# "Your CAF file has been suspended": the fake family-benefits SMS scam

> A text message announces that your benefits have been suspended, or asks you to "confirm your bank details" on the CAF website. Here's how this scam works, why it targets low-income households, and the reflexes that keep you out of the trap.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-09-21/arnaque-sms-caf-allocations-trop-percu-rib
- Published: 2026-09-21 (21 September 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, SMS, France 2026, Protection des données, Guide, Smartphone

---
"CAF: your file no. ALL-77204 has been suspended due to missing bank details. Update your bank details before 25/09 to avoid interruption of payment: http://caf-allocataire-maj.fr/rib"

It's 6:40 p.m., you've just got back from the shops, and this message pops up between two other notifications. You haven't been in touch with the CAF this month. But you did switch banks in July. Or your daughter moved out. Or your household means-test rating shifted after the last income declaration. In a benefits file, there's always some little thing that isn't perfectly up to date.

And above all: if the payment fails to arrive, it isn't an administrative annoyance. It's the rent due on the 5th, the school canteen, the petrol to get to work. That tension is exactly what the scam leans on.

![Man in a suit holding a smartphone and a bank card in front of a laptop in a café](/images/blog/2026-09-21-arnaque-sms-caf-allocations-trop-percu-rib/hero.jpg)

## Why the CAF became such an attractive target

The Caisse nationale des allocations familiales (CNAF) and its network of local offices pay benefits to roughly **13.7 million claimants** in France. Family allowances, housing benefit, in-work benefit, income support, family support allowance, the education allowance for disabled children: it is the country's largest register of beneficiaries after the national health insurance system.

For a fraudster, that scale changes everything. Send 100,000 random texts impersonating a regional bank and you might reach 3% genuine customers. Impersonate the CAF and you reach a huge slice of the population — and, crucially, a population that statistically has an immediate need for the money in question.

Add three specific ingredients:

- **Intimidating administrative jargon.** "Reminder of entitlements", "overpayment", "excess received", "means-test rating", "quarterly income declaration", "adjustment". Who instinctively knows which of these triggers a refund and which triggers a demand for payment?
- **Scheduled, eagerly awaited payments.** The CAF payment calendar is public: money generally lands on the 5th of each month. A text arriving on the 28th or the 2nd slots perfectly into the anxiety about the upcoming transfer.
- **A digital-first relationship.** Since the online claimant account and mobile app became standard, the CAF genuinely does communicate by email and push notification. The fake slips into a legitimate stream.

The CNAF regularly publishes alerts on its caf.fr website and official accounts, reminding people that it **never asks for full bank details, card numbers or passwords by text or email**.

## The four scenarios doing the rounds

### 1. The suspended file

The most common one. A plausible file number, a deadline three or four days away, and a link to a page that faithfully reproduces the look of caf.fr. You're asked for your claimant number, your date of birth, and then bank details "to confirm" — in reality to steal, or to swap for the scammer's own on a hijacked genuine session.

### 2. The overpayment to repay

An aggressive variant: the CAF supposedly paid you €428.30 too much, and you must settle up online or face "enforcement proceedings". The amount is always precise, never round. Payment is taken by card on a fake payment page, often followed by a call from the "recovery department" to get you to authorise a larger transaction.

### 3. The exceptional payment

The positive mirror image: you're supposedly entitled to a "solidarity supplement" or an "exceptional back-to-school grant" of €180, to be claimed before it expires. To receive it, you must… enter your bank card details, supposedly to "verify the identity of the account holder". This version flourishes at the start of the school year and in December.

### 4. The fake adviser who calls back

The most dangerous. The text merely plants the seed of doubt; a human then calls, from a number displaying as your local office (caller ID spoofing, technically trivial). He already knows your name and your town — sometimes taken from an earlier data breach. He asks you to read out a code received by text "to authenticate the call". That code actually validates a payment, a change of details, or the addition of a device to your online banking.

In its annual report from the Observatoire de la sécurité des moyens de paiement, the Banque de France highlights the steady rise of these **manipulation-based frauds**: it is no longer the technology that breaks security, it is the victim who, in good faith, opens the door herself.

## The signs that don't lie

There are reliable markers, and there are false ones. Let's start by killing off a myth: **spelling is no longer a criterion**. Today's text generators produce flawless messages. Some fakes are better written than the real thing.

Here's what still holds up:

| Element | Genuine CAF text | Fraudulent text |
|---|---|---|
| Link | Points to `caf.fr` or the app; often no link at all | `caf-allocataire.xyz`, `caf-regularisation.com`, `caf.fr.secure-maj.net` |
| Request | Invites you to check your personal account | Asks for bank details, card number, password, ID document |
| Urgency | Long administrative deadlines, reminder letters | 24 to 72 hours, threat of suspension |
| Payment | The CAF never takes card payments via a link in a text | Immediate card payment page |
| Sender | Short name ("CAF") or official number | Mobile number starting 06/07, foreign prefix, or spoofed name |

The most important point is the **subdomain**. `caf.fr.verification-dossier.com` does not belong to the CAF: the real domain is always whatever comes immediately before the last dot preceding the first `/`. Here, `verification-dossier.com`. It's the single most effective trap in all of smishing, because a phone screen truncates the address and displays precisely the reassuring part.

A practical detail: reading a full URL on a cracked screen or a five-inch display set too small is a feat in itself. Many victims describe having "seen caf.fr" without seeing what came after. Replacing broken glass or fitting a [tempered glass screen protector](https://www.amazon.co.uk/s?k=verre+tremp%C3%A9+protection+%C3%A9cran+smartphone&tag=ds0608-21) isn't a cybersecurity measure as such, but a legible screen is one of the basic conditions for checking a link before tapping it.

## What the CAF actually does — and never does

To recognise the fake, you need to know the real thing. A few reference points drawn from how the CAF network officially operates:

- **Entitlement notifications** and important decisions arrive in the "Mon compte" area on caf.fr and, for the most formal ones, by post.
- An **overpayment** is notified by letter, with details of appeal routes and deadlines, and is recovered by deduction from subsequent benefits or by a payment order sent to the office. Never by bank card via a link received in a text.
- A **change of bank details** is made from your authenticated personal account, or via FranceConnect. The CAF does not phone you to dictate it.
- The CAF **never** asks for your password, nor for the one-time code sent by your bank.
- Outbound calls from an adviser do exist, but an adviser will never demand a financial transaction on the spot.

If in doubt, the only sound method is to ignore the message and come back through a channel you control: the CAF app installed from your phone's official store, the address caf.fr typed by hand, or 3230 — the national public-service number, charged at standard rates.

![Man wearing glasses holding a bank card and looking at his smartphone in front of a laptop](/images/blog/2026-09-21-arnaque-sms-caf-allocations-trop-percu-rib/body-1.jpg)

## Who really gets caught

It's tempting to picture elderly victims with little digital confidence. The data from public reporting platforms tells another story. Those hit by fake texts from social security bodies are often **working people, young parents, in insecure jobs or shared custody arrangements** — precisely the people whose files change frequently and whose monthly budget has no slack at all.

Three aggravating factors come up again and again in testimonies:

1. **Multitasking.** The text is read on the bus, between two children, at a shop checkout. Available attention lasts a few seconds.
2. **Anticipated shame.** Many fear they've "made a mistake on a declaration". That diffuse guilt pushes people to sort it out quickly and quietly, without mentioning it.
3. **The habit of the digital counter.** When the entire relationship happens through a screen, one more screen raises no alarm.

There is one very simple and very effective counter-reflex: **forbid yourself from making any financial decision within five minutes of an unexpected message**. Five minutes is enough for the fear to subside and the inconsistency to surface.

## Protecting your phone without becoming an expert

No tool replaces vigilance, but a few settings substantially reduce your exposure.

**Turn on filtering for unknown senders.** On iPhone, Settings → Apps → Messages → "Filter Unknown Senders". On Android, Google's Messages app offers spam protection you can enable in the settings. Suspicious messages are then isolated in a separate tab, which defuses the element of surprise.

**Never open a link from the notification.** Get into the habit of closing the text, opening the official app and looking for the information there. If the message is genuine, the information will be there.

**Lock down payment authorisation.** Most banks let you cap online payments and require biometric validation in the app. That's the last barrier when everything else has given way.

**Back up what matters.** A [USB stick for smartphones](https://www.amazon.co.uk/s?k=cl%C3%A9+USB+smartphone+USB-C&tag=ds0608-21) or a small external hard drive lets you keep benefits-related documents offline (certificates, supporting papers, bank details) without depending on an account that could be compromised.

**Prepare the ground for less confident relatives.** For an elderly parent or someone unused to digital tools, a [mobile phone with large buttons](https://www.amazon.co.uk/s?k=t%C3%A9l%C3%A9phone+portable+senior+grosses+touches&tag=ds0608-21) and no internet browser simply removes the risk of tapping a booby-trapped link. Plenty of families make that choice and are very happy with it.

And for those who'd rather understand than endure, a [practical cybersecurity guide for the general public](https://www.amazon.co.uk/s?k=livre+cybers%C3%A9curit%C3%A9+grand+public+fran%C3%A7ais&tag=ds0608-21) in French — there are several, including some written by former investigators — does more good than yet another security app installed and then forgotten.

## If you've clicked: what to do, in order

The costliest reflex is waiting. Here's the sequence to follow.

1. **Cut it off.** Close the page, enter nothing else, and don't answer any call from the "fraud department".
2. **Call your bank immediately**, using the number on the back of your card. Ask for the card to be blocked and the account monitored. If a transfer has already gone out, explicitly request a recall of funds procedure.
3. **Report the text to 33700**, the national reporting service for spam calls and texts: forward the message to 33700, then send the sender's number when prompted. It's free and it feeds into the blocking of ongoing campaigns.
4. **File a complaint.** For bank fraud, the **Perceval** platform (via service-public.fr) lets you report fraudulent use of your card. For broader online fraud, the **THESEE** system allows you to file a complaint online.
5. **Notify the CAF** through your personal account or on 3230, to check that no change of bank details has been recorded on your file.
6. **Report the fraudulent site** to **Phishing Initiative** and **Cybermalveillance.gouv.fr**, which supports victims free of charge and points them towards the appropriate steps.
7. **Change your passwords** if you entered a login you reuse elsewhere. A [password manager](https://www.amazon.co.uk/s?k=gestionnaire+de+mots+de+passe+cl%C3%A9+s%C3%A9curit%C3%A9&tag=ds0608-21), even a free one, avoids the trap of a single password used across ten sites.

> Worth remembering: under French law, article L133-18 of the Monetary and Financial Code requires the bank to refund an unauthorised payment transaction, unless the customer has been grossly negligent. The Cour de cassation has ruled on several occasions that handing over data in response to a sophisticated fraudulent message does not automatically establish such gross negligence. Don't give up on claiming a refund on the grounds that "it's your own fault".

## Talking about money is already a form of protection

What makes the CAF scam powerful isn't its technique — that part is crude. It's the silence it creates. People don't readily admit they're afraid of losing their housing benefit, or that they believed they owed €428 to a social security body.

The best antivirus here is a sentence said out loud: "I got a weird text from the CAF — did you get one too?" In a household, a family or a neighbourhood association, it's often that question that stops the scam dead.

And if you want to quickly warn several people close to you that a campaign is circulating, a simple message will do — and that one, at least, won't contain a booby-trapped link.

{/* image-sources: https://images.pexels.com/photos/23496937/pexels-photo-23496937.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/23496925/pexels-photo-23496925.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
