"You Have a New Voicemail": The Fake Voicemail Scam That Drains Bank Accounts

Guide

Back to the blog
L'équipe Envoyer SMS Gratuit31 August 202610 min read
Filed underGuide

You're walking out of a meeting, or leaving the doctor's office. Your phone buzzes: "You have received 1 new voicemail. Listen to it: [link]". Nothing alarming. Nobody is threatening you, nobody is demanding €2.99, there's no parcel stuck in customs. Just someone who tried to reach you while you were unavailable.

That is exactly why it works.

Over the past two years, the voicemail notification has established itself as one of the most profitable lures in smishing in France. It triggers neither fear nor excitement — the two emotions we've been taught to spot. It triggers something far harder to fight: ordinary curiosity.

Seated man looking at a smartphone held in both hands, a blue pen between his fingers

Why this particular message slips under every radar

Awareness campaigns — those run by Cybermalveillance.gouv.fr as much as those run by banks — rest on a checklist of warning signs: urgency, threats, spelling mistakes, requests for money, unknown sender. The fake voicemail ticks none of those boxes.

Look at what it actually offers:

  • No urgency. A voicemail is waiting. It will still be waiting tomorrow. There's no countdown, so no suspicion is triggered.
  • No transaction. You aren't asked for a bank card, a transfer, or proof of identity. At least, not right away.
  • A 100% plausible premise. You're bound to have missed calls this week. The message doesn't even need to be credible: it is, mechanically.
  • A familiar gesture. Listening to voicemail has been part of the routine of every phone user for thirty years.

Add to this the fact that several French carriers send genuine voicemail notifications by text, sometimes with a link to their "visual voicemail" service. Users are left with no reliable way to tell the real from the fake. They've been taught to distrust links, yet their own carrier keeps sending them.

The rule that still holds: a legitimate voicemail is listened to from your own phone, by calling your voicemail number or using your carrier's official app. Never from a link received by text.

What happens after the tap: three scenarios

The link doesn't always lead to the same place. Fraudsters test, segment and adapt according to the operating system detected by the landing page. Three families of consequences dominate.

1. The credential harvesting page

This is the simplest version. The link opens a page that mimics your carrier's interface: logo, colours, legal notices copied and pasted. The message never varies: "Log in to your account to listen to your message."

You enter your username and password. They go straight to the scammer. And a carrier account is a goldmine: it holds your address, your bank details, your itemised billing, and above all the ability to order a new SIM card or change your options. At that point we're in SIM-swap territory.

2. The app you're asked to install

A more aggressive version, aimed mainly at Android. The page states that "listening requires the Visual Voicemail app" and offers a file to download from outside the Play Store.

The installed file is a banking Trojan. The families known to security researchers — variants descended from FluBot, dismantled in 2022 by Europol but widely copied since, or Anatsa-type strains flagged by several antivirus vendors — all work on the same principle:

What the app asks forWhat it actually does with it
Access to text messagesIntercepts banking verification codes
Access to contactsForwards the same booby-trapped text to your entire address book
Accessibility serviceOverlays fake login screens on top of your real apps
Display over other appsCaptures what you type, including passwords

It's that last point that makes the whole thing so serious: the victim doesn't lose money at the moment of the tap, but three days later, when they open their banking app and enter their credentials on a perfectly imitated fake screen.

3. Redirection to a premium-rate number

A more discreet variant: the link displays a "Call voicemail" button that dials a number starting with 0899 or 0891. The call is billed at several euros a minute, with a recorded voice keeping you on hold as long as possible. The loss is modest, a few dozen euros, but massive across an entire campaign.

The warning sign almost nobody looks at: the address

A genuine voicemail never points to an exotic domain. Fraudsters use short addresses, often registered the day before, that borrow reassuring words.

Examples of patterns spotted in recent campaigns:

  • messagerie-vocale-espaceclient.xyz
  • repondeur-orange-fr.info
  • voicemail-sfr.online
  • generic link shorteners that hide the real destination

The useful reflex fits in one sentence: the domain name is whatever is written just before the first /. In orange.fr-messagerie.xyz/ecoute, the domain isn't orange.fr, it's fr-messagerie.xyz. Everything before it is set dressing.

On a smartphone screen, reading this is painful: the address bar is short, the text tiny, and half the URL is truncated. That's one reason mobile fraud works better than email fraud. For anyone squinting at their screen, an adjustable-height phone stand sitting on the desk genuinely changes things: you read an address calmly instead of guessing at it at arm's length.

What to do, in practice, when this text arrives

Doing nothing is already a valid response

If you're unsure, ignore the message and call your voicemail the normal way. On virtually every French line, you simply dial 888 (Orange), 123 (SFR), 660 (Bouygues) or 740 (Free) — or press and hold the 1 key. If there's a real message, it's there. If there's nothing, you've just closed your investigation in eight seconds.

Report it to 33700

Forward the suspicious text to 33700, the official reporting platform for fraudulent texts and calls, run by the carriers under public authority oversight. The service replies asking for the sender's number: forward that too. It's free, and it's what leads to sending numbers being shut down.

You can also file a report on Cybermalveillance.gouv.fr, and for a fraudulent website, on the Phishing Initiative platform or via internet-signalement.gouv.fr (PHAROS).

Block and delete

On both iPhone and Android, blocking a sender takes two taps from within the conversation. It won't stop the campaign — fraudsters change numbers every hour — but it cleans up your message thread and prevents a less vigilant relative you lend the device to from tapping the link by accident.

If you've already tapped the link

The tap alone, with nothing entered or installed, is rarely a disaster. The danger starts at the next step. Here's the order of operations.

  1. Cut off the network. Airplane mode immediately, long enough to regain control. This interrupts any data exfiltration in progress.
  2. Check your list of installed apps. Settings → Apps, sorted by installation date. Any unknown app that appeared in the minutes after the tap must be uninstalled. On Android, if the app refuses to be removed, restart in safe mode.
  3. Change the relevant passwords, starting with your carrier account, your email and your bank — from another device, not from the suspect phone. A laptop at home does the job perfectly.
  4. Alert your bank. Have your card blocked if you entered banking details. Remember that Article L133-18 of the French Monetary and Financial Code requires reimbursement of unauthorised transactions, unless the bank can demonstrate gross negligence.
  5. Warn your contacts. This kind of software spreads through the address book: a simple group message saying "don't tap anything I sent you" prevents a dozen secondary victims.
  6. File a complaint if you've suffered a financial loss, attaching screenshots of the text and of the transactions.

For the most serious cases — a malicious app installed several days ago, persistent abnormal behaviour — a full factory reset of the phone remains the only guarantee. Hence the value of having your data already safe: an external hard drive for smartphones or simply an active cloud backup turns a catastrophe into an unpleasant afternoon.

Protecting a relative who receives a lot of these messages

The most exposed people aren't the least intelligent; they're the most solicited and the most alone in front of the screen. An elderly parent who gets three notifications a day will, statistically, end up opening one.

A few effective levers, in order of return:

  • Turn on the built-in spam filter. On iPhone: Settings → Messages → Filter Unknown Senders. On Android, Google Messages has offered enhanced protection against dangerous links since 2025 — check that it's active in the security settings.
  • Disable installation of apps from unknown sources on Android. That's the lock that blocks 90% of the Trojans described above.
  • Agree on a single reflex: "if in doubt, send me a photo of the message before you touch anything." No complicated rules, just one.
  • Simplify the hardware where it makes sense. For use limited to calls and texts, a large-button senior phone removes the web browser attack surface entirely.
  • Put the knowledge on paper. A practical guide to digital safety left on the coffee table gets consulted far more often than a link sent by message, especially by people who are already wary of screens.

What this scam teaches us about all the others

The fake voicemail isn't technically sophisticated. Its strength lies elsewhere: it slots into a habit instead of disrupting one.

That's the major shift in mobile fraud over the last two or three years. The first waves of smishing shouted: account blocked, unpaid fine, parcel held. They played on panic, and panic eventually educates — you get used to it, you develop antibodies. Today's campaigns do the opposite: they whisper. A voicemail, an app update, an appointment confirmation, a refund of a few euros. Nothing alarming, therefore nothing to examine.

Against that, a checklist of warning signs is no longer enough. It has to be replaced by a rule of the road, far simpler to remember and to pass on:

Never reach a service by the route a message offers you. Go by the route you already know: your voicemail number, your installed app, the address you type by hand, your adviser's direct line.

This rule requires no technical skill. It doesn't depend on the quality of the fake, the spelling, the logo or the domain name. It works just as well against the fake voicemail as against the fake courier, the fake bank or the fake tax office. And it has the merit of fitting into a single sentence you can repeat to a teenager or a grandparent alike.

The next text announcing a voicemail will arrive. Maybe tomorrow. The right response won't be to guess whether it's genuine: it will be to call your voicemail, the way we all did before anyone thought of sending you a link.

Free SMS · No sign-up · To France

Envoyez votre SMS gratuit en quelques secondes

Pas de compte à créer, pas de publicité, pas de limite : écrivez votre message, indiquez le mobile, et envoyez-le gratuitement depuis votre navigateur.

Envoyer un SMS gratuit