# "You've won a prize, only 1 left": the fake brand prize-draw SMS scam

> Fake prize draws, fake loyalty programmes, fake brand birthday giveaways: how the winning-SMS scam works, why the €1.95 "delivery fee" is the real trap, and how to react.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-10-01/arnaque-sms-faux-parrainage-cadeau-fidelite-tirage-au-sort
- Published: 2026-10-01 (1 October 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, SMS, Guide, Protection des données, France 2026, smartphone, Anonymat

---
"CONGRATULATIONS! Your number has been drawn among our loyal customers. Your prize (latest-generation smartphone) is reserved until tonight. Only 1 left: https://fidelite-recompense-cadeau.com/lot"

This one doesn't threaten you. It says nothing about a fine, a blocked account or a parcel stuck in customs. It congratulates you. And that is precisely what makes it so formidable: we have learned, collectively, to be wary of text messages that frighten us. We have never learned to be wary of text messages that please us.

The **fake prize-draw** scam is one of the oldest in the smishing landscape, and one of the few that doesn't need to impersonate a public service in order to work. It doesn't necessarily steal your banking credentials. Often it does something far worse in terms of duration: it signs you up to a recurring charge you won't notice for months.

![Young woman wearing glasses, looking worried, talking on a turquoise smartphone outdoors](/images/blog/2026-10-01-arnaque-sms-faux-parrainage-cadeau-fidelite-tirage-au-sort/hero.jpg)

## Why good news works better than a threat

Smishing campaigns that play on fear — a fine, a missed delivery, a suspended account — have one flaw: they also trigger suspicion. A worried person tries to check. They call their bank, ask a relative, type the name of the service into a search engine.

A flattered person, on the other hand, doesn't check in the same way. They check **whether the prize is real**, not whether the sender is real. All their attention goes to the reward itself, never to the identity of whoever is promising it. It's a shift of attention that scammers have been exploiting since the earliest days of telephone marketing, and one that **Cybermalveillance.gouv.fr** unambiguously classifies among the variants of phishing: whatever emotion is used, the mechanism remains the collection of data or money through deception.

Three very concrete levers are added to this:

- **Artificial scarcity.** "Only 1 left", "offer valid until tonight", "just 3 winners". The countdown removes any time for reflection, exactly as in fake fine notifications.
- **Personal designation.** "Your number has been drawn" creates the illusion of selection. In reality, the message goes out to tens of thousands of numbers at once.
- **The trivial amount.** You're not asked for €500, you're asked for €1.95 in "delivery fees". An amount too small to trigger genuine vigilance — and that is the whole point of the set-up.

## The five most common disguises

The gift scenario comes in fairly stable families, found from one campaign to the next.

**1. The big-retailer prize draw.** The message mentions a supermarket chain, an electronics retailer or a very well-known fashion brand. The prize is a €500 gift card or a "mystery parcel". The argument: you're a customer, therefore you're eligible.

**2. The brand anniversary.** "For our 40th anniversary, we're giving away 1,000 prizes." The pretext is seemingly verifiable (the brand does exist and does have an anniversary somewhere), but unverifiable in practice.

**3. The mobile operator's loyalty programme.** The message presents itself as coming from your mobile operator and mentions "loyalty points about to expire" that can be converted into a gift. This is the most credible version, because operator loyalty programmes genuinely exist.

**4. The product test.** "You have been selected to test a new robot vacuum cleaner / a [connected toothbrush](https://www.amazon.co.uk/s?k=brosse+%C3%A0+dents+%C3%A9lectrique+connect%C3%A9e&tag=ds0608-21) / a coffee machine for free." All you have to do is "cover the shipping costs". This format thrives because product-testing programmes also exist, run by genuine consumer panels.

**5. The promotional refund.** The reverse variant: nothing is being given to you, money is being given back on a past purchase. The message imitates a customer service department.

In every case, the landing page follows the same skeleton: a wheel of fortune or a three-question satisfaction survey, a winning animation, then a form.

## The real trap isn't the prize, it's the form

This is where the gift scam differs from the others. The aim isn't always to empty an account in a single operation. It is often to get you to sign up, without noticing, to an **automatically renewing subscription**.

The typical sequence:

1. You "win" on the rigged wheel (it always lands on a prize).
2. You're asked for surname, first name, address, date of birth, email, mobile number. A lot of data, justified by "shipping the prize".
3. You're asked for €1.95 or €2.99 in postage, payable by bank card.
4. In tiny print, under the payment button: mention of a "premium" service billed at, say, €39.90 per month, cancellable at any time, 48-hour trial period included.
5. The prize never arrives. The monthly charge, however, begins.

The €1.95 amount is not a price: it's a **card validity test**. It confirms that the number, the expiry date and the security code are correct, and it serves as the basis for authorising subsequent charges.

> A free gift that requires a bank card is not a gift. Being asked for bank details to "cover the costs" is the stop signal, whatever the amount displayed.

Some variants don't ask for a card at all. They ask you to "confirm by SMS" by sending a keyword to a premium-rate short code, or to validate a code you receive — which triggers a subscription to a content service billed on your phone bill. This is the historic SMS+ mechanism, hijacked.

## The signs that give the message away in ten seconds

Even before you open the link, several clues pile up.

| Signal | What it reveals |
|---|---|
| No mention of your name | The mailing is mass, not personalised |
| Sender = 10-digit mobile number | Brands use sender names or short codes |
| Long, hybrid domain name (`fidelite-cadeau-lot-2026.xyz`) | Throwaway domain created for the campaign |
| "Only 1 left" | Manufactured scarcity, a classic pressure lever |
| Prize unrelated to the brand cited | Generic template reused from one campaign to the next |
| Missing accents, no cedillas | Foreign sending gateway using unaccented text |
| No accessible competition rules | A legal prize draw in France publishes them |

This last point is the strongest legally. A serious promotional operation has **rules** available for consultation, identifies the organiser (company name, address), and never makes handing over a prize conditional on a payment. The DGCCRF regularly points out that advertising lotteries must not mislead consumers about their chances of winning or about the actual costs involved.

And there's one common-sense test that is unbeatable: **did you take part?** You don't win a competition you never entered. If the message can't remind you when and how you played, there was no competition.

## Why you, and how they got your number

The question always comes up: "How do they know my number?" Three channels dominate.

**Data breaches.** The major breaches of recent years have put files into circulation containing surname, first name, email, mobile number and sometimes address. The CNIL regularly reports on this. Your number wasn't guessed: it was bought.

**Earlier prize draws, real or fake.** Every form filled in on a "free entry" page feeds databases that are then resold. Yesterday's fake competition funds today's text message.

**Random generation.** The structure of French mobile number ranges is public. A gateway can mechanically dial millions of combinations, without any personal data at all.

In the first two cases, the message may contain your first name — which enormously increases its credibility without proving anything whatsoever about the sender. It's the same slippage as in fake delivery texts that quote an exact address: the data is no longer a guarantee of legitimacy.

## The practical reflexes, in order

**Don't click, not even out of curiosity.** Simply opening the page is enough to confirm that the number is active, if the link contains a unique identifier. Curiosity is paid for in the volume of texts received in the following weeks.

**Report it to 33700.** This is France's official reporting system for unwanted texts and calls, backed by Arcep and the operators. Forward the message to 33700, then reply to the confirmation text with the sender's number. The service is free and genuinely feeds into the blocking of sending numbers.

**Report the fraudulent address on Phishing Initiative** and file a report on **cybermalveillance.gouv.fr** if you interacted with the page. For confirmed fraud, the **THESEE** platform (service-public.fr) allows you to file a complaint online.

**Verify through the official channel.** If the text mentions your operator, your retailer or your bank, go through the app installed on your phone or the number on the back of your card — never through the link. This reflex is easier to maintain when the phone stays usable: a [USB-C mains charger](https://www.amazon.co.uk/s?k=chargeur+secteur+USB-C+rapide&tag=ds0608-21) prevents the flat batteries that push people to "be quick" on a dying screen.

**Don't call back premium-rate numbers.** A call back "to confirm your prize" to an 08 number or a short code may be billed by the minute.

## If you've already handed over your bank card

Timing matters more than anything.

1. **Block your card immediately** with your bank, via the app or your institution's emergency number. In France, the interbank blocking service can be reached on 0 892 705 705.
2. **Request cancellation of the payment and revocation of the authorisation.** An unauthorised payment must be refunded by the bank under the conditions set out in the French monetary and financial code; the ACPR and the Banque de France regularly restate this framework, including where the victim was manipulated.
3. **Look for recurring charges** on your last three statements: an anonymous €39.90 line item often recurs every month without attracting attention.
4. **File a complaint** and keep everything: screenshot of the text, URL, timestamp, statements. A statement annotated by hand on a dated [A5 notepad](https://www.amazon.co.uk/s?k=bloc+notes+A5&tag=ds0608-21) does the job perfectly well for reconstructing the chronology at a counter.
5. **Monitor your other accounts**: the same email address and the same password used elsewhere are an open door.

If the charge goes through your operator's bill, contest it with customer service and ask for SMS+ services and on-bill purchases to be blocked. This block is free and permanent for as long as you don't lift it.

## Protecting those most at risk

Fake winnings affect every profile, but two groups pay more dearly: isolated elderly people, for whom personalised contact has a social value, and teenagers, who sometimes pay without grasping the recurring nature of a subscription.

A few simple measures change the situation:

- **Disable on-bill purchases** on the lines of minors and vulnerable people. It's the most effective step, and it's free.
- **Favour a card with systematic authorisation** or a [rechargeable prepaid card](https://www.amazon.co.uk/s?k=carte+prepayee+rechargeable&tag=ds0608-21) for online purchases: the ceiling mechanically limits the damage from a hidden subscription.
- **Turn on the SMS spam filter** offered by iOS and Android, and block the sender after reporting them.
- **Set up a conversation.** A practical guide to digital scams left within easy reach, with the rule "no gift ever has to be paid for", is worth more than a verbal reminder forgotten a week later.
- **Keep the screen readable.** A large share of accidental clicks comes from hurried reading on a cracked or dirty screen; a tempered-glass protector won't stop the scam, but it makes doubt easier to resolve when you reread a link character by character.

For seniors using a button-based handset, a [mobile phone with large buttons](https://www.amazon.co.uk/s?k=telephone+portable+senior+grosses+touches&tag=ds0608-21) also simplifies life: fewer apps, fewer browsers, fewer attack surfaces — even if the text message still gets through.

## Key takeaways

The fake SMS prize draw isn't a second-rate scam. It's simply more patient than the others: it isn't after a bank transfer within ten minutes, it's after a direct-debit authorisation that will last a year.

Three sentences are enough to protect yourself for good:

- You don't win a competition you never entered.
- A prize that requires postage paid by bank card is not a prize.
- A message that forbids you to think — "only 1 left", "until tonight" — is a message that knows it wouldn't survive being thought about.

The rest is habit. Forwarding to 33700 takes twenty seconds, blocking the sender five, and talking about it around you costs even less. That is exactly what drives down the yield of these campaigns: not better technology, but a collective reflex.

{/* image-sources: https://images.pexels.com/photos/27086833/pexels-photo-27086833.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
