"DGFiP: following the recalculation of your tax assessment, an overpayment of €284.17 is owed to you. Please provide your details before 18/09: impots-remboursement-gouv[.]net"
There is nothing frightening in this message. No threat, no parcel stuck in transit, no fine that doubles, no panicked bank adviser on the line. Just a sum of money that belongs to you and that you are being invited to claim. And that is precisely what makes it so dangerous.
The vast majority of awareness campaigns against smishing target the register of fear: the fake parcel, the fake fine, the fake overdraft. The public is taught to be wary of anxiety-inducing urgency. Almost no one is taught to be wary of good news. Fraudsters, on the other hand, worked that out long ago.

The refund lure: psychology in reverse
Classic scams trigger a stress response. Stress makes people click fast, but in many of us it also sets off a reflex to double-check: we call our partner, we search online, we look at the official parcel tracking page. Fear is a poor adviser, but it is loud — it alerts those around us.
The prospect of a refund produces the opposite effect. It creates a climate of trust and discretion. You don't phone your daughter to announce that you're about to receive €284. You don't ask a colleague, "Did you get this one too?" You simply think: makes sense, my situation did change this year.
Three well-documented decision-making biases combine here:
- Confirmation bias: most households have, at one point or another, a vague feeling of having overpaid for something. The message confirms a pre-existing intuition rather than creating one.
- Reciprocity: an organisation that gives you money back presents itself as benevolent. We are reluctant to suspect a benefactor.
- Low vigilance around mid-range amounts: €284 is neither large enough to seem too good to be true, nor small enough for you to skip the trouble. Fraudsters calibrate that figure very carefully.
Cybermalveillance.gouv.fr, France's national victim assistance service, has ranked phishing as the leading reason individuals seek help for several consecutive years, across all channels. And among the pretexts used, the refund holds a structurally strong position because it can be recycled indefinitely: taxes, health insurance, family benefits, social contributions, energy suppliers, phone operators, airlines, toll roads.
The tax and benefits calendar: the fraudsters' work schedule
A refund scam never lands at random. It follows the French administrative calendar, because a credible message is one that arrives at the right moment.
| Period | Most common pretext | Why it works |
|---|---|---|
| July – September | Tax assessment, DGFiP overpayment | Real assessments arrive, and so do adjustments |
| September – October | Back-to-school: family benefits, allowances, grants | A surge in family-related paperwork |
| November – January | Energy bill reconciliation | Annual meter readings and tariff changes |
| All year round | Health insurance reimbursements | A constant flow of statements |
| After a house move | Overpayment from an operator or insurer | Cancellations and pro-rata refunds are genuinely common |
The rule is simple: if you're expecting a letter from an organisation this month, a fraudster knows it too. You are not being targeted personally; they are targeting statistically, across millions of people, a fraction of whom really are waiting for that kind of news. On a mass mailing, a few percent of coincidences are enough to make the operation profitable.
The technical trap: why you "pay" to be refunded
This is where the most counter-intuitive part of the scenario comes in — the part that catches out even careful people. The fraudulent page doesn't ask for money. It asks where to send the money. In other words, your bank details — and, very often, a great deal more.
The typical journey unfolds across four screens:
- Identification: surname, first name, date of birth, address, sometimes a tax reference or social security number. Nothing alarming on the face of it — the organisation is supposed to know who you are.
- Bank details: your IBAN, then, "for an instant transfer", your card number, expiry date and the security code on the back. This is the pivotal moment: no public body ever issues a refund to a bank card.
- Phone number: presented as necessary for confirmation. In reality, it allows the fraudster to call you afterwards, posing as your bank.
- Validation: a small "verification" charge of €1 or €2, supposedly to "test" the card. That payment actually triggers the enrolment of your card in the fraudster's digital wallet.
This last step is the most modern and the least well known. Since the widespread rollout of strong customer authentication required by the European PSD2 directive, a card number alone is no longer enough to debit an account: the transaction must be approved in the banking app. So fraudsters have shifted their objective. They are no longer trying to pay directly with your card, but to add it to a phone they own, so they can then make contactless payments in shops, quietly, until you notice.
Hence the phone call that often follows the form by a few minutes or a few hours: a calm, professional voice asking you to "approve the notification you've just received". You approve. You have just authorised the enrolment.

Seven signs that give away a fake refund text
None of these clues is decisive on its own. Two of them together are enough to classify the message.
- A link that isn't a
.gouv.fraddress. French government websites always end in.gouv.fr, never-gouv.net,gouv-fr.comorimpots-service.info. The hyphen is the fake domain's favourite disguise. - A precise amount including cents. It is designed to mimic accounting realism. Genuine DGFiP notifications don't communicate amounts by text message anyway.
- A request for bank details. The tax authority, the family benefits agency, the health insurance service and Urssaf already have your bank details: you gave them during previous dealings. They won't ask again by text.
- A short deadline. A legitimate refund doesn't expire in 72 hours. That's artificial urgency, borrowed from the fear playbook.
- The words "security code", "CVV" or "the 3 digits on the back". That code exists solely to make payments, never to receive them.
- A spoofed alphanumeric sender. A fraudulent message can display a credible sender name, and sometimes slip into the existing conversation thread of a genuine organisation. The thread is therefore not proof of authenticity.
- Near-perfect spelling. Crude typos have disappeared. Stop hunting for the grammatical slip: look at the domain.
A survival rule that applies to every administrative text message: never click inside the message; always go back to the official site under your own steam — impots.gouv.fr, caf.fr, ameli.fr, urssaf.fr — or use the app already installed on your phone. If the refund exists, it will be there. If it isn't there, it doesn't exist.
Who is most exposed, and why
Retirees and people less at ease with digital tools
Pay-as-you-earn tax withholding has made taxation more opaque for many households: people no longer always know what they're paying, or why. So the announcement of an adjustment sounds plausible. There's also a practical factor: reading a truncated web address on a small screen is objectively difficult. Many families solve part of the problem by permanently increasing the phone's display font size, or by installing an adjustable phone stand next to the armchair so the screen can be read at a comfortable distance rather than at arm's length. Seeing a domain name clearly is already half the battle.
Students and young working adults
Grants, housing benefits, mobility allowances, travel reimbursements: this group combines a stream of small-value administrative payments with heavily mobile-first habits. An announced transfer of €120 seems perfectly ordinary.
Freelancers and sole traders
They genuinely receive messages from Urssaf, genuinely exchange bank details, and manage their cash flow day by day. A fake "overpaid contributions" notice finds ideal ground here. For them, separating uses is a real security gain: a second phone dedicated to professional activity, or at the very least a prepaid SIM card reserved for administrative contacts, mechanically reduces the exposure surface.
What to do if you've already clicked, or entered your details
Time matters more than embarrassment. Here is the order of priorities.
- Block your card immediately with your bank, via the app or the number printed on the back of your card — never a number received by text. In France, the interbank card-blocking service is available around the clock on 0 892 705 705.
- Check the enrolled devices in your online banking area: most banks now list the phones linked to your card for mobile payments. Remove any unknown device.
- Change the passwords of the accounts concerned if you have reused the same one elsewhere. A paper password notebook kept at home remains, for many households, a more realistic solution than relying on shaky memory — provided you never photograph it or carry it around.
- Report the message. The number 33700 is France's official reporting service for unwanted and fraudulent text messages: forward the message to 33700, then send the sender's number when the service asks for it. You can also report the fraudulent address on the Phishing Initiative platform and file a report on the French Interior Ministry's official reporting portal.
- File a police report at a police station or gendarmerie if money has actually been taken. It is often a prerequisite for obtaining a refund.
- Request reimbursement. French monetary and financial law provides that, in the event of an unauthorised payment transaction, the bank must reimburse the account holder, unless they have been grossly negligent. The Banque de France and the Autorité de contrôle prudentiel et de résolution have repeatedly stressed that simply having been manipulated does not automatically amount to gross negligence. If your bank refuses, refer the matter to its ombudsman.

Cutting the risk for good, without becoming paranoid
The goal isn't to distrust everything, but to make doubt easy. A few habits are enough.
- Install the official apps (impots.gouv, ameli, CAF – Mon Compte) and get into the habit of checking there rather than in a link. That single reflex neutralises 90% of these campaigns.
- Turn on real-time banking notifications for every transaction, including small amounts: it's the €1 charge that gives away a fraudulent enrolment.
- Keep your phone up to date, both the operating system and the browser. Built-in anti-phishing filters block a share of reported domains.
- Don't let your battery drive your decisions. A significant share of impulsive clicks happen when people want to "sort this out quickly" before the phone dies. A compact power bank in your bag also buys you thinking time.
- Talk about the attempts you receive. Across all research on fraud, the single biggest protective factor remains having discussed it with someone. A general-audience book on everyday cybersecurity, left on the living-room table, starts more family conversations than any lecture.
Finally, one sentence worth remembering and passing on, especially to parents and grandparents: no French public body will ever ask for your bank card number in order to pay you money. A refund is made by bank transfer, to details already on file, with nothing required from you. Any message that departs from this rule is a scam, whatever the logo, the tone or the amount announced.
The real good news is that this scam collapses the moment you name it. It rests on no technical feat whatsoever: only on the fact that we've been taught to be wary of threats, and never of gifts.



