"Your Netflix subscription has expired": the fake account renewal text message scam

Guide

Back to the blog
L'équipe Envoyer SMS Gratuit6 October 20269 min read
Filed underGuide

"NOTICE: your subscription has expired. Your access will be suspended within 24h. Please update your payment method: https://compte-renouvellement-maj.net/billing"

This one doesn't mention a fine, or a parcel, or an inheritance. It doesn't threaten you with the police and it doesn't promise you a €326 refund. It tells you something perfectly mundane: a payment that didn't go through. And honestly: how many subscriptions are you paying for right now? Video streaming, music, online storage, antivirus, games, news, gym membership, that photo-editing app whose free trial you forgot about. Three? Eight? Twelve?

That uncertainty is exactly what the scam exploits. The fraudsters don't need to know what you're subscribed to. They know that you don't entirely know either.

Grey Samsung smartphone lying face down on a wooden table

The perfect ground: a life sliced into €7.99 direct debits

In little more than a decade, we have moved from a purchase model to a subscription model. The shift runs deep: the amounts are small, recurring and, above all, invisible. An €11.99 debit in the middle of a bank statement sets off no mental alarm. Plenty of households can no longer say off the top of their head:

  • which platforms are still active;
  • which bank card is registered on each one (often an expired card, since replaced);
  • which email account serves as the username;
  • which renewal date applies.

Add to that a very concrete fact: genuine subscription services really do send payment failure messages. When a card expires, when a limit is reached, when the bank declines the transaction, the platform gets in touch. So smishing isn't inventing an implausible situation: it's imitating something you've already experienced.

That's the very definition of good bait: a message that drops straight into the information gap, at precisely the moment when you can't verify it from memory.

Anatomy of the message

The variants come in waves, but the skeleton is always the same.

ElementWhat the scammer doesWhat the real service does
SenderMobile number starting 06/07, unknown short code, or a cobbled-together display nameA stable alphanumeric sender, and above all a notification inside the app
Urgency"Within 24h", "immediate suspension", "final reminder"Several reminders spread over days, even weeks
LinkOdd domain: netflix-paiement-maj.info, compte-billing-fr.net, a shortened linkA link to the official domain, or no link at all
AmountOften tiny: €1, €1.99, "card verification"The exact amount of your plan
SpellingMissing accents (typical of bulk sending), clumsy phrasingA clean message, personalised with your first name and your plan

The most telling detail remains the trivial amount. Asking for €59.99 triggers suspicion. Asking for €1 "to revalidate your card" slips under the radar: you think you're authorising a trifle, when in fact you've just handed over your full card number, its expiry date, its security code and sometimes the 3-D Secure code you'll go on to read out over the phone.

What actually happens after the click

The page that opens is, in most cases, a near-perfect copy of the official payment screen: logo, typography, colours, legal notices copied word for word. Some phishing kits go as far as displaying the real price of the plan you select.

Three scenarios then unfold, sometimes one after another.

1. Bank card harvesting. Your details go off to an admin panel where they are resold or used within the hour. The scammer will often try a small test purchase before scaling up.

2. Relaying the verification code. If your bank requires strong authentication, the fake page displays a field reading "Enter the code received by SMS". You are then approving, in real time, a transaction initiated by the fraudster. Cybermalveillance.gouv.fr and the Banque de France are emphatic on this point: an authentication code should only ever be entered on a page you opened yourself, for a transaction you initiated yourself.

3. Theft of the account itself. Sometimes it isn't the card the scammer is after but your login credentials. A stolen streaming account resells for a few euros; an online storage account gives access to your photos, your scanned ID documents, your invoices — ideal raw material for later identity theft.

The four families of impersonated subscriptions

Video and music streaming

This is the scam's shop window, because penetration is enormous: send the message to 100,000 numbers and half of them will genuinely be customers. The message plays on domestic frustration: an evening in, a series part-watched, and the idea that your access is about to be cut off.

Online storage and ecosystem accounts

More dangerous, less spectacular. "Your storage space is full, your backups have been interrupted": here the lever is the fear of losing photos. The defence, in fact, isn't a link but a habit: a local backup on an external hard drive for backups drastically reduces your dependence on the cloud, and therefore your panic when a message waves that threat around.

Antivirus and paid "protection" services

A nastier variant: the text announces either the expiry or the automatic renewal of an €89 subscription, with a number to call "to cancel". At the other end of the line, a bogus adviser talks you through installing remote-access software. This is where it joins up with the fake tech support scam.

Administrative and telecoms services dressed up as subscriptions

"Your multi-device option has not been renewed", "your data plan is about to expire". The message mixes operator vocabulary with subscription vocabulary, which makes it hard to categorise and therefore more credible.

The thirty-second check

There is a single rule, and it is enough in 100% of cases: never check a subscription from the message that alerted you to it.

  1. Close the text message. Don't click, not even "just to see": some pages already collect technical information, and your mere visit confirms that the number is active.
  2. Open the official app or type the service's address into your browser yourself. A genuine payment problem is always displayed there, usually right on the home screen.
  3. Check your bank. A rejected payment leaves a trace in your banking app. If nothing shows up, there's nothing to sort out.
  4. Look at the renewal date in your account settings. If it's three months away, case closed.
  5. Report it, then delete it. Forward the message to 33 700 (the official French reporting service for unwanted text messages, run by the mobile operators) and submit the link to Phishing Initiative. Reports genuinely help: they feed into blocklists.

No reputable subscription platform will ever ask you for your full bank details by text message, nor for your password, nor for a verification code to be typed in anywhere other than its own payment flow.

Taking back control of your subscriptions: the best protection of all

Subscription smishing dies the day you know exactly what you're paying for. It's an hour's work, and it's worth more than any antivirus.

  • Take inventory. Open the last twelve months of your bank statements and note every recurring payment. Many people discover two or three forgotten services in the process. A simple spiral notebook kept next to the computer is enough to maintain the list: renewal dates, the email used, the amount.
  • Centralise your credentials. A password manager stops you reusing the same password across ten services. For those who prefer paper, a secure password notebook kept out of sight remains infinitely safer than a "passwords.txt" file on the desktop.
  • Turn on two-factor authentication everywhere it's offered, ideally via an authenticator app rather than by text message — SMS can still be intercepted, notably through SMS Blaster-type attacks or line hijacking.
  • Ring-fence recurring payments. A virtual card with a spending cap, offered by most banks, mechanically limits the damage from a leak.
  • Shrink your exposure. If your phone is your single point of access to everything, protect it physically too: a cracked screen, a device handed over for repair or resold without being properly wiped — these are all open doors. A tempered-glass screen protector and an up-to-date backup beat an improvised plan B.

And if you've already clicked?

Don't panic — but be methodical, and quick.

In the first few minutes:

  • Call your bank or block the card from the app. The "I'll wait and see if anything gets debited" instinct is the most expensive of all.
  • Change the password for the service concerned, and for every other account sharing that same password.
  • Check the connected devices in your account settings, and log out any unfamiliar sessions.

In the following days:

  • Keep an eye on your statements. In the event of a fraudulent debit, the French Monetary and Financial Code (articles L133-18 onwards) provides for the reimbursement of unauthorised transactions, provided you report them promptly. The Banque de France regularly points out that the bank must refund unless there has been proven gross negligence — and that falling for a well-crafted phishing attempt is not, in itself, gross negligence.
  • File a complaint, or at the very least report the facts on the official online complaint platform. Banks often require the case reference number.
  • If your identity documents have circulated, watch for credit accounts opened in your name and contact Info Escroqueries (0 805 805 817, free service).

The giveaway that never fails

Every variant of this text message has one thing in common, and it's the best detector there is: they hand you the route. A link, a number to call back, a button. Genuine services simply ask you to log in — full stop. They don't care how you get there, because they know you have their app.

Put another way: the moment a message helpfully offers you directions for fixing the problem it has just told you about, the directions are the problem.

Bear in mind, too, that the scam is evolving. Automatically generated texts are now free of spelling mistakes, cloned pages are flawless, and some waves include your first name — lifted from a commercial data breach. The "spelling mistake" test no longer cuts it. The only criterion that holds up over time is structural: financial information is verified at the source, never in the notification.

No subscription has ever expired within twenty-four hours. None has ever been rescued by a text message. And none ever renews on a domain you've never seen before.

Free SMS · No sign-up · To France

Envoyez votre SMS gratuit en quelques secondes

Pas de compte à créer, pas de publicité, pas de limite : écrivez votre message, indiquez le mobile, et envoyez-le gratuitement depuis votre navigateur.

Envoyer un SMS gratuit