

The Texto SMS Gratuit team
26 July 2026 · 6 min read
Every summer, the same pattern resurfaces: as the tax refund payments approach, scammers send out bulk SMS messages impersonating the French tax office (DGFiP) to trick taxpayers. In 2026, the campaign has reached unprecedented scale: 12.6 million households are due to receive a payment from the French Treasury between 24 July (first wave) and 31 July (second wave), and cybercriminals are timing their messages to this calendar. For an SMS service like Texto SMS Gratuit, it is the right moment to remind everyone why trusting a short code and reading every link critically remain your best defences.
How the scam works
The method, documented by Cybermalveillance.gouv.fr in its 15 July 2026 alert, is now well-oiled. You receive an SMS — sometimes an email or a phone call — that looks for all the world like an official communication from the Direction générale des Finances publiques (France's tax administration). The message announces a tax refund for a precise amount (often between €187 and €262, sometimes more), with a 48-hour countdown to "validate" the payment. The embedded link points to a fake site mimicking impots.gouv.fr, which pushes the user to enter their bank details or tax login credentials.
Three red flags should warn you immediately:
- The sender number: a genuine DGFiP SMS is never sent from a standard French mobile number. The official channels are the personal account on impots.gouv.fr, the secure messaging system on the site, or an email ending in
@dgfip.finances.gouv.fr. - The URL of the link: it mimics the official address but uses a sketchy domain (
impots-gouv-remboursement.com,dgfip-fr.net, etc.). A lower-case h swapped for a capital H, an extra hyphen, a.topor.clicksuffix are typical giveaways. - The request for bank details: the DGFiP never asks for your IBAN, card number or login by SMS. A real refund is paid automatically to the account already known by the tax office.
Photo: Unsplash — a single SMS on a screen is enough to trigger a several-hundred-euro bank fraud.
Why this wave is especially dangerous
Three reasons explain the virulence of the 2026 campaign. First, the tax calendar is perfect timing: taxpayers are genuinely expecting a payment, which lowers their guard. When a message arrives at the right moment, with the right amount, doubt creeps in. Second, criminals now cross-reference several databases from past leaks: name, address, operator, sometimes even IBAN — exactly what happened in the Free data breach of 2024 sanctioned by the CNIL. Third, the quality of the SMS keeps improving: no glaring spelling mistakes, a copied logo, an impeccable administrative tone, even a legal disclaimer at the bottom. The trap is, technically, well built.
Arcep and the operators have set up several barriers, but they don't catch everything: filtering of premium-rate numbers, reporting to 33700, tagging of long SMS as "potential spam" on iPhone and Android. These protections are not a substitute for human vigilance.
The right attitude in three moves
When you receive an SMS about a refund, apply the "zero-click rule" in three steps:
- Zero click on the link. Type
impots.gouv.fryourself in your browser's address bar. If a refund really is pending, it will show up in your personal account, under "Account situations". - Zero call-back to the number. Scammers sometimes leave a number to call back: it is a foreign VoIP line, billed at premium rates, designed to keep you on the phone. Hang up immediately.
- Zero data transmission. No IBAN, no password, no SMS code. No public service will ask for these by SMS — this is an unmissable marker of fraud.
If you have received such an SMS, forward it to 33700 (the free SMS spam reporting platform run by the operators under Arcep supervision). You can also report the fraudulent site on Signal-Spam and on Phishing Initiative.
You clicked? Here is the order of actions
Even the most cautious among us can fall for it on a tired day. If you have clicked the link and entered information, act in this order:
- Within the first hour: immediately place a card stop with your bank. Every minute counts: most scams trigger an online payment within minutes of your data being entered.
- Within 24 hours: file a report on the Perceval platform (perceval.interieur.gouv.fr) run by the French Ministry of the Interior. Perceval turns your submission into a file sent directly to the police or gendarmerie.
- Within 48 hours: change the passwords of your sensitive accounts (online banking, main email, impots.gouv.fr). If you used the same password on another service, change it too — this is the principle of credential stuffing we described in our article on protecting your SMS privacy.
- Within the week: file a complaint at a police station or gendarmerie, or via the online pre-complaint form. Article 226-4-1 of the French Penal Code punishes digital identity theft with one year in prison and a €15,000 fine.
Photo: Unsplash — checking your online accounts yourself, from your browser, is still the most effective safeguard.
The institutional network behind the alert
The fight against these scams now mobilises a full ecosystem, and that is good news. Cybermalveillance.gouv.fr publishes alerts and keeps a "Awareness and best practices" guide up to date; the DGFiP reminds everyone on its official social channels that it never asks for bank details by SMS or email; the operators filter premium-rate numbers and block certain domains at the network level; and 33700, which turns 18 in 2026, has led to the closure of several thousand fraudulent numbers. Finally, Arcep reminded in its latest report on operator satisfaction in France that the fight against spoofing (number impersonation) remains a priority for 2026-2027, with a short-number authentication system being rolled out.
What you need to remember
- 12.6 million households are concerned by the 24 and 31 July 2026 tax refunds: that is the target.
- The DGFiP never asks for your IBAN, bank card or login by SMS.
- Three reflexes: don't click, don't call back, don't transmit anything.
- If you have clicked: card stop → Perceval → change passwords → file a complaint.
- Report any suspicious SMS to 33700 and any fraudulent page to Phishing Initiative.
To send a free SMS without giving your number to a third party and without leaving a trace, our sending form remains accessible to everyone, without registration. For any question on the privacy of your messages, you can consult our FAQ, our legal notice or contact us.

