"CIC: unusual login detected on your account from a new device. If this wasn't you, secure your account here: cic-verification-acces[.]com"
You get this message at 6:40 p.m. as you leave the station. The person next to you checks their phone at the very same moment and frowns. The message is identical. You don't have the same mobile operator, nor the same bank, and there's no connection between you. Yet you have both just received the same text message at the same second.
This is not a classic smishing campaign. There was no list of numbers bought on the black market, no bulk-messaging gateway, no operator at the other end. There is a car parked 150 metres away, a box running off a battery, and a fake cell tower that forced every phone in the neighbourhood to connect to it in order to push a message straight into the inbox. This is what's known as an SMS Blaster.

What the SMS Blaster changes radically
Until now, every fraudulent text message we've dissected in this magazine has shared one characteristic: it travels over the network. The scammer pays for a bulk-sending service, often abroad, uploads a list of numbers and hits "send". The message passes through operators, crosses anti-spam filters and leaves usable traces. That's why reporting to 33700, the official French reporting service for voice and SMS spam run by the Association Française du Multimédia Mobile together with French operators, makes sense: it feeds a very real blocking chain.
The SMS Blaster skips that entire layer. The device behaves like a mobile base station — a miniature cell tower. Phones in the vicinity, designed to latch onto the strongest signal, connect to it spontaneously. Once the connection is established, the device pushes a message into the handset exactly as a real network would. The consequences cascade:
- No operator is involved. Neither Orange, nor SFR, nor Bouygues, nor Free ever saw this message. Operators' anti-smishing filters, which block tens of millions of fraudulent texts every year, are out of the picture.
- No phone number was needed. The scammer doesn't know your number, has never bought it, has never seen it. They blanket a geographic area, not a list.
- The displayed sender is entirely arbitrary. The box decides on the header: "CIC", "Ameli", "Chronopost", "ANTAI". Nothing forces it to use a plausible number format.
- The message can land in an existing thread. This is the most unsettling detail: if the displayed sender exactly matches that of a brand from which you have already received legitimate texts, some phones will group the fake message into the same conversation, right after the genuine ones.
That last point destroys the main verification reflex the general public had finally acquired. "Check whether the message appears in the same thread as the previous ones": this advice, valid for a long time, no longer protects you against this technique.
How can a small box impersonate a cell tower?
The answer comes down to one word: 2G. GSM, rolled out in the early 1990s, was designed at a time when the main concern was preventing private individuals from eavesdropping on calls. The network authenticates the phone, but the phone doesn't really authenticate the network. In other words: your mobile proves its identity to the tower, but the tower has nothing to prove to your mobile.
Later generations fixed this flaw. 3G, then 4G and 5G, require mutual authentication: a rogue device can no longer pretend to be a legitimate network. Except that backwards compatibility remains enabled by default on many handsets. All the attacker has to do is jam or locally overpower the 4G/5G bands so that phones, deprived of any better option, obediently "fall back" to 2G. This is known as a downgrade attack.
The technical principle isn't new: it's a cousin of "IMSI catchers", the interception suitcases long used by certain agencies and known to security researchers for more than fifteen years. What is new is the price, the miniaturisation and the mass criminal use.
The required hardware, once reserved for states, now fits in a backpack and is driven from a laptop. Authorities in several countries — the United Kingdom, Thailand, Vietnam and New Zealand among them — have seized devices of this type in recent years, often installed in vehicles driving around city centres. In France, operating an unauthorised radio transmitter on frequencies allocated to operators constitutes several distinct offences, quite apart from the fraud itself: jamming and unlawful transmission are punishable under the French postal and electronic communications code, under the supervision of the ANFR (Agence nationale des fréquences).
Short range, but enormous throughput
An SMS Blaster doesn't cover a city. Its useful range is measured in hundreds of metres — a few dozen in a dense environment, more in open terrain. Within that perimeter, however, it can reach several thousand handsets per hour. Hence the choice of locations: railway stations, metro exits, markets, retail parks, areas around stadiums, festival queues. Anywhere the density of people is at its highest and where people stare at their phones while walking.
The modus operandi described by the specialist press is almost always the same: an unremarkable vehicle, equipment in the boot powered by a high-capacity power bank, a stop of twenty to forty minutes, then a move elsewhere. No interaction with the victims. No physical contact. The "delivery driver" doesn't exist, the "bank adviser" isn't calling yet — everything hinges on the click.
Spotting a message sent by an SMS Blaster
Since the sender header no longer proves anything, attention has to shift to other signals. Four clues often appear together:
| Clue | What you observe | Why it's revealing |
|---|---|---|
| Simultaneity | Several people around you receive the same message | A classic campaign doesn't target a geographic area |
| Brief network drop | Your phone switched to "E", "G" or lost data just before | A sign of a forced downgrade to 2G |
| Inconsistent brand | A text from a bank you're not a customer of | The attack isn't targeted: it blankets |
| Cobbled-together domain | cic-verification-acces.com, ameli-mise-a-jour.net | No government body or bank uses domains like these |
The second clue is the most technical but the most reliable. If, in the middle of a city centre covered by 4G/5G, your phone suddenly drops to an "E" or "G" indicator for a few minutes, and then a surprising text arrives, the coincidence deserves your suspicion. Users who keep a compact power bank in their bag often notice these switches, because they watch the status bar more closely when charging on the move.
The third clue nevertheless remains the most accessible: an area-wide scam is, by definition, poorly targeted. If you receive a "payment problem" notice from a retailer you've ordered nothing from, or an alert from a bank that isn't yours, the matter is settled.
The setting that neutralises the attack: disable 2G
This is the most effective countermeasure, and it's free. Since the attack relies on a forced fallback to 2G, preventing your phone from connecting to it amounts to sawing off the branch the scammer is sitting on.
On Android
Most recent versions of Android offer a dedicated toggle, inherited from a feature introduced by Google as of Android 12:
- Settings → Network & internet → SIMs (or "Mobile network")
- Look for the "Allow 2G" option and turn it off.
Some manufacturers name it differently, or tuck it away in a "Preferred network type" menu where you select "4G/5G only". On devices that don't expose this setting, it is often still reachable via the advanced operator menu.
A broader "enhanced protection" mode also exists under the name Advanced Protection on the most recent versions of Android: it disables 2G, blocks unencrypted connections and hardens several network behaviours in one go.
On iPhone
Apple doesn't offer a standalone "2G" toggle, but Lockdown Mode (Settings → Privacy & Security → Lockdown Mode) disables, among other things, insecure mobile connections, including 2G. This mode is deliberately restrictive: it also limits attachments, certain web features and incoming invitations. It's aimed at genuinely at-risk individuals, not at everyone's daily use.
Failing that, you can at least check under Settings → Cellular → Cellular Data Options → Voice & Data that the handset is set to 5G or LTE, and not to a legacy-compatible mode.
And if you need 2G?
Two legitimate cases remain. First, some rural areas retain residual 2G coverage as a safety net for voice calls. Second, many connected objects — trackers, alarms, big-button mobile phones for older people, GPS watches for children — exist only in 2G. If you're equipping a relative, the choice of handset matters: a 4G VoLTE-compatible model, even a very simple one to use, is better than a device stuck on 2G. French operators have in any case begun the gradual shutdown of 2G and 3G by the end of the decade, which will make this point moot — but we're not there yet.
The other reflexes that still apply
Disabling 2G removes the most common entry vector. But the rest of the scam doesn't change: the message wants you to click a link and enter your credentials. The classic defences therefore retain all their value.
- Never use the link you received. Open your bank's official app, or type the address yourself. This single rule cancels out the vast majority of campaigns, blaster or not.
- Verify through an independent channel. Call the number printed on the back of your bank card, never the one given in the text message.
- Enable robust two-factor authentication. A physical FIDO2 security key or an authenticator app is better than a code sent by SMS — precisely because the SMS channel is the weak link.
- Keep your system updated. Monthly Android and iOS security patches regularly close holes in the network stack. A phone abandoned by its manufacturer is more vulnerable, and not only to blasters.
- Beware of the second step. The text message is rarely the whole scam: it serves as a hook for a "fake bank adviser" call a few hours or a few days later. This manipulation scenario, sharply on the rise according to observations by the Banque de France, is the one that costs victims the most.
For households wanting to formalise a minimum of digital hygiene, a paper password notebook kept out of sight remains, paradoxically, a perfectly defensible security tool for people who don't want a software manager — provided it contains no bank PINs and never travels in a bag.
What to do if you clicked
The order of the steps matters more than their number.
- Cut off data immediately (airplane mode) if you suspect an app download is under way. A blaster can also push a link to install malicious software on Android.
- Change your passwords from another device, starting with your main email account and your online banking.
- Call your bank using the official number and block your card if you entered card details. Remember that, under the French monetary and financial code, an unauthorised transaction must in principle be refunded by the bank, except in cases of gross negligence on your part — hence the importance of reporting it quickly and in writing.
- Report to 33700 by text (by forwarding the message) and file a police complaint. Even if the operator didn't carry the message, reporting it helps document the campaign and block the associated domains.
- Warn the people around you geographically: colleagues, neighbours, local shopkeepers. An area attack hits a community, not an individual.
The official portal cybermalveillance.gouv.fr offers a free assistance pathway and referrals to service providers, and service-public.fr sets out the complaint procedure. Arcep, for its part, regularly reminds people of the channels for reporting unwanted communications.
What this technique tells us about what comes next
The SMS Blaster marks a discreet but profound shift: SMS fraud is becoming a threat of physical proximity. For twenty years, the public has been taught that danger came from "somewhere out there", from an anonymous server abroad. Here, it comes from the next street along, from an ordinary vehicle, for half an hour.
This has two practical consequences. First, vigilance can no longer be delegated entirely to operators: a network filter, however powerful, sees nothing of a message that never crosses the network. Second, handset settings, long regarded as a detail for experts, become a front-line defence — just as a tempered glass screen protector is for the display.
The one piece of advice that survives everything hasn't shifted a millimetre: no bank, no government body and no delivery company will ever ask you to enter your credentials via a link received by text message. Whatever the displayed sender, whatever the conversation thread, whatever the tower — real or fake — that carried the message.



