# "Your phone is infected": the fake tech support scam that starts with a text message

> A text message claims your smartphone is infected with a virus and urges you to call a support hotline. A breakdown of a fake tech support scam that uses the phone, not a link, to trap its victims.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-09-14/arnaque-sms-faux-support-technique-telephone-piratage
- Published: 2026-09-14 (14 September 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, SMS, Smartphone, Guide, France 2026, Seniors, Protection des données

---
"SECURITY ALERT: 3 threats have been detected on your device. Your banking data is exposed. Contact approved support immediately on 01 84 XX XX XX."

You read this message on the very screen of the device supposedly infected. That's the whole power of the script: the proof and the symptom are one and the same. And unlike 90% of the fraudulent text messages we dissect here, this one contains **no link at all**. No strange domain, no `[.]info` to spot, nothing to hover over. Just a phone number starting with 01, perfectly French, waiting for one thing only: for you to call.

This variant has a name in cybersecurity jargon: *callback phishing*. It reverses the usual logic. It's no longer the fraudster pushing you towards a website, it's you willingly dialling his number. And from that point on, you're no longer facing a form, you're facing a trained human being.

![Man wearing glasses sitting on a sofa, looking at his mobile phone, black and white photo](/images/blog/2026-09-14-arnaque-sms-faux-support-technique-telephone-piratage/hero.jpg)

## Why fraudsters are abandoning the booby-trapped link

The clickable link was long the ultimate smishing weapon. It is less and less so, for three very concrete reasons.

**Filters have improved.** French mobile operators and the anti-spam systems built into iOS and Android now analyse the URLs contained in messages. A domain created the day before, hosted in some exotic country and imitating a well-known brand, has a life expectancy measured in hours. A text message without a link, on the other hand, triggers almost no automatic alert: it contains nothing but text and a national phone number.

**The public has been educated — on a single reflex.** Prevention campaigns from Cybermalveillance.gouv.fr have massively spread one simple message: "don't click on the link." Excellent advice, but it creates a blind spot. Many people have internalised "link = danger" without internalising "unknown number = danger." Calling can even feel like the cautious thing to do: people prefer to "check with a real human" rather than click.

**A human converts better than a form.** A phishing page captures a username and a password. A fraudster on the phone gets far more: the name of your bank, your availability, your level of technical skill, your emotional state — and above all your active cooperation for thirty to forty minutes. The Banque de France, in its work on payment fraud, indeed highlights the marked rise in so-called **"manipulation" scams**, where the victim carries out the fraudulent transactions themselves. This text message is a typical entry point.

## How a call to "support" typically unfolds

The scenarios vary, but the mechanics are remarkably stable. Here is the sequence most victims describe.

### 1. Building technical trust

At the other end of the line, a calm voice, a faint call-centre buzz in the background — often artificially recreated to lend credibility to the idea of a genuine support centre. You're given a "case number," you're asked for your name and your phone model. They may read out a reference found in the text message. Nothing sensitive is requested at this stage: that's deliberate. The aim is to settle you into a normal customer service relationship.

### 2. Demonstrating the infection

The fake technician has you open some harmless screen on your device: the list of recent apps, an account's login history, the network settings. Then he interprets it. "See this line? That's a connection from abroad." These are almost always perfectly normal entries, but unreadable for a non-specialist. The technique is identical to the one used for the past fifteen years in fake Windows support scams, simply transposed to mobile.

### 3. Installing remote access

This is the tipping point. You're asked to install a "diagnostic" app under a reassuring name, available on the official stores because these are genuine remote maintenance tools diverted from their intended use. Once accessibility permissions are granted, the person on the line can see your screen and act on it.

### 4. "Securing" your funds

The script almost always ends with the same line: your savings are supposedly at risk and must be transferred to a "secure account" — sometimes presented as an account at the Banque de France or an escrow account. In other variants, you're made to approve a transaction in your banking app while the fraudster controls it remotely, or you're asked to read out codes received by text message in order to "cancel" a debit.

> No customer service, no bank, no telecom operator and no French public body will ever ask you to install remote access software on your personal phone, or to transfer money to a "security account." Those two requests alone are the signature of the scam.

## Who receives these messages, and why they work

This script primarily targets two profiles, for opposite reasons.

**People uncomfortable with technology**, who have absorbed the idea that a phone can "catch a virus" without knowing what that actually involves. For them, the existence of a support hotline fits everything else they know: the internet box, household appliances, insurance. Calling support is part of the repertoire of normal actions. That's why supporting an elderly relative matters more than any software: a [practical guide to digital security](https://www.amazon.co.uk/s?k=livre+s%C3%A9curit%C3%A9+num%C3%A9rique+arnaques+internet+guide&tag=ds0608-21) left within reach, with the official numbers written on it, often has more impact than a long lecture.

**People who are, on the contrary, fairly connected**, who manage many accounts, receive legitimate security alerts constantly, and for whom one more notification triggers no particular suspicion. With them, it isn't ignorance at play, it's alert fatigue.

![Man in a yellow jacket looking at his mobile phone in the street, a pizza box under his arm](/images/blog/2026-09-14-arnaque-sms-faux-support-technique-telephone-piratage/body-1.jpg)

## Six signals that give fake support away

| Signal observed | What a genuine service does | What the fraudster does |
|---|---|---|
| The point of contact | You contact them via the official app or the number on the back of your card | He forces on you a number supplied in the message |
| The vocabulary | Precise, measured, "we're going to check" | Alarmist, full of figures, "3 threats detected" |
| The pace | You can call back later | Every minute counts, you must not hang up |
| The software | Nothing to install | An indispensable "diagnostic" app |
| Codes received by text | Never requested verbally | Read out "to confirm the cancellation" |
| Where the money goes | Nowhere, your money stays put | A "secure" account, a fundraising pot, crypto |

One further detail deserves attention: **the very nature of the alert**. A genuinely compromised phone would not warn you by text message with a number to dial. Authentic Android or iOS security alerts appear in the system settings or in the app concerned, never as a text message from an unknown sender.

## What to do immediately if you've already called

The order matters. Here are the steps, from most to least urgent.

1. **Cut the connection.** Airplane mode, or switch the device off. If remote access software is running, this ends the current session.
2. **Uninstall the app installed during the call**, along with any app you don't recognise, and revoke accessibility permissions in the settings.
3. **Call your bank from another device**, dialling the number on the back of your bank card — never the one you were given. Ask for transactions to be blocked and your card to be stopped.
4. **Change the passwords** of sensitive accounts from a clean device: your main email first, then banking, then shopping accounts. A [password manager](https://www.amazon.co.uk/s?k=gestionnaire+de+mots+de+passe+licence&tag=ds0608-21) stops you reusing the same combination everywhere, which is exactly what the fraudster is hoping for.
5. **File a complaint** at a police station or gendarmerie, with your screenshots, the number called, the times and the amounts. The official Cybermalveillance.gouv.fr platform also points you towards local specialists.
6. **Report the text message to 33700**, the French national reporting service for SMS and voice spam, by forwarding the message. Report the number you called as well: that's how it gets taken out of circulation faster.

If a transfer has gone through, Article L. 133-18 of the French Monetary and Financial Code requires the bank to refund an unauthorised transaction. The difficulty in manipulation fraud is that the transaction was approved by the customer themselves: banks then invoke gross negligence. Don't give up for all that. The Fédération bancaire française and the Médiateur national de l'Assurance et des banques regularly handle this type of dispute, and several rulings have found the institution liable where the manipulation was particularly sophisticated.

## Reducing your exposure before the next message

No protection makes you immune, but a few settings substantially lower the risk.

**Lock the banking front door.** Strong authentication in your banking app should rely on biometric validation or a code entered inside the app, never on a code given out verbally. Also check your transfer limit: a low limit, raised temporarily when you need it, mechanically caps the damage.

**Isolate critical accounts.** A [FIDO2-compatible physical security key](https://www.amazon.co.uk/s?k=cl%C3%A9+de+s%C3%A9curit%C3%A9+FIDO2+USB+NFC&tag=ds0608-21), plugged in via USB or tapped over NFC, renders stolen credentials useless on your main email account. It's the most worthwhile investment for anyone managing several sensitive accounts, because the mailbox is the key to everything else.

**Don't let your phone be the only point of access.** If your mobile is your sole means of authenticating everywhere, its compromise means losing everything. Keeping a second factor elsewhere — a tablet, a computer, or a sheet of backup codes stored out of sight — separates the risks.

**Keep up with updates.** An up-to-date system blocks known attack vectors. And a tired battery that leads you to postpone updates to save power is an indirect security problem: a [compact power bank](https://www.amazon.co.uk/s?k=batterie+externe+compacte+smartphone&tag=ds0608-21) is often enough to break that cycle.

![Man wearing glasses sitting on a sofa looking at his smartphone while holding a bank card](/images/blog/2026-09-14-arnaque-sms-faux-support-technique-telephone-piratage/body-2.jpg)

## The special case of elderly relatives

It's among this group that fake support scams do the most damage, because they combine three levers: the fear of "getting it wrong" with technology, deference to the presumed authority of a technician, and isolation at the moment of the call.

A few simple measures, more effective than any amount of talking:

- **Write the real numbers down on paper.** The bank's number, the doctor's, the mobile operator's customer service, noted on a card kept next to the phone. The rule becomes: "we only call what's on the card."
- **Establish a pause reflex.** "Before installing anything or moving any money, call me." A simple family rule, stated once, defuses the artificial urgency.
- **Simplify the equipment where it makes sense.** For use limited to phone calls, a [large-button phone](https://www.amazon.co.uk/s?k=t%C3%A9l%C3%A9phone+portable+senior+grosses+touches&tag=ds0608-21) drastically reduces the exposure surface: no apps to install, no remote access possible.
- **Turn on call filtering.** All four French operators offer options for blocking unwanted calls and messages, often free and rarely activated.

## What this text message tells us about how scams are evolving

The shift from the link to the phone call isn't a technical detail, it's a change of nature. Fraudsters have understood that technological defences are improving faster than human ones. Filtering a malicious URL is a solved problem; stopping someone from trusting a calm voice on the phone is not, and never will be entirely.

Hence the only truly robust reflex, the one that works whatever the scenario, whatever the brand being imitated, whatever the sophistication of the message: **never call back a number given in an unsolicited message**. Hang up, look up the official number yourself, and dial it. That takes thirty seconds. On its own, it cancels out the entire chain described in this article.

And if the temptation to call "just to be sure" is still strong, remember the question that settles everything: why would a service that had genuinely detected a threat on your device need you in order to deal with it?

{/* image-sources: https://images.pexels.com/photos/1064103/pexels-photo-1064103.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/9461632/pexels-photo-9461632.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/39219476/pexels-photo-39219476.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
