and your own provider, the money crosses several countries and several contracts. Each one can legitimately claim it merely routed a call.
The call back comes from you. Unlike cold calling — now subject to explicit prior consent — it's the victim who dials the number. Legally, that nuance changes everything: you are deemed to have initiated the communication.
A missed call is never an emergency. If someone genuinely needs you, they'll call again, leave a voicemail, or reach you through another channel. Silence is your best defence.
The moves that stop the scam dead
Before: shrink your exposure
Your number gets around. It has been typed into forms, resold by data brokers, or exposed in customer database leaks. You can't take it back, but you can limit the damage.
- Never call back a number received by text. Look up the official number of the organisation yourself, on its website, or on a contract document you already have.
- Turn on call filtering on your smartphone. Both Android and iOS offer an option to automatically silence unknown numbers and send them to voicemail. It's the most effective defence against Wangiri, since it removes the temptation to satisfy your curiosity.
- Ask your operator to block premium-rate services. All the major French operators allow you, on a simple request to customer service, to block calls and texts to premium-rate numbers and value-added services. It's free, reversible, and it secures a line for the long term — particularly useful on an elderly parent's or a teenager's phone.
- Check your itemised bill once a quarter. Five minutes are enough to spot a "multimedia purchase" line that has no business being there.
For a line used by an elderly person, a large-button mobile phone with simplified functions mechanically reduces the risks: fewer screens, fewer menus, no browser, and often a whitelist of approved contacts. Security through simplicity remains an underrated strategy.
During: you called back — now what?
If you realise mid-call that something is off — endless hold music, a robotic voice, an invitation to "please hold a few moments longer" — hang up immediately. Every second literally counts. Don't follow any voice instructions, don't press any key: fraudulent voice servers sometimes use the keys you press to validate a subscription.
Don't call back "just to check". Don't try to figure it out. Don't reply to the text, not even to insult the sender: a reply confirms your number is active and increases its value on database resale markets.

After: report and dispute
Reporting is free and it genuinely serves a purpose: it feeds the lists of numbers blocked by operators.
- Forward the text to 33700, the official platform for reporting unwanted texts and calls, run by French operators. You'll receive an automatic reply asking for the sender's number: send that too.
- Contact your customer service to dispute the billed line. Operators have refund procedures for subscriptions you never agreed to, especially if you act quickly.
- File a report on Cybermalveillance.gouv.fr, the national assistance scheme for victims of cybercrime, which documents these campaigns and points you towards the appropriate steps.
- Report the content on Pharos, the Interior Ministry's platform, if the message amounts to clear-cut fraud.
- If the loss is significant, file a complaint. Fraud is punishable under Article 313-1 of the French Criminal Code, and a modest amount is no barrier to filing.
The weakest link is still the device itself
A large share of these frauds exploits not a technical flaw but a lapse in attention: the phone checked one-handed on public transport, the cracked screen that makes the URL unreadable, the battery at 3% that pushes you to act fast to "get it over with".
A few practical precautions reduce that fertile ground. An ordinary tempered glass screen protector keeps the display legible and lets you tell a dubious domain name from a legitimate one — the difference between ameli.fr and ameli-remboursement.info can come down to a handful of pixels. A backup power bank prevents decisions made in the panic of a dying phone. And for those managing several lines, a secure paper address book remains the most reliable way to keep the real numbers of your bank, your operator and your insurer — the ones you should dial yourself rather than the ones a text whispers to you.
To dig deeper into the psychological machinery behind these campaigns, a practical guide to everyday cybersecurity offers useful perspective: understanding why we fall for the trap is worth more than memorising a list of forbidden numbers, which changes every six months.
Key takeaways
Wangiri and premium-rate call-back texts form a category of their own in the mobile fraud landscape. They're after neither your password, nor your card number, nor your banking verification code. They exploit a perfectly legal infrastructure — value-added service pricing — by hijacking it with a simple lie about the reason for the call.
The defence comes down to a single rule, valid in every situation: never call back a number you don't recognise, and never reply to a text asking you to call back. If the organisation is real, you'll find its number by your own means. If it isn't, you've just saved yourself several euros and a lot of time.
And if the idea of leaving a call unanswered makes you uncomfortable, remember the translation of the word: one ring, then hang up. The scammers themselves named their method after the only gesture that matters.



