Fake school texts: canteen fees, supplies and field trips — the back-to-school trap for parents

Guide

Back to the blog
L'équipe Envoyer SMS Gratuit2 September 202611 min read
Filed underGuide

First week of September. You've filled in fourteen forms in three days, ticked a box for the class photo, paid a membership fee to the school co-op, and created an account on a family portal whose password you've already forgotten. Your phone buzzes: "Canteen service — negative balance detected on your child's account. Settle before 08/09 to maintain access to the school restaurant: [link]".

It doesn't strike you as absurd. You did in fact pay for something last week, without being entirely sure it was the canteen. You can't remember whether the direct debit was renewed. And the thought of your child sitting there with no lunch on Thursday is enough to tip the scales.

School smishing relies on no technical feat whatsoever. It relies on something far more mundane: in September, parents have lost track of their own paperwork.

Woman sitting on a bed, looking worried, checking her mobile phone near a staircase

Why the start of the school year is the perfect window

SMS scam campaigns follow the calendar. Fake parcel notifications spike in November and December, fake fines after long weekends, fake tax refunds over the summer. September belongs to school — and the ground is particularly fertile, for three reasons.

The volume of legitimate messages is abnormally high. Between the school-life app, the town hall's family portal, the parents' association, the sports club and the school bus operator, a family can receive a dozen official communications in a fortnight. A fraudulent message slipped into that stream doesn't stand out.

Payment channels are fragmented. Depending on the municipality, canteen fees are paid through a council portal, via a private provider, by direct debit, by card, or through a local authority collection office. No parent knows their town's provider by heart. That perfectly normal ignorance is exactly what the scammer exploits: he doesn't even need to impersonate the right organisation, since you don't know which one to expect.

A child is at stake. That's the real difference with a fake bank text. You can put off checking an account until tomorrow. You don't put off something that could leave your child without a meal, keep them from a school trip or exclude them from an activity. The lever isn't the fear of losing money, it's the fear of being a bad parent.

The most common scenarios this year

The wording changes, the mechanics stay the same. Here are the variants that show up most often in back-to-school reports.

PretextTypical messageWhat you're really being asked for
Unpaid canteen fees"Negative balance, settle within 48 h"Card details on a fake portal
Supplies or textbooks"Textbook order incomplete, balance due"Small payment + banking data
School trip / travel"Trip deposit not recorded"Transfer to a fraudulent IBAN
School insurance"Mandatory certificate missing, subscribe here"Bogus policy + full identity
School transport"Bus pass not validated, reactivate your badge"Regional portal credentials
Class photo"Your photo order is expiring"Payment on a cloned site
School digital account"Your access will be deactivated, log back in"Credentials reusable elsewhere

Two trends deserve special attention.

The first is the financial-aid scam. Messages announce an outstanding back-to-school allowance payment, a "canteen bonus" or a county grant to claim. The principle is the same as with fake refunds from the CAF or the health insurance fund: you're promised money in order to obtain your bank details and ID document, which will then be used to open a line of credit or divert genuine payments. Let's be clear: the back-to-school allowance is paid automatically by the CAF or the MSA to eligible families, with no procedure by text message and no link to click.

The second is the urgent message supposedly sent by the school: "incident on school premises, read the notice to families", with a link. That pretext doesn't ask for money. It aims to get an app installed or credentials harvested, leaning on an emotion that short-circuits all reasoning. No school ever sends a safety alert via an external link from an unknown mobile number.

What makes these messages believable

The sender's name proves nothing

Many of these texts display a text sender name — "SCHOOL", "CANTEEN", "TOWN HALL" — rather than a number. This header forgery, or spoofing, is technically trivial to pull off via certain international gateways. Worse: when the displayed name matches a sender already in your history, the fake message can slot into the same conversation as genuine texts from the school, right below the legitimate message you received the previous week.

That's the point parents discover with the most astonishment. The message thread is not proof of authenticity: your phone groups messages by displayed name, not by verified identity.

Personal details prove nothing either

Some messages cite the child's first name, the town, sometimes the school's name. That seems impossible without access to the school's files — and yet this data circulates: data breaches at after-school activity providers, association mailing lists, activity sign-ups, social media where parents post photos and school names every September. A first name the sender knows is not a signature.

The rule that always holds: an accurate detail in a message does not validate the message. It only validates that the sender got hold of that detail, one way or another.

The amount is deliberately trivial

€12.40. €6.90. €23. The sums demanded are calibrated not to trigger suspicion: too small to be worth phoning the town hall about, plausible enough to match a few meals. The payment is almost never the point. The point is capturing your card number, its expiry date and the security code on a cloned page — data that will later be used for far heavier transactions, with authorisation hijacked by a fake adviser who will call you a few days later.

Young woman sitting in front of a laptop, looking at her smartphone screen held in both hands

The thirty-second check

You don't need to be an expert. You need one single habit: never use the route the message offers you.

  1. Don't click the link. Not even to "just have a look". Some pages attempt an automatic download on Android.
  2. Open the usual portal yourself. Through the app you already have installed, or your saved bookmark, or by typing in the town hall's address. If there really is an outstanding balance, it will show up there.
  3. Call the school office or the town hall's education department on the number printed on a paper document you received at the start of term — never the number in the text.
  4. Look at the link's domain without opening it, using a long press that displays the URL. Official French addresses end in .gouv.fr, the municipality's .fr, or the name of a known provider — not exotic suffixes or endless domain names.
  5. Ask another parent. A message to the class parent representatives is often enough to find out in thirty seconds whether the whole class got the same text.

That last point is underrated. School smishing campaigns are sent en masse: if your next-door neighbour received the same message even though their child is at a different school, the doubt is settled instantly.

The aggravating factor: the child's phone

September is also the month when many children get their first device. And fraudulent messages don't stop at parents: teenagers get their own versions — fake game codes, fake mobile plan offers, fake competition wins — and they are statistically quicker to click.

Three precautions are worth more than a long lecture:

  • Set up filtering for unknown senders in the Messages app (both Android and iOS offer automatic sorting of messages from unsaved senders).
  • Disable app installation from outside the official store on Android devices.
  • Keep passwords on paper: a password notebook kept at home remains, for many families, safer than a "codes.txt" file in the phone's notes app.

And if the device is meant for very limited use, a simple big-button mobile phone, with no browser and no app installation, mechanically shrinks the attack surface — the booby-trapped message can still arrive, but it leads nowhere. It's also the solution many families adopt for a grandparent who receives these same messages without the reference points to sort them.

Securing the device that receives these messages

A smartphone that serves as the sole gateway to the family's administrative life deserves a few basic, often overlooked physical precautions.

Keep the system updated. Most phishing pages exploit credulity, not vulnerabilities — but those that try to install spyware target old, unpatched versions.

Protect the screen and the casing. A cracked phone ends up being replaced in a rush, often by restoring backups hastily and reinstalling apps at random: that's when security mistakes creep in. A tempered glass screen protector and a shockproof case are hardly glamorous, but they head off that kind of rushed transition.

Watch the battery. A device that dies at the wrong moment cuts you off from your banking apps and two-factor authentication, precisely when you need to check something. A compact power bank in your bag solves the problem for the school day.

Young blonde woman with sunglasses checking her smartphone outdoors against a green grass background

If you clicked, or paid

The worst reflex is staying silent out of shame. These messages are designed by professionals to fool attentive people; getting caught is not a failure of intelligence.

Within the hour:

  • Contact your bank to block the card used and report the transaction.
  • Change the password for the portal concerned, and for any other service where you used the same one.
  • Don't answer any incoming call claiming to be from your bank: the fake adviser almost always turns up after the data has been entered.

In the following days:

  • Report the message to 33700, France's official reporting platform for fraudulent texts (forward the text to 33700, then send the sender's number when prompted).
  • File a complaint, online or at a police station. Banks often require the receipt.
  • Consult Cybermalveillance.gouv.fr, which offers a guided diagnosis and points you to the appropriate steps, and the Info Escroqueries service (0 805 805 817), free of charge.
  • Tell the school: it can alert other families, which shuts down the campaign far more effectively than an isolated report.

Article L. 133-18 of the French monetary and financial code provides for reimbursement of unauthorised transactions, except in cases of gross negligence by the customer. Deliberately entering your codes on a fraudulent site is often classified as negligence by banks, but case law has shifted in favour of victims of convincing spoofing. Stand your ground, and don't hesitate to refer the matter to the banking ombudsman if you're refused.

The reflex to install once and for all

The start of term will pass, and the pretexts will change: Halloween, Christmas presents, January sign-ups, spring school trips. What won't change is the structure of the trap.

A real organisation + a short deadline + a small amount + a link. As soon as those four elements coexist in the same message, treat it as fake until proven otherwise — and go looking for that proof somewhere other than in the message itself.

Explain it to your children, to your parents, to the other families in the class. A general-audience book on family cybersecurity can help lay the groundwork with teenagers, but the essential fits in a single sentence anyone can remember: you never verify a message with the message.

And if you need to warn other parents quickly that a campaign is doing the rounds, a simple text sent from an online service, with nothing to install, does the job perfectly. The best collective defence against a smishing campaign is still the speed at which the information travels between neighbours.

Free SMS · No sign-up · To France

Envoyez votre SMS gratuit en quelques secondes

Pas de compte à créer, pas de publicité, pas de limite : écrivez votre message, indiquez le mobile, et envoyez-le gratuitement depuis votre navigateur.

Envoyer un SMS gratuit