# Fake SMS from Your Mobile Carrier: When "Your Plan Has Been Suspended" Is Really a Bid to Steal Your Line

> Fake text messages impersonating Orange, SFR, Bouygues or Free promise an overdue-bill fix or a loyalty gift. Here's how a scam that targets far more than your bank card actually works — what it really wants is your mobile line itself.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-09-12/arnaque-sms-faux-service-client-operateur-telephonique
- Published: 2026-09-12 (12 September 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, SMS, Guide, Carte SIM, France 2026, Protection des données, Smartphone

---
"Your mobile plan will be suspended on 14/09 for non-payment (€1.90 still due). Settle here: espace-client-regularisation[.]info"

A trivial amount. A deadline two days away. And above all: a service you definitely have, since you're reading this message on the very phone concerned.

That's where this scam holds a statistical edge over all the others. A fake delivery text only works if you're expecting a parcel. A fake fine only works if you drive. A fake health-insurance message assumes you have health cover. But **a fake text from a mobile carrier reaches 100% of recipients by definition**: to receive the message at all, you must have a mobile line, therefore a carrier, therefore a bill. Relevance is maximised without any targeting whatsoever.

![Smiling man in shirt and tie holding a bank card and a smartphone](/images/blog/2026-09-12-arnaque-sms-faux-service-client-operateur-telephonique/hero.jpg)

## Why this scenario is mathematically the most profitable

Smishing campaigns are judged on their yield: number of victims relative to number of messages sent. The fraudsters, who buy phone-number databases by the bucketload, think exactly like advertisers.

And the "carrier" scenario stacks up four advantages:

- **A universal target.** No filtering needed. Orange, SFR, Bouygues Telecom and Free cover most of the French market: by picking one of the four at random, the scammer already has a one-in-four or one-in-five chance of getting it right — and better still by simply writing "your carrier" with no brand name at all.
- **A credible, painless amount.** €1.90, €2.40, €4.99: sums that match what everyone has already seen on a telecoms bill (out-of-plan usage, premium-rate call, an option switched on by mistake). Too small to justify calling customer service, real enough that you want it dealt with.
- **An immediate, concrete penalty.** Line suspension is not an abstract threat. Without a phone, you no longer receive your banking codes, you can't call anyone, you're cut off. That fear far outweighs the fear of a lost parcel.
- **A pre-existing habit.** Carriers genuinely do send texts: usage tracking, data allowance running out, bill reminders, order confirmations. The fake message slips into a legitimate flow that already feels familiar.

In its recommendations on unwanted and fraudulent messages, Arcep notes that the telecommunications sector is among the most impersonated identities in phishing campaigns in France, alongside public services and banks. Cybermalveillance.gouv.fr ranks smishing among the threats most reported by private individuals, with a growing share of scenarios mimicking everyday service providers.

## The five variants you actually come across

### 1. The overdue bill

The most widespread. Small amount, short deadline, link to a fake payment page reproducing the carrier's logo and brand styling. The immediate objective is the bank card — number, expiry date, security code — followed by 3-D Secure validation hijacked by a fake adviser who calls you moments later.

### 2. The loyalty gift

"Dear customer, 18 years of loyalty: claim your free refurbished smartphone, €2 shipping." The register changes completely: no more fear, just reward. It's the same lever as refund scams. The shipping fee serves to capture the bank card — and above all to get you to sign up, in small print, to a recurring €49-a-month subscription.

### 3. The fake technical fix

"An anomaly has been detected on your SIM card. Confirm your identity to avoid an interruption of service." Here, no money is requested. What's requested is your **customer ID, your account password, sometimes your SIM card number or your ID document**. This is the most dangerous scenario, and the one the public understands least well.

### 4. The fake carrier overpayment refund

"Following a billing error, a credit of €38.60 is owed to you." A commercial variant of the fake tax refund: you're asked for your bank details "for the transfer", then for your banking credentials "to verify the account holder".

### 5. The fake plan change

"Your plan is changing on 1 October: +€3 per month. To decline, click here." Technically, carriers are entitled to amend their contractual terms with one month's notice, and the customer may cancel free of charge: that genuine rule, drawn from the French Postal and Electronic Communications Code, lends the fake message formidable credibility.

## The real prize: your online account, not your bank card

This is the point most prevention articles miss. Stealing €1.90 is of no interest. Stealing a bank card number is useful, but the card will be blocked within days.

**Access to your carrier account, on the other hand, is worth far more.** From that account, a fraudster can:

- order a **replacement SIM card** and have it delivered to an address he controls — the gateway to SIM swapping, which then lets him receive your banking validation codes;
- retrieve your **RIO code**, essential for porting your number to another carrier: with that code and your identity data, he can transfer your line and dispossess you of it;
- view your **itemised bills**, which contain your address, your bank details (sometimes only partially masked) and your order history;
- take out add-ons, order a phone on instalments in your name, change the contact email address to cut you off from alerts.

In other words, the form asking for "just" your login details is infinitely more toxic than the one asking for your card. The first costs you your digital identity; the second costs you a sum you can recover from the bank.

> Simple rule: a carrier will **never** ask you by text for your password, your RIO code, your PUK code or a photo of your ID document. Those things do not travel by message.

## Six signs that give away a fake text

| Sign | Legitimate message | Fraudulent message |
|---|---|---|
| Sender | Short, non-repliable name (e.g. "Orange") or a 5-digit short code | Ordinary mobile number starting 06/07, or a foreign number |
| Link | The carrier's official domain, no exotic subdomain | A near-miss domain: `orange-facture-client[.]info`, `sfr-regul[.]xyz` |
| Personalisation | Often your name, the last 4 digits of your line | "Dear customer", no verifiable data |
| Amount | Matches your actual bill | Round or tiny sum, never cross-checkable |
| Deadline | Several weeks, staggered reminders | 24 to 72 hours, threatening tone |
| Payment method requested | Direct debit already in place | Bank card to be entered "exceptionally" |

The most reliable sign remains the link. French carriers use their main domains; anything resembling `brand-name-something.tld` warrants immediate suspicion. On a phone, the URL is truncated by the display: press and hold the link to see it in full **without opening it**, or type it out by hand on a larger screen. Many readers spot the trick simply by looking at the message on a computer or a [tablet with an adjustable stand](https://www.amazon.co.uk/s?k=tablette+avec+support+inclinable&tag=ds0608-21), where the address appears in full.

## What to do, in order, if you clicked

Don't waste time beating yourself up: speed matters more than hindsight.

1. **If you entered your bank card details**: immediately call your bank's card-blocking line (or the number on the back of the card) and stop the card. If a debit has gone through, the bank must refund unauthorised transactions under the French Monetary and Financial Code, barring gross negligence on your part — hence the importance of reporting quickly.
2. **If you entered your carrier login details**: change your account password from the official app, enable two-factor authentication if it's offered, and check that no SIM order or address change has been recorded.
3. **If you reused that password elsewhere** (very common), change it everywhere. This is the moment to switch to a password manager, or failing that to a paper [password notebook](https://www.amazon.co.uk/s?k=carnet+de+mots+de+passe+papier&tag=ds0608-21) kept out of sight — an imperfect solution, but far better than the same password on fifteen sites.
4. **Report the message to 33700**, the official reporting service for unwanted texts and calls, run by the carriers and overseen by Arcep: forward the text to 33700, then send the sender's number when prompted. It's free, and it feeds into the blocking of sending numbers.
5. **Report the website address** to Phishing Initiative or via cybermalveillance.gouv.fr, which also directs you to free support.
6. **File a complaint** if you have suffered financial loss — at a police station, a gendarmerie, or through the French Interior Ministry's online complaint service. Keep screenshots, statements and timestamps.

## Shrinking the attack surface for good

You can't stop a fraudster from writing to you. What you can do is limit what he can make of your reaction.

**Lock down physical access.** The SIM card itself is protected by a PIN code: don't leave it on the factory setting. If you change devices often or travel, a small [SIM card storage case](https://www.amazon.co.uk/s?k=boite+rangement+carte+SIM&tag=ds0608-21) prevents you losing the original card carrying the PUK code — a document fraudsters love to see circulating as a photo.

**Separate the banking channel from the everyday one.** Many scams succeed because the same phone receives the ads, the unknown texts and the banking validation codes. Some households deliberately keep a [basic mobile phone with large buttons](https://www.amazon.co.uk/s?k=telephone+portable+senior+grosses+touches&tag=ds0608-21), with a second line reserved for sensitive institutions: it's a common practice among people who have already been victims, and among older people supported by their families.

**Install updates, and a filter.** Both Android and iOS now filter some unknown senders and flag certain dangerous links. These protections only work on an up-to-date system — which sometimes means replacing a tired battery rather than putting off updates for fear of losing battery life.

**Protect the hardware too.** A cracked screen isn't a cybersecurity matter, but it makes reading a URL virtually impossible; a tempered glass screen protector and a decent case cost less than a misread address.

**Learn, calmly.** The Cybermalveillance.gouv.fr guides are excellent and free, but for people less at ease with technology, a [printed guide to online scams](https://www.amazon.co.uk/s?k=livre+arnaques+internet+prevention&tag=ds0608-21) left near the phone often works better than a link sent by the family: you leaf through it at the moment of doubt, with no screen involved.

## The one habit that renders the scam useless

The whole thing comes down to a single rule, easy to remember and applicable with no technical skill at all:

> **Never use the route provided by the message.**

If the bill is real, it will be in your online account, accessible from the official app that you open yourself. If the suspension is real, it will show up there too. If the loyalty gift exists, it will survive five minutes of checking. No French carrier cuts off a line within 48 hours over €1.90 without several written reminders beforehand.

Close the text. Open the app. Look at the bill. In 100% of fraudulent cases, there will be nothing to pay — and in thirty seconds you will have beaten a scam that thousands of people will pay dearly for this month.

One last piece of advice, and it applies to every family: talk about it. These messages work because we deal with them alone, in a hurry, between two other tasks. A text read aloud in front of someone else instantly loses its persuasive power. It is probably the cheapest security measure in existence.

{/* image-sources: https://images.pexels.com/photos/36766768/pexels-photo-36766768.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
