# RCS, the next-generation SMS: what this standard really changes for scams

> RCS is gradually replacing SMS on Android phones and iPhones. Verified logos, encryption, rich messages: what this standard actually protects, and the new doors it opens for scammers.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-09-06/sms-frauduleux-messagerie-rcs-chiffrement-nouvelles-menaces
- Published: 2026-09-06 (6 September 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, SMS, Smartphone, Protection des données, Guide, France 2026

---
"Colissimo — Your parcel could not be delivered." The message pops up, but something has changed. Next to the sender's name sits a small round logo in the company's colours. Below it, a blue tag: "Verified." And three suggested buttons: "Track my parcel," "Reschedule," "Contact customer service."

This is no longer an SMS. It is an RCS message — and it looks far more like a WhatsApp conversation than the plain 160-character text we have known for thirty years. Ever since Apple built the standard into iOS in late 2024 and Google rolled it out broadly on Android, your phone's native messaging app has quietly changed its nature. Most users never noticed a thing.

This shift is good news for security. But it also creates a dangerous situation: a public learning to trust little logos and "verified" badges without knowing what they actually guarantee — and, above all, what they do not.

![Smartphone lying on a wooden table showing a dialler screen with an unknown number typed in](/images/blog/2026-09-06-sms-frauduleux-messagerie-rcs-chiffrement-nouvelles-menaces/hero.jpg)

## RCS: what exactly are we talking about?

The acronym stands for *Rich Communication Services*. It is a standard promoted by the GSMA, the global association of mobile operators, designed as far back as 2008 to replace SMS and MMS, which had become technically archaic next to internet messaging apps.

In practical terms, RCS delivers four things SMS never could:

- **Messages with no size limit**, including photos, videos and files at full resolution;
- **Read receipts and the "typing" indicator**, just like app-based messengers;
- **Delivery over the internet** (Wi-Fi or mobile data) rather than through the phone network's signalling channel;
- **Identified business senders**, complete with logo, full name, brand colour and verification badge.

It is this last point that concerns us here. In the RCS ecosystem, a company wanting to message you can no longer simply pay for a gateway and type "SFR" or "CPAM" into the sender field. It has to go through a registration process: verification of its legal identity, approval of its logo, checks by the operator or by Google. This is the building block known as **RCS Business Messaging**.

On paper, this fixes the historic flaw of SMS: the complete absence of sender authentication.

## The original sin of SMS, and why RCS corrects it

You have to appreciate just how naive a protocol SMS is. Created in the late 1980s for use between subscribers on the same network, it never included any mechanism for verifying the sender. When a company sends a message, it fills in a free-text field called the *sender ID*. Nobody anywhere in the technical chain checks that field.

That is precisely what makes **spoofing** possible: impersonating the sender name. A scammer who types "AMELI" into that field will see their message land in the existing conversation thread from France's health insurance service on your phone, right underneath the genuine messages. Cybermalveillance.gouv.fr, the national support scheme for victims of cybercrime, has been documenting this mechanism for years in its factsheets on smishing.

In response, France set up the **SMS sender name registry** in October 2023, operated by the Association Française du Multimédia Mobile (AF2M) under the supervision of Arcep. Any company wanting to use an alphanumeric sender name must now declare it, and operators block messages whose sender is not registered. It is genuine progress, but it remains national in scope: messages routed through foreign gateways or fake base stations (the notorious SMS blasters) partly bypass the system.

RCS goes further, because verification is not declarative but **cryptographic and visual**: the logo and the badge are pushed by the platform, not by the sender of the message. A scammer cannot fabricate them within the text of their message.

## What the "verified" badge guarantees — and what it doesn't

This is the heart of the matter, and the source of most misunderstandings.

**What the badge guarantees:**

> The entity writing to you has provided corporate identity documents and has been validated by the platform. The logo shown belongs to it. The message was not fabricated by a third party posing as it.

**What the badge absolutely does not guarantee:**

- That the content of the message is honest. A genuinely registered commercial company can perfectly well send you a misleading offer, a subscription trap or an aggressive sales pitch. Verification covers identity, not intent.
- That the link in the message is safe. Nothing prevents a legitimate message from pointing to a compromised page.
- That every unverified message is fraudulent. Plenty of small businesses, associations, medical practices and garages still send plain SMS. The absence of a badge is not a sign of fraud.

This nuance is essential to convey, particularly to the most vulnerable audiences. We spent ten years teaching older people that "the green padlock in the browser doesn't mean the site is honest." The RCS badge is fast becoming the new green padlock: a useful clue, turned into absolute proof by those who don't know what it measures.

## The new attack surfaces opened up by RCS

Moving from plain text to rich messaging inevitably shifts the playing field. Three developments deserve attention.

### 1. The message that no longer looks like a message

A fraudulent SMS used to give itself away through sheer ugliness: typos, a strange URL in plain view, no layout to speak of. An RCS message can display an **image carousel**, action buttons, an interactive map, a brand colour. The spelling mistake is still there, but it is drowned in a polished interface that inspires confidence.

The reflex of "I check the link before clicking" also becomes harder: inside an action button, the destination URL is simply **not visible**. You tap "Track my parcel" without ever seeing where it takes you.

### 2. The return of the attachment

SMS could only carry a link. RCS carries files, up to several hundred megabytes. So mobile messaging has inherited a vector we thought belonged to email alone: the booby-trapped attachment. On Android, an APK file sent in a conversation and presented as "the app to track your case" remains one of the main ways banking spyware gets installed, as ANSSI teams and mobile security vendors regularly document.

### 3. Dependence on the internet

RCS runs over data. A message sent while you are in a dead zone or out of data allowance automatically falls back to a standard SMS — meaning no badge, no logo, no encryption. This silent fallback creates a visual inconsistency that scammers can exploit: "your message arrived in degraded mode, tap to view it." Keeping your phone charged and connected genuinely serves a security function here, which explains the popularity of [pocket power banks](https://www.amazon.co.uk/s?k=batterie+externe+compacte+pour+smartphone&tag=ds0608-21) among heavy mobile users.

![Young woman in sunglasses reading a message on her mobile phone in front of a shop window](/images/blog/2026-09-06-sms-frauduleux-messagerie-rcs-chiffrement-nouvelles-menaces/body-1.jpg)

## And what about encryption?

This is the most widely misunderstood aspect. SMS is **not end-to-end encrypted**: it travels in the clear through the operator's infrastructure, which can technically read it, and it is stored for a while on its servers. That is precisely why specialists have long advised against receiving banking authentication codes by SMS.

RCS long inherited that same weakness. Google added end-to-end encryption to its own Messages app, but only between two users of that app. Since the GSMA published the **RCS Universal Profile 3.0** in 2025, end-to-end encryption has been built into the standard itself, including between Android and iPhone. Its actual rollout depends on operating system and app updates.

Two things to remember:

| | Standard SMS | RCS (recent profile) |
|---|---|---|
| Authenticated sender | No (AF2M registry in France) | Yes for verified businesses |
| End-to-end encryption | No | Yes, depending on version |
| Transport | Operator network | Internet |
| Attachments | No | Yes |
| Readable without data | Yes | No |

Encryption protects your **private** exchanges from interception. It does absolutely nothing to protect you from a scam: a fraudster writing to you directly is writing through an encrypted pipe, which makes their lie no safer. Confusing confidentiality with trustworthiness is the most common reasoning error on this subject.

## The habits to update in 2026

The arrival of RCS makes none of the existing habits obsolete. It simply adds a few.

**1. Check the channel, not the message.** The golden rule remains unchanged: no government body, no bank, no delivery company will ever ask you to enter your credentials or bank details from a message you have received. Whatever logo is displayed, close it and go to the official website or app yourself.

**2. Press and hold rather than tap.** In most messaging apps, a long press on an action button or a link reveals the destination address without opening it. Get into the habit: it is the only way to see where an RCS button leads.

**3. Be wary of any file received in a conversation.** No public service, no French bank distributes its app anywhere other than the App Store or the Play Store. An installation file received by message is fraudulent, without exception.

**4. Look at consistency, not aesthetics.** A verified business message that addresses you over-familiarly, threatens you with a 24-hour deadline or asks you to "settle an outstanding €1.99" is suspicious no matter how it is dressed up. Urgency and micro-payments are the two most consistent hallmarks of a scam.

**5. Keep 33700 to hand.** France's national reporting service for fraudulent texts and calls, run by the operators under public authority supervision, accepts forwarded unwanted messages. Alongside it, the Pharos platform and the cybermalveillance.gouv.fr website remain the entry points for more serious cases.

**6. Tidy up your messaging apps.** Many Android phones host two apps capable of receiving messages, which multiplies the entry points and blurs the landmarks. Keeping just one, kept up to date, makes staying alert considerably simpler.

## The particular case of older and less confident users

Every interface change produces a side effect: it resets the landmarks that some people took years to build. An 80-year-old who had finally grasped that "a genuine message from my bank never contains a link" is now confronted with colourful bubbles, buttons, logos and thumbnails.

A few simple measures reduce the risk:

- **Turn off RCS** in the Messages app settings if the user has no use for it. The phone reverts to standard SMS — poorer, but easier to read.
- **Block the installation of apps from unknown sources**, an option in Android's security settings that neutralises most attachment-based attacks.
- For truly limited needs, consider a **[senior phone with large buttons](https://www.amazon.co.uk/s?k=telephone+portable+senior+grosses+touches&tag=ds0608-21)**, whose messaging deliberately stays basic: fewer features also means a smaller attack surface.
- Write important credentials down in a **paper password notebook** kept at home, rather than storing them in phone notes or having to ask for them urgently — a moment scammers are quick to exploit.
- Set up a **desk phone stand** near the home workstation, so the person gets into the habit of reading their messages calmly, sitting down, rather than out in the street while walking. Haste is the number one cause of clicking.

## Key takeaways

RCS is a real improvement. Authenticating business senders makes the crude impersonation of "CPAM" or "La Poste" — which fuelled smishing for a decade — far harder. End-to-end encryption, as it rolls out, closes a structural weakness in SMS.

But no technical improvement has ever eliminated a scam: it merely displaces it. Fraudulent campaigns are migrating to ordinary mobile numbers, to WhatsApp, to the messaging systems of marketplace platforms, to fake QR codes. And above all, they rely on what technology will never fix: fear, urgency, tiredness, the trust placed in a logo.

So the question to ask yourself in front of a message is not "does it look genuine?" but "is it asking me for something I didn't initiate?" That question works just as well on a text from 1995 as on a rich message from 2026.

{/* image-sources: https://images.pexels.com/photos/11090579/pexels-photo-11090579.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/12679946/pexels-photo-12679946.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
