# "Billing error, €47.80 is owed to you": the fake operator refund scam that follows a contract cancellation

> A text message tells you there's an overcharge to claim back after switching providers. A breakdown of this scam, which exploits the confusion around cancellation periods, and the reflexes that let you check in three minutes.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-10-08/arnaque-sms-faux-remboursement-forfait-trop-factureoperateur-resiliation
- Published: 2026-10-08 (8 October 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, SMS, Protection des données, operateur, forfait, France 2026, Guide

---
"CUSTOMER SERVICE: following the closure of your line, an overpayment of 47.80 EUR has been identified on your final bill. Enter your details before 12/10 to receive your refund: https://espace-regularisation-mobile.net/rb4780"

There's nothing spectacular about this one. No police force, no parcel stuck in customs, no account about to be shut down. Just a small sum, slightly odd, with cents attached — €47.80, not €50 — and a mundane piece of admin. The kind of message you deal with while walking, between two metro stops.

And if you've switched providers or cancelled a line in the past few months, it lands at the worst possible moment: the one where **you no longer quite know where you stand**.

![Dimly lit keypad of a push-button mobile phone in the dark, in black and white](/images/blog/2026-10-08-arnaque-sms-faux-remboursement-forfait-trop-factureoperateur-resiliation/hero.jpg)

## Why cancellation is the perfect blind spot

Number portability has made switching providers extremely easy. A RIO code obtained by calling 3179, a subscription with the new provider, and the switch happens within a few days. Simple to do, yes. Far less simple to understand from an accounting point of view.

Because behind that smooth switch, several things are happening at once:

- a **final pro-rata bill** from the old provider, calculated over a number of days that is often far from intuitive;
- sometimes residual **cancellation fees**, or conversely their reimbursement by the new provider as part of a promotional offer;
- a possible **security deposit** or usage advance to be returned;
- a **direct debit** that keeps running one month too long before being cancelled, followed by a refund that arrives later;
- **add-ons** billed over an incomplete month, out-of-plan charges from the transition period, tapering discounts that stop dead.

The result: a final bill that almost nobody checks line by line, and a vague feeling of having perhaps paid a little too much. That feeling is the fuel of the scam.

Worse: **genuine refunds do exist**. Arcep regularly handles billing disputes between subscribers and operators, consumer associations such as UFC-Que Choisir publish entire dossiers on final-bill errors, and operators do sometimes spontaneously refund an overpayment. So the fake text isn't inventing an absurd situation. It is **imitating a credible event** that you may well have experienced yourself.

## Anatomy of the message

Variants circulate in several forms, but the structure stays remarkably stable.

| Element | What the scammer does | Why it works |
|---|---|---|
| Sender | A mobile number starting 06/07, an unfamiliar short code, or a vaguely plausible alphanumeric sender name | The reader doesn't know their former provider's sending numbers by heart |
| Amount | A small, precise sum including cents | A round figure smells made up; €47.80 smells calculated |
| Reference | A fictitious case or credit-note number | Gives the impression of a real information system |
| Deadline | 48 hours, 72 hours, or a nearby cut-off date | Prevents calm verification |
| Action | "Enter your details" | Neutral wording that hides the request for an IBAN and card details |
| Link | A domain containing `-regularisation`, `-remboursement`, `espace-client-` | Looks like an operator URL without being one |

Note the absence of aggressive pressure. That's deliberate. A threat triggers suspicion; a **modest piece of good news** triggers routine. The scammer doesn't want you to think, they want you to tick the task off.

## What actually happens after the click

The form that opens never asks for everything at once. It advances in stages, each one seeming harmless after the last.

### Stage 1: identity

Surname, first name, postal address, date of birth, former line number, sometimes the name of the previous provider. Nothing secret on the face of it — and that's exactly the problem. This block of information makes up a reusable identity-theft kit for an attempted **SIM swap**, or for a "fake adviser" phone call a few weeks later, in which the scammer recites your details to establish credibility.

### Stage 2: the IBAN

Logical enough: you're being refunded, so an account is needed. Except that an IBAN handed over in this context is used to set up fraudulent **SEPA direct debits**, often small monthly amounts to fictitious providers, which slip under the radar for months.

### Stage 3: the bank card

This is the break in logic that nobody spots, because it's buried in a funnel that seemed legitimate. You're told a "€1 verification" is needed to validate the account. The data you enter goes straight to a control panel, and a payment attempt is launched **within the minute**.

### Stage 4: the authentication code

Your bank then sends you a real 3-D Secure code, or pushes a notification into the banking app. The fake site asks you to copy it out, sometimes calling you straight afterwards to "guide you through it". That's the moment when the few dozen euros you were hoping for turn into a transaction of several hundred, or even several thousand, euros.

> No organisation, no operator, no bank will ever ask you to type in or read out an authentication code received by text message. That code authorises a transaction; it never confirms an identity.

## The five signs that give away a fake text

### 1. A refund isn't requested, it's paid out

This is the simplest and most decisive point. When an operator identifies an overpayment, it **already has** your bank details: those of the direct debit you were using. It refunds to that same account, or applies a credit to your next bill. Giving it an IBAN again serves no technical purpose. The moment a message asks for your bank details in order to send you money, the matter is settled.

### 2. The link doesn't lead to the operator

Look at the domain, not the displayed text. The rule: read from right to left starting at the `/`. The real domain is whatever immediately precedes the first forward slash. In `espace-regularisation-mobile.net/orange`, the domain is `espace-regularisation-mobile.net` — "orange" is just a folder that anyone can create.

### 3. The channel doesn't match the operator's habits

French operators communicate about billing mainly by **email and through the customer account area**, sometimes by letter for disputes. A refund announced solely by text message, with no trace anywhere else, is an anomaly.

### 4. The urgency is unjustified

An overpayment doesn't expire. Under consumer law, a sum paid without cause can be reclaimed for years. A five-day deadline on a refund has no basis whatsoever.

### 5. The amount is too small to warrant a procedure

An operator doesn't build a secure data-entry funnel to give you back €47.80. It makes a bank transfer. The mismatch between the sum and the process being demanded is itself a warning sign.

## The three-minute check

The reflex to build is always the same: **get out of the message**.

1. **Don't touch the link.** Not even to "see what it looks like": some pages already collect technical information, and your visit alone confirms that the number is active.
2. **Open your customer account** via the official app you already have installed, or by typing the operator's address yourself. A genuine credit note or refund always shows up there.
3. **Reread your final bill.** It remains downloadable for several months after cancellation. If you keep your important documents, an [administrative document binder](https://www.amazon.co.uk/s?k=classeur+archivage+papiers+administratifs&tag=ds0608-21) saves you from digging through an inbox of 40,000 messages the day a doubt arises.
4. **Check your bank statement** for the last two months: an extra direct debit shows up in black and white, and so does a refund.
5. **Call customer service** on the number printed on an old bill — never the one in the text message.

If nothing corroborates the message: it's fake. Full stop.

## Report it, then delete it

Reporting takes fifteen seconds and feeds into a system that genuinely works. In France, **33700** is the reporting service for unwanted and fraudulent text messages, run by the operators under the aegis of the SMS+ association. Forward the message to 33700, then reply to the automated text with the sender's number. The sending number can then be blocked.

You can also:

- report the fraudulent address to **Phishing Initiative** (a France-based service that gets phishing pages taken down);
- file a report on the French Interior Ministry's **PHAROS** platform;
- consult **Cybermalveillance.gouv.fr**, which publishes free best-practice sheets and offers a support pathway for victims.

Then delete the message and move on. There's no point replying "STOP" to a scammer: that opt-out only has legal weight for legitimate commercial marketing.

## If you've already entered something

The decisive factor is time. Acting within the hour radically changes the outcome.

**If you handed over your card details**: block the card immediately via your banking app or the interbank hotline on 0 892 705 705. Then monitor every transaction. Under articles L133-18 and following of the French Monetary and Financial Code, an unauthorised payment transaction must be refunded by the bank, unless the cardholder has been grossly negligent.

**If you handed over an IBAN**: notify your bank and ask for monitoring or a whitelist to be set up on direct debits. An unauthorised SEPA direct debit can be disputed for **13 months** (8 weeks for a no-questions-asked refund, under SEPA rules).

**If you read out an authentication code**: assume a transaction is under way. Call the bank straight away, and file a police complaint. Filing a complaint is often a precondition for a compensation claim being processed.

**If you installed an app** offered by the page: turn off mobile data and Wi-Fi, uninstall it, then change your passwords from **another** device. For your most sensitive accounts, a [physical FIDO2 security key](https://www.amazon.co.uk/s?k=cl%C3%A9+de+s%C3%A9curit%C3%A9+FIDO2+USB&tag=ds0608-21) is the most robust protection against code hijacking, because there's no longer anything to copy out or read aloud.

## Reducing your attack surface for next time

This type of text message isn't going to disappear. What you can do is reduce the odds of it landing on your phone — and above all of it hitting home.

**Handle your exit from an operator carefully.** When you cancel, write down in a notebook the RIO code, the exact portability date, the amount of the final bill as announced, and the date of the last direct debit. A simple [spiral-bound notepad](https://www.amazon.co.uk/s?k=carnet+de+notes+%C3%A0+spirale+A5&tag=ds0608-21) sitting next to the computer is enough: three lines written on the day spare you any hesitation six weeks later, when a text message mentions an overpayment.

**Limit how widely your number circulates.** As WeLiveSecurity regularly points out, scammers harvest numbers from database leaks, prize-draw forms, reverse directories and the resale of contact files. A secondary number or a prepaid SIM dedicated to commercial forms is an effective way of compartmentalising.

**Turn on your phone's filters.** Android has strengthened its scam text detection in France, and iOS offers filtering of unknown senders. These filters aren't infallible, but they strip out some of the noise.

**Protect the device itself.** A smartphone that gets dropped, damaged or sent off for repair is a smartphone outside your control — and a trip to the repair shop is precisely when fake repair texts start arriving. A [tempered glass screen protector](https://www.amazon.co.uk/s?k=verre+tremp%C3%A9+protection+%C3%A9cran+smartphone&tag=ds0608-21) and a shockproof case cost less than a repair job, and above all save you from handing the device over to a third party.

**Talk about it with those around you.** This scenario particularly targets people who have recently switched providers — which means a lot of retirees who have moved to a cheaper plan. A [practical guide to digital security](https://www.amazon.co.uk/s?k=livre+s%C3%A9curit%C3%A9+num%C3%A9rique+arnaques+internet&tag=ds0608-21) left on a coffee table often starts the conversation better than a lengthy lecture, and lets you lay down the one rule worth remembering: **never give out bank details via a link received by text message**.

## Key takeaways

- A genuine overpayment is refunded to the account the operator already knows: you will never be asked for your IBAN to make that happen.
- Cancellation creates several weeks of accounting fog: that's precisely the window fake texts will aim for.
- An amount with cents and the absence of any threat are not proof of authenticity — they're techniques.
- Always check in the official customer account area, never via the link in the message.
- Report to 33700, block, delete.

A text message announcing money coming your way is no more trustworthy than one demanding money from you. Often it's the opposite: good news disarms vigilance better than any threat. Before you enter anything, put the phone down and go and check elsewhere. Three minutes, and the scam collapses all by itself.

{/* image-sources: https://images.pexels.com/photos/896895/pexels-photo-896895.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
