
An urgent message from your bank, a cut-price offer on an unknown site, a link received via SMS to retrieve a package: these situations affect millions of French people every year. Online scams are no longer limited to clumsy emails filled with mistakes. Some frauds are so well constructed that the victim themselves authorizes the payment, without even realizing they have been trapped. Understanding these mechanisms allows you to react before it’s too late.
Bank manipulation fraud: when the victim authorizes the payment
The content circulating on the prevention of online scams often focuses on fake websites or classic phishing. However, one angle remains underexplored: fraud where you validate the transaction.
The principle is simple. A scammer contacts you pretending to be your bank advisor. They know your name, sometimes your account number. They report a suspicious transaction and ask you to “block” it by confirming an action on your banking app. In reality, you are authorizing an outgoing transfer.
This type of manipulation relies on urgency and trust in the displayed identity. The phone number may even appear as that of your bank due to spoofing. According to the Observatory of Payment Means Security of the Banque de France, online transfers are now the primary vector of fraud by amount in France, ahead of credit cards.
Checking a website is no longer sufficient if the attack comes via a phone call. To protect yourself, you should hang up and call your bank yourself, using the number listed on your card or official documents. Seeking to protect yourself from faljam scams starts with this habit of active verification, which is much more effective than simple passive distrust.

Common online scams: recognizing the signals before clicking
Before discussing warning signals, let’s take a concrete example. You receive a text message: “Your package is pending, confirm the delivery here.” The link leads to a site that looks like that of a well-known carrier. You are asked to pay a few euros in customs fees. You enter your banking details.
This scenario is a typical case of phishing. The fraudulent site copies the appearance of a well-known brand, but the URL is slightly different. An extra hyphen, an unusual extension (.shop instead of .fr), a misleading subdomain: these details are the first clues.
Have you ever noticed that an online offer pushes you to act quickly? “Only 2 items left,” “offer valid for 15 minutes”: time pressure is a lever used by the majority of scams. A legitimate seller never conditions a purchase on a decision made in a few seconds.
Here are the signals that should trigger a verification reflex:
- The URL of the site does not exactly match the name of the brand, or uses an unusual extension (.xyz, .top, .shop for a French brand)
- The message (SMS, email) contains a request for personal or banking data, even for a small amount
- The legal mentions of the site are absent, incomplete, or copied from another site
- The offer displays an abnormally low price compared to the market, without a credible explanation
A useful reflex: copy the name of the site into a search engine followed by the word “scam.” Forums and reporting sites often respond very quickly.
Protecting your banking and personal data on a daily basis
Why do scammers target personal data so much? Because a name, an address, and an IBAN are enough to set up secondary frauds: identity theft, unauthorized withdrawals, opening accounts in your name.
Never save your credit card on a site used only once. This habit, often taken for the sake of time, exposes your data in case of a leak on the concerned platform.
For online purchases, prefer virtual single-use cards offered by most banks. They generate a temporary number, valid for a single transaction. Even if this number is intercepted, it becomes unusable.
Passwords and two-factor authentication
A password reused across multiple sites is an open door. If one of those sites suffers a leak, all your accounts become vulnerable. Use a unique password for each service, stored in a dedicated manager.
Two-factor authentication (validation via SMS, app, or physical key) adds a layer of protection. Even with your password, an attacker cannot log in without the second factor. Activate it as a priority on your email and banking services.

Fake technical support scam: France among the main targets
A message appears on your screen: “Your computer is infected, call this number immediately.” The screen may even freeze, reinforcing the impression of a breakdown. This is the fake technical support scam.
The scammer pretends to be a Microsoft or Apple technician, takes control of your machine remotely, and charges for a fictitious “repair.”
No software publisher will ever contact you via an alarming pop-up window. If your screen displays this type of message, force close the browser (Ctrl+Alt+Delete on Windows, Cmd+Q on Mac). Never call the displayed number.
What to do if you are a victim of an online scam
Acting quickly limits the damage. Here are the concrete steps:
- Contact your bank immediately to block your card or stop an ongoing transfer
- Change the passwords of the affected accounts, starting with your email
- Report the scam on the Thésée platform (service-public.fr) for online scams, or on Pharos for illegal content
- Keep all evidence: screenshots, emails, SMS, bank statements
A quick report helps authorities identify networks and can allow funds to be frozen before they disappear. The speed of response is the determining factor in recovering lost amounts.
Scams evolve faster than internet users’ reflexes. The common thread of all these frauds remains the creation of a sense of urgency. Taking thirty seconds to verify a sender, a URL, or a phone number is often enough to thwart the trap.