"BANQUE DE FRANCE: following a payment incident, your file is subject to FICP registration proceedings. Mandatory settlement within 48 h: bdf-regularisation-dossier[.]com"
The message lands on a Tuesday morning, somewhere between a delivery notification and an appointment reminder. It says nothing about a parcel, a fine or a health insurance card. It talks about something far more intimate: your creditworthiness. And it targets a pressure point most scams ignore — shame.
Because being blacklisted by the Banque de France isn't an administrative annoyance. It's a phrase people don't dare say out loud, a situation they mention neither to family nor to colleagues. Fraudsters have understood this: when victims are afraid to talk about it, they have no safety net. They click alone, they pay alone, and afterwards they say nothing.

What the Banque de France has actually said
This campaign is no laboratory hypothesis. The Banque de France has repeatedly published warnings on its official website about fraudulent messages — texts, emails, phone calls — impersonating the institution and referring to a registration or over-indebtedness procedure. Those alerts restate one simple rule that should be remembered before anything else:
The Banque de France never asks, by text message or email, for a payment, bank details, a copy of an identity document or login credentials.
Correspondence about a registration goes through postal mail — via your bank, which is the reporting institution — or through the Banque de France's official channels that you yourself have contacted. Never through a link that turns up unprompted on your phone.
Another crucial point, often overlooked: the Banque de France doesn't register anyone on its own initiative. It maintains the files, but the entry is reported by a bank or a credit institution following a specific incident (unpaid loan instalments, a bounced cheque, a ruling by an over-indebtedness commission). The institution is a registrar, not an inspector who ambushes you by text.
The three files fraudsters deliberately blur together
The scam message works all the better because banking vocabulary is hazy for most of us. Here's what the acronyms brandished by fraudsters actually cover.
| File | What it records | Source of the entry | Maximum duration |
|---|---|---|---|
| FICP (register of personal loan repayment incidents) | Confirmed loan arrears, over-indebtedness cases | Reported by the lending institution or the over-indebtedness commission | 5 years (up to 7 years for an over-indebtedness plan) |
| FCC (central cheque register) | Bounced cheques, bank card withdrawals for improper use | Reported by the bank | 5 years (lifted immediately once settled) |
| FNCI (national register of irregular cheques) | Stolen or lost cheques, closed accounts | Reported by the bank | Variable |
In fraudulent texts, these acronyms are used interchangeably, and sometimes invented outright ("FBF file", "national incident register"). That's an excellent tell: a genuine bank letter is precise, dated, and names the reporting institution explicitly.
Anatomy of the booby-trapped message
Across the dozens of variants observed, the structure stays remarkably stable. It rests on four building blocks.
- Borrowed authority. "Banque de France", sometimes "BDF", sometimes "National Banking Settlement Service" — an entity that doesn't exist. The sender may display a name instead of a number: that's header spoofing, technically trivial to pull off.
- A very short deadline. 24 h, 48 h, "before your file is closed". Urgency is smishing's universal ingredient: it prevents verification.
- A wildly disproportionate consequence. "Your accounts will be frozen", "5-year banking ban", "wage garnishment". None of these measures is ever triggered by text message.
- A single link. A long domain, multiple hyphens, an exotic extension (.info, .icu, .top) or a domain name mimicking the official
banque-france.frby tacking on a word (banque-france-regularisation).
The landing page itself is often a clean copy: logo, institutional typeface, legal notices lifted wholesale. It asks for your civil status, your social security number, a scanned ID document, then bank details — and ends up offering a "de-registration processing fee" of €29 to €99. There is no fee whatsoever for being removed from a Banque de France file.
Why this scenario catches very different profiles
We readily imagine that only people in financial difficulty take the bait. That's wrong — and it's precisely the opposite that makes the fraud profitable.
People who really are registered read the message as confirmation of what they already know. They click because the message "fits" their situation — and because they hope for a quick way out.
People who aren't registered at all panic differently: they wonder whether a forgotten loan, a guarantee given to a relative or an identity theft has created an incident without their knowledge. The doubt alone is enough to trigger a click.
Older people and those less comfortable with digital tools are overexposed. According to work by the Défenseur des droits and Crédoc on digital illiteracy, several million people in France still struggle with online procedures. Faced with an official-looking message, the instinct is to comply, not to verify. Within families, it helps to have set the rule in advance: no financial message is ever handled alone. A large-format telephone address book kept beside the landline, listing the bank branch's direct number and that of a trusted relative, beats any technical filter: it turns a panic reflex into a calling reflex.
Freelancers and micro-entrepreneurs, finally, live with the constant fear of a client payment incident. The message targets them very effectively at the end of a quarter.
Checking for free whether you're listed: the only right move
This is the most effective response to that kind of text, and it costs nothing. The right to access Banque de France files is free and guaranteed by the GDPR as well as by the French Data Protection Act.
There are three routes:
- Online, via the incident-file access service offered on the Banque de France's official website, using FranceConnect authentication.
- In person, at one of the Banque de France's branches, with a valid identity document.
- By post, to the address given on the official website, enclosing a copy of your ID.
In all three cases: no payment, no intermediary, no link received by text message. If you discover an entry you dispute, the party to contact is the reporting institution — your bank — then, if the disagreement persists, the Banque de France itself, and where appropriate the CNIL.
One detail that matters: for these steps you'll need to scan or photograph supporting documents. You may as well do it properly, well away from any dubious website — a portable document scanner, or simply an official app on your phone, lets you build a clean file to send through official channels, without ever uploading your papers to an unknown platform.
The red flags that should stop you within three seconds
Even before reading the content, a few sorting reflexes are enough.
- A public body never puts a payment link in a text message. Not the Banque de France, not the DGFiP, not the health insurance service.
- Institutions don't address you informally, and they don't produce grammatical slips or random capitals ("Your File is On Hold").
- A French mobile number starting 06 or 07 for an institutional message is an aberration: official bodies use short codes or alphanumeric sender IDs.
- Shortened links (bit.ly, tinyurl and the like) are never used by a public institution.
- The message knows too little about you, or too much. No full name, no case reference? Suspicious. Conversely, a hyper-personalised message may betray an earlier data breach.
One technical point is worth restating: the displayed sender proves nothing. A fraudulent text can slot into an existing conversation thread with your real bank if the spoofed sender ID is identical. So the thread is no guarantee of authenticity — one of the most dangerous misconceptions about smishing.
What to do if you've already clicked
The timeline matters more than the apparent severity.
Within the hour: if you entered banking credentials, immediately call the number on the back of your card or in your official banking app — never a number found in the text message. Block the card. The interbank loss-and-theft service (0 892 705 705) allows emergency card blocking.
During the day: change the password for your online banking from a clean device, and turn on two-factor authentication if you haven't already. For anyone managing lots of accounts, a physical FIDO2 security key is the most robust level of protection, far superior to a code received by text — precisely because it doesn't depend on the mobile network.
Within 48 hours: report the message to 33700, France's official SMS spam-reporting platform, by forwarding the text you received and then the sender's number. Next, file a report on cybermalveillance.gouv.fr and, if you've suffered financial loss, a complaint with the police or gendarmerie. The Perceval service, accessible via service-public.fr, lets you report bank card fraud.
Within the week: if you sent an identity document, assume there is a risk of identity theft. Exercise your right of access to the Banque de France files to check that no loan has been taken out in your name, and monitor your statements for several months.
Finally, a reminder of the principle laid down in the French Monetary and Financial Code: where an unauthorised payment transaction is reported without delay, the bank must in principle refund the account holder, unless the holder has been grossly negligent. A now substantial body of Cour de cassation case law has clarified that merely passing on a code received by text, in a context of sophisticated fraud, is not enough to establish such gross negligence. In other words: don't give up on claiming your money back.
Protecting a loved one without putting their back up
This is often the trickiest part. Talking about money, debt or blacklisting with an elderly parent or a newly independent young adult touches on self-esteem. A few approaches work better than a lecture:
- Start with yourself. "I got this text and it fooled me for ten seconds" opens a conversation where "be careful" shuts it down.
- Set up a fallback channel. A family password, or simply the rule "we never deal with a financial message alone", defuses artificial urgency.
- Make calling easier than clicking. For older relatives, a senior mobile phone with large buttons with a few numbers stored in direct memory mechanically reduces the temptation to respond to a link: the first instinct becomes calling someone.
- Secure the device. An up-to-date smartphone, protected by biometric locking and possibly fitted with a dedicated prepaid SIM for sensitive uses, limits the damage if it's lost or stolen.
Ultimately, general knowledge remains the best protection. A good book on everyday cybersecurity, left on the coffee table, teaches a family more than ten ministerial alerts — because it explains the why behind the mechanisms rather than listing prohibitions.
Key takeaways
The fake Banque de France registration text invents nothing technically: it's textbook smishing. Its strength lies elsewhere, in the choice of pretext. By striking at financial reputation, it isolates the victim and neutralises the single most effective defence against a scam — asking someone else what they think.
Three sentences are enough to inoculate yourself:
- The Banque de France never notifies a registration by text message.
- Having a registration lifted is always free and goes through the reporting institution.
- Consulting the incident files is a free right, exercisable online, at a branch or by post.
The rest — the links, the 48-hour deadlines, the "processing fees" — is just scenery. Very well painted scenery, but scenery all the same.



