# "I've Already Paid, Just Confirm the Delivery": The Fake Buyer Scam on Classified Ad Sites

> You're selling a second-hand item and an impatient buyer sends you a text message with a link to "confirm receipt of payment." A full breakdown of the fake buyer scam, the warning signs, and what to do if you've already clicked.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-09-16/arnaque-sms-vente-entre-particuliers-faux-acheteur-lien-paiement
- Published: 2026-09-16 (16 September 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, SMS, Guide, Cas d'usage, France 2026, Smartphone, Protection des données

---
"Hello, I'll take your bike at the asking price, no need to haggle. I've already made the secure payment through the platform, you'll receive a text message to confirm receipt of the funds. My courier will come by tomorrow morning."

The message is polite, quick, no bargaining. That is precisely what should raise a red flag — and precisely what puts people at ease. After three weeks of the listing sitting online and four time-wasters offering half the price, a buyer who says yes straight away feels like a relief, not a trap.

The fake buyer scam has one feature that makes it formidable: it reverses the roles. Every awareness campaign has taught us to be wary when we **buy** online. Almost no one has explained that you can be robbed while **selling**. Yet this is now one of the most widespread smishing scenarios in France, and it no longer targets only beginners.

![Man in a beige jumper checking his mobile phone in the street, holding a coffee cup](/images/blog/2026-09-16-arnaque-sms-vente-entre-particuliers-faux-acheteur-lien-paiement/hero.jpg)

## The full scenario, step by step

Unlike the fake delivery text that arrives out of the blue, this scam builds itself up. It always starts with a **real** listing, published by you, on a **real** platform. The fraudster fabricates nothing: he exploits what you have put online.

**Step 1 — The lightning-fast contact.** Anywhere from a few minutes to a few hours after the listing goes live, a message arrives through the site's internal messaging system. The buyer accepts the asking price, asks no technical questions about the item, and says he is "very interested." He often invokes a constraint: he's travelling for work, he's buying for a relative, he can't come in person.

**Step 2 — Leaving the platform.** This is the pivotal moment. The buyer asks for your phone number "to speed things up" or "because the app is glitching." You give it, and the exchange moves to text messages or an encrypted messaging app. You have just left the space where the platform archives, moderates and can suspend an account.

**Step 3 — The proof of payment.** The fraudster sends a screenshot of a completed bank transfer, sometimes a fake confirmation email in the platform's colours. These documents are well made: correct logo, correct font, legal notices copied over. They are worthless, but they create a sense of progress.

**Step 4 — The booby-trapped text message.** A message arrives, supposedly automated, with a link: "Your seller account has €480 pending. Click to confirm receipt of the funds into your account." The domain mimics that of the platform or of a well-known payment service, with one tiny variation.

**Step 5 — The form.** The page asks for your bank card number, expiry date, security code, sometimes your available balance "to verify the compatibility of the payout." Then it asks you to approve a notification in your banking app.

**Step 6 — The debit.** That approval does not authorise an incoming payment, it authorises an **outgoing payment** or the registration of your card in a digital wallet controlled by the fraudster. The charges follow, sometimes spread over several days to avoid triggering an alert.

## The central lie: you never "confirm" an incoming payment

This needs to be carved in stone somewhere, because it is the single point the whole scam rests on.

> Receiving money **never** requires you to disclose your bank card number or security code, nor to approve a transaction in your banking app.

An incoming transfer arrives on its own. A refund arrives on its own. A payment made through a marketplace lands in the platform's wallet, then in your account after a withdrawal request that **you** initiate from the official app, logging in yourself.

Bank card details serve one purpose only: to **debit** that card. The three-digit code on the back exists solely to prove you physically hold the card at the moment of a purchase. No system in the world needs it in order to pay you money. Cybermalveillance.gouv.fr, France's national assistance scheme for victims of cybercrime, repeats this principle in every one of its phishing fact sheets.

The practical corollary: the moment anyone, whoever they are, links the words "receive" and "bank card" in the same sentence, the conversation is over.

## The variants circulating in 2026

The basic scenario comes in several flavours. Here are the most frequently reported forms.

| Variant | Pretext | What you're asked for |
|---|---|---|
| The overpayment | "I paid €800 instead of €80, please refund the difference" | A bank transfer from you to an unknown IBAN |
| Delivery charges | "The courier requires the seller to advance the fees, refunded afterwards" | A card payment of €30 to €60 |
| Parcel insurance | "The item must be insured, the platform reimburses you afterwards" | A payment + your bank details |
| The business account | "Your account must be upgraded to verified seller status" | ID document + bank details + a card |
| The fake dispute | "The buyer is contesting the sale, settle this within 24 hours" | A login on a fake customer portal |

The overpayment variant deserves special attention: it doesn't involve a booby-trapped link at all. The fraudster sends a fake transfer receipt, you notice "a mistake," and your instinct for honesty pushes you to refund immediately. The initial transfer never existed, or it will be reversed. Your refund, on the other hand, is very real and unrecoverable.

## Why sellers fall for it, cautious ones included

There are structural reasons, and they have nothing to do with naivety.

**The context made the exchange plausible.** You were expecting a buyer. The text message arrives at the exact moment when it makes sense. This is what security researchers call the *expectation context*: a fraudulent message that coincides with a real action by the victim multiplies its success rate.

**The fraudster knows real details.** The model of the bike, the colour of the sofa, the asking price, sometimes your first name: it's all in your listing. These elements give the message a veneer of authenticity that no generic fake text can match.

**Time pressure is built into commerce.** "My courier is coming tomorrow" is perfectly normal in a transaction. Urgency isn't perceived as manipulation, it's perceived as logistics.

**The seller is the one who wants something.** They want to get rid of the item, often to recover a sum already mentally spent. This emotional asymmetry switches off critical thinking far more effectively than any threat.

![Young man sitting on a wooden bench in a park, looking at his smartphone](/images/blog/2026-09-16-arnaque-sms-vente-entre-particuliers-faux-acheteur-lien-paiement/body-1.jpg)

## Reading the URL: the three seconds that save you

When a link arrives, there is a simple method for examining it without clicking. Read the address **from right to left**, starting at the first `/`.

The real domain is whatever immediately precedes the first `/`, going back to the dot before the extension. Everything else is decoration.

- `https://leboncoin.paiement-securise[.]xyz/valider` → the real domain is `paiement-securise.xyz`. The brand is merely a subdomain, i.e. text that anyone can write.
- `https://secure-paypa1[.]com/confirm` → the `1` replaces the `l`. On a 6-inch screen, while walking, nobody spots it.
- `https://bit[.]ly/3xK9pL` → a link shortener completely hides the destination. A legitimate payment service never uses one in a transactional text message.

This check requires a legible screen and decent light. Plenty of people click simply because they can't make out the characters: if you struggle to read small text, increasing the system font size genuinely makes a difference, as does an [anti-glare screen protector for smartphones](https://www.amazon.co.uk/s?k=film+protection+%C3%A9cran+antireflet+smartphone&tag=ds0608-21) when you check your phone outdoors. This isn't a cosmetic detail: a good share of smishing relies on typographic differences of a single character.

Another useful habit: never open a sensitive link on public transport or while walking. Visual vigilance drops, and statistically that's where accidental clicks happen.

## The warning signs to know by heart

No single signal is enough on its own. Two signals together mean it's a scam until proven otherwise.

- **The buyer doesn't negotiate and asks no questions about the item.** A genuine buyer wants to know whether the bike has been serviced, whether the warranty is still running, whether the screen is scratched.
- **He wants to leave the platform's messaging system.** Always, immediately, with a technical excuse.
- **He imposes his own courier.** A "private courier" he pays for himself, arriving very soon, and for whom you must advance the fees.
- **Payment goes through an unusual channel.** A link sent by text message, a confirmation email received before you signed up for anything, a request for your bank details outside the app.
- **The wording is almost perfect — but not quite.** A "please validate your reception of fund" in the singular, a misplaced capital letter, a sign-off that reads like a translation.
- **The number is a mobile starting 06 or 07 while the message claims to be automated.** Genuine platform notifications come from an alphanumeric sender ID or a short code.

## If you clicked and entered your details

Time matters more than anything else. Here is the exact order.

**1. Block your card immediately.** Call the card-blocking number printed on the back of your card or listed in your banking app. France's national interbank card-blocking service is reachable on **0 892 705 705**, 24/7. Do this before telling anyone else.

**2. Change the relevant passwords.** The one for the classified ads platform, the one for your bank if you entered it, and the one for your email if the password was reused. Enable two-factor authentication everywhere you can. For people juggling dozens of accounts, a [paper password notebook](https://www.amazon.co.uk/s?k=carnet+de+mots+de+passe+papier&tag=ds0608-21) kept out of sight remains an imperfect solution, but an infinitely safer one than a "passwords.txt" file on the desktop.

**3. Report the message.** Forward the fraudulent text to **33700**, France's national reporting service for spam calls and texts. It's free and it feeds into the blocking of numbers. The site **signal-arnaques.com** and the **Pharos** platform (internet-signalement.gouv.fr) also accept reports.

**4. File a complaint.** At a police station, at a gendarmerie, or via the online pre-complaint service. Bring screenshots of the listing, the conversation and the text message. Without a complaint, any hope of reimbursement is close to nil.

**5. Request a refund from your bank.** Article L133-18 of the French Monetary and Financial Code provides for the reimbursement of unauthorised payment transactions reported without undue delay. Banks often invoke the customer's "gross negligence" when they entered their own details. That refusal is not final: the Cour de cassation has repeatedly held that it is up to the bank to **prove** gross negligence, not up to the customer to prove its absence. If refused, refer the matter to the banking ombudsman, then potentially to the courts.

**6. Monitor your statements for several months.** Card details resold on underground markets can be exploited long afterwards. Some people add a low-tech layer of monitoring: paper statements filed in a [document organiser with compartments](https://www.amazon.co.uk/s?k=classeur+%C3%A0+compartiments+documents&tag=ds0608-21) rather than lost in a pile of post, to spot an anomaly from one month to the next.

![Man in a dark shirt, hand on his face, looking at his smartphone in front of a metal façade](/images/blog/2026-09-16-arnaque-sms-vente-entre-particuliers-faux-acheteur-lien-paiement/body-2.jpg)

## Selling online without exposing your phone number

The best protection is never giving the scam a chance to begin. A few habits are enough.

**Stay inside the platform's messaging system, no exceptions.** No stated reason justifies leaving it. If the buyer insists, he has just disqualified himself.

**Favour in-person handover with cash payment, or an instant transfer received and verified in your own app.** Verified means: you open your banking app, you see the amount credited. Not a screenshot presented by the buyer.

**Never advance any fees.** No legitimate courier asks a seller to pay in order to receive money.

**Clean up your listing photos.** A number plate, a street number, an invoice lying in the background, a parcel with your address on it: all of it later serves to personalise the attack. For close-up shots of items, photographing against a neutral background — a simple [foldable photo backdrop mat](https://www.amazon.co.uk/s?k=fond+photo+pliable+studio+produit&tag=ds0608-21) does the job — avoids exposing your home.

**Use a secondary number when the platform requires one.** A [prepaid SIM card](https://www.amazon.co.uk/s?k=carte+SIM+pr%C3%A9pay%C3%A9e+sans+engagement&tag=ds0608-21) dedicated to classified ads isolates your main number, the one tied to your bank and your accounts. If the secondary number ends up on a spam list, you simply bin it.

**Archive your exchanges.** Screenshots of the listing, the conversation and the buyer account's identity. These will be essential if you file a complaint.

## The blind spot: the buyer can be a victim too

Fraudsters sometimes use a hacked account belonging to a legitimate user, complete with its history, positive reviews and seniority. Displayed reputation is therefore not an absolute guarantee: it reduces the risk, it doesn't eliminate it.

By the same token, a profile created that very day with zero reviews isn't necessarily fraudulent — everyone starts somewhere. It's the **combination** of a brand-new profile, an absence of negotiation and a request to move off the platform that forms the body of evidence.

## Key takeaways

The fake buyer scam exploits no technical flaw. It exploits an asymmetry of vigilance: we have all learned to be careful when buying, and nobody warned us that we should be just as careful when selling.

The rule that sums everything up fits in one sentence: **receiving money never requires anything more than waiting**. No link to click, no card to enter, no approval to confirm, no fees to advance. The day someone tells you otherwise, with flawless logos and impeccable wording, you'll know exactly what you're looking at.

{/* image-sources: https://images.pexels.com/photos/5648374/pexels-photo-5648374.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/5384455/pexels-photo-5384455.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/13801812/pexels-photo-13801812.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
