🎓 CoursesConsumers & everyday paymentsBeginner⏱ 60 min
🔒
Protecting your everyday payments. 6 chapters and a final quiz.
Phishing, fake bank advisors, skimming, transfer fraud: this course for everyday consumers covers every major payment scam and the concrete habits that protect you from them. Set up your card, understand 3-D Secure, respond to an unrecognized debit, and protect your family, with the legal deadlines and the right contacts.
🇫🇷
Recognize the main types of payment scams: phishing, spoofing, skimming, transfer fraud
Foil the fake bank advisor scam and know when to hang up
Set up your card to reduce risk: limits, contactless, virtual cards, 3-D Secure
Follow the exact procedure for an unrecognized debit: block, dispute, refund, report
Chapter 1. Payment fraud in France: the big picture.
Every year, the Observatoire de la sécurité des moyens de paiement (OSMP), France's payment security watchdog hosted by the Banque de France, publishes the official snapshot of fraud. Its findings cut two ways. Payments have never been more secure technically (EMV chips, strong authentication, tokenization), yet fraud remains massive because it has changed targets. Fraudsters no longer attack the card; they attack the person holding it. This is called social engineering: getting you, through pressure or trickery, to do yourself what no hacker could do in your place.
€1.195B
fraud on non-cash payment instruments in France in 2023
OSMP, annual report published in July 2024
0,053 %
fraud rate on card payments (2023), one of the lowest in Europe
OSMP / Banque de France
≈ 2/3
share of remote (online) payments in card fraud losses
OSMP
13 months
legal deadline to dispute an unauthorized transaction
French Monetary and Financial Code, Art. L. 133-24
Paying in a store with chip and PIN has become almost impossible to defeat. Fraud has shifted to remote payments and above all to manipulating the victim (fake advisors, fake websites, fake bank details). Checks, although they are disappearing, are paradoxically still the most defrauded payment method relative to the amounts they carry. Here is the map of the threats we will defuse one by one.
Card type
How it works
Channel
#1 defense
Phishing / smishing
Fake email or text (package delivery, fine, Ameli health insurance, bank) leading to a fake site that harvests your data
Email, text
Never click: type the official address yourself
Spoofing / fake bank advisor
A call that spoofs your bank's number to get you to approve transactions
Phone
Hang up and call the number on the back of your card yourself
Skimming
Copying the card's magnetic stripe at a tampered ATM or terminal
ATM, card terminal
Inspect the card reader, shield your PIN
Transfer fraud
Fake bank details (contractor, notary, employer) or a fake emergency to divert a transfer
Email, mail
Verify the IBAN through another channel + Verification of Payee (VoP)
Family emergency scam
A “Mom, I lost my phone” message asking for an urgent payment
WhatsApp, text
Call the relative back on their usual number; use a family code word
The main types of payment fraud (and the main defense against each)
🔑
The one principle to remember
Nearly all modern fraud needs your cooperation: a click, a code you share, an approval in the app. No technology protects you against an approval you give willingly, so the security of your payments depends first on a reflex. When it feels urgent, slow down.
🎯 Quick question
According to the OSMP, where is most card fraud concentrated by value?
Chapter 2. Phishing and the fake bank advisor: the scam of the century.
Three words, one playbook: phishing (by email), smishing (by text), and vishing (by phone, voice phishing). The bait imitates a legitimate sender: a delivery company, the tax office, the national health insurance fund, or a bank. It steers you to a fake site where you type in your own card details or login credentials. That data feeds the second, far more dangerous phase: the call from the fake bank advisor.
What a phishing text looks like (real examples, anonymized)
CHRONOPOST: your package N.FR2941X is on hold.
Customs fee required (EUR 1.45) within 24h:
https://chronopost-parcel-tracking-fr.info
AMELI NOTICE: your new Vitale health card is ready.
Update your information:
https://ameli-card-renewal-secu.com
=> Red flags: made-up domain, believable micro-amount,
countdown, subtle typos. A real organization
NEVER sends a payment link by text.
A few hours or days after you enter your details on the fake site, your phone rings. The screen shows your bank's real number, thanks to a technique called spoofing, which uses software that can display any number the caller chooses. The “advisor” is calm and professional, knows your name, and sometimes knows your recent transactions (harvested through the phishing). He reports suspicious payments “in progress” and offers to help you block them. The trap closes.
Anatomy of the fake bank advisor scam
Fraudster
Sends a phishing text (package, fine, Ameli...)
Goal: collect card number, name, and phone number
➜
Victim
Enters card details on the fake site
The fraudster now has a complete profile
➜
Fraudster
Calls, displaying the bank's real number (spoofing)
The script: “fraudulent payments are going through on your account right now”
➜
Victim
Receives genuine authentication notifications
They are for payments the fraudster is making at that very moment
➜
Fraudster
Asks you to “approve to cancel” or to add the card to a wallet
Each approval actually authorizes a payment or adds the card to HIS phone
➜
Victim
Approves in their banking app
The money is gone: the fraud is over in a few minutes
⚠️
The absolute rule
Your bank will never ask you to approve a transaction in the app “to cancel it.” Nor will it ask you to share a code received by text, transfer money to a “safe account,” or add your card to a wallet over the phone. Approving = paying. Any request to approve something over the phone is fraud, without exception.
Regulators are fighting back too. Since October 1, 2024, French telecom operators must block calls that spoof a French landline or mobile number. The system, created by the 2020 Naegelen law, relies on a number authentication mechanism called MAN. Spoofing is declining, but fraudsters are already working around it with foreign numbers and messaging apps. In the courts, the Cour de cassation ruled on October 23, 2024 (Cass. com., No. 23-16.267). A victim of a fake advisor calling from the bank's displayed number was not grossly negligent, because this setup “lowers the vigilance” of the user, so the bank must refund.
Hang up as soon as an “advisor” mentions fraud in progress and asks you to act: a real fraud team blocks first and explains later.
Call back yourself on the official number printed on the back of your card or on your statement, never on a number the caller gives you.
Never approve a notification that you did not trigger with a purchase you are making right now.
Never share a code received by text, even with someone who claims to work for your bank.
Forward fraudulent texts to 33700, France's national reporting number, then delete them.
Read the notification text before approving: the amount, the merchant, and sometimes the device are spelled out in black and white.
🔑
The foolproof test
A real advisor will always accept that you hang up and call the bank back on its official number. A fraudster never will, and will invoke urgency, the office about to close, an imminent risk. Insistence is the telltale sign.
🎯 Quick question
A “bank advisor” calls you (the number displayed really is your bank's) and asks you to approve a notification to “cancel a fraudulent payment.” What do you do?
Chapter 3. Skimming, theft, and in-person fraud.
“Physical” fraud has not disappeared; it has become rarer and more professional. Skimming means tampering with an ATM or payment terminal to copy the card's magnetic stripe, while a pinhole camera or fake keypad captures the PIN. The stolen data is used to make cloned cards for use in countries where the magnetic stripe still works. In France, the EMV chip makes a clone useless in stores, but your PIN remains valuable to thieves.
🏧
Tampered ATM
A reader fitted over the card slot, an overlay keypad, a camera hidden in the brochure holder. Warning signs: a part that moves, visible glue, an unusual-looking slot. Use ATMs inside bank branches when you can.
👀
PIN theft by observation
In “shoulder surfing,” someone memorizes your PIN over your shoulder, then steals the card a few minutes later (a bump, a distraction). Always shield the keypad.
🎭
Distraction theft
A “good Samaritan” points to a bill you supposedly dropped or offers to help while an accomplice snatches or swaps your card at the ATM. Never accept help from a stranger at an ATM.
📳
The contactless myth
No, nobody can “drain your card” by brushing past your pocket. Each transaction is capped at €50, your bank limits the cumulative amount without a PIN, and every transaction can be traced to the fraudster's account.
Contactless actually has one of the lowest fraud rates of any payment method: about 0.01% of amounts according to the OSMP, five times lower than the card average. The €50 per-transaction cap (in effect since May 11, 2020) and regular PIN prompts make a stolen card hardly worth exploiting. And blocking a card now takes two taps in the app.
Before inserting your card, give the ATM's card reader a gentle tug: a poorly attached skimmer will come loose.
Shield your PIN with your free hand, every time, even when you are alone.
Turn down any help from a stranger at the ATM; if the machine keeps your card, stay at the machine and call your bank right away.
At a restaurant or store, never let your card out of your sight: the terminal comes to you, not the other way around.
Turn on instant notifications in your app: you spot an unknown debit within seconds, not at the end of the month.
ℹ️
Card swallowed by the ATM
Don't walk away thinking you'll come back tomorrow. A card “swallowed” by an ATM can be retrieved by a fraudster who planted a trap in the slot (a “Lebanese loop”). Stay put, call the ATM's bank or your own, and block the card if in doubt. It costs nothing, and a replacement card arrives in a few days.
🎯 Quick question
What can a fraudster actually do with a contactless reader held near your pocket?
Chapter 4. Setting up your card: limits, virtual cards, and 3-D Secure.
The best protection is free and sits in your banking app's settings. A well-configured card automatically limits the damage from fraud. A low limit, contactless kept under control, and a virtual card for unfamiliar sites turn a potential loss of several thousand euros into an incident of a few dozen euros.
📉
Right-sized limits
Spending and withdrawal limits run on rolling 7- or 30-day windows and can be changed in real time in the app. Set them as close as possible to what you actually need, and raise them temporarily for a big purchase.
📳
Contactless your way
Most apps let you turn it off or lower its limit. If you never use it, turn it off. That removes one risk vector if your card is stolen.
🔒
Temporary lock
A temporary lock suspends the card without canceling it. Lock it with one tap as soon as you can't find it, instead of blocking it. If it turns up in the lining of your bag, just unlock it. Blocking, on the other hand, is permanent.
🌍
Geoblocking
Block payments outside Europe, or abroad, when you are not traveling. A compromised card then becomes useless from the other side of the world.
💳
Virtual cards
A temporary or single-use card number, linked to your account, for paying online without exposing your real card. Ideal for an unfamiliar site, a free trial, or a subscription.
🔔
Real-time notifications
Instant notification of every payment is your personal alarm system. An unknown debit spotted in 10 seconds is much easier to dispute than one found at the end of the month.
3-D Secure: the bodyguard for your online purchases
Since the second Payment Services Directive (PSD2), most online payments require strong customer authentication (SCA). The cardholder proves their identity with two factors out of three: something you know (a code), something you have (a registered phone), and something you are (biometrics). In practice, you approve the payment in your banking app or with biometrics at checkout, through a protocol called 3-D Secure (version 2). Here is what happens behind the scenes.
Some payments go through without any approval, because PSD2 provides for exemptions: amounts under €30 (within certain cumulative limits) and transactions the bank's analysis rates as low risk (Transaction Risk Analysis). Add merchants you have put on a trusted list and recurring subscriptions where only the first payment is authenticated. So a missing 3DS step is not abnormal, but a payment you authenticated yourself is much harder to dispute. Never approve blindly.
Mobile wallets: paying without ever showing your card
Apple Pay, Google Pay, and bank wallets rely on tokenization. Your real card number is never sent to the merchant; a device-specific token replaces it. Every payment requires your biometrics, and if a merchant suffers a data breach, your real card number stays hidden. On security alone, paying with your phone is now safer than handing over your physical card.
The companies behind your everyday secure paymentsVisaMastercardCACartes Bancaires (CB)Apple PayGoogle PayPayPal
🔑
The minimum kit for worry-free payments
1) Real-time notifications on, 2) limits as tight as possible, 3) a virtual card for any unfamiliar site or free trial, 4) a mobile wallet for in-store payments, 5) each 3DS request read before you approve it. Fifteen minutes of settings, years of peace of mind.
🎯 Quick question
Why do some online payments not trigger any 3-D Secure approval?
Chapter 5. Unknown debit or transfer fraud: the step-by-step procedure.
A debit you don't recognize appears on your account. Don't panic. European law and the French Monetary and Financial Code set out a detailed procedure that is highly protective of consumers, provided you act in the right order and on time. Before disputing, first rule out an obscure merchant descriptor: the company's legal name often differs from its brand name. A forgotten subscription or a purchase by a family member allowed to use the card also explains many unrecognized debits.
Minute 0
Lock or block the card
In the app (2 taps), by calling your bank, or through the interbank card-blocking line at 0 892 705 705 (24/7). If the card details have been compromised, block the card, because that stops any further use.
Day 0
Dispute it in writing with your bank
Using the online form, a secure message, or a letter, report the transaction as unauthorized, citing Articles L. 133-18 and L. 133-24 of the French Monetary and Financial Code. You have up to 13 months after the debit, but every day counts.
Business day 1
Refund from the bank
For a reported unauthorized transaction, the bank must refund immediately, and no later than the end of the first business day after the report, unless it has good reason to suspect fraud on your part, in which case it must notify the Banque de France.
Following days
Report it: Perceval or a police report
Card fraud that happens while you still have your card is reported online on Perceval (service-public.fr), the government's card fraud reporting service. An online scam is reported by filing a police report through THESEE, the online complaint platform. The receipt supports your case but is not a condition for the refund.
If refused
Escalation: ombudsman, then the ACPR
To challenge a refused refund, first send a written complaint to customer service, then refer the case, free of charge, to the banking ombudsman. The ACPR and the Banque de France oversee compliance with the rules. The bank must prove gross negligence, not the other way around.
Case
Who pays?
Basis
Fraud while you still have the card (stolen data, remote payment)
Full refund, nothing out of pocket
CMF Arts. L. 133-19 and L. 133-18
Card lost or stolen, PIN used, transactions before the block
You bear at most €50; the rest is refunded
CMF Art. L. 133-19
Transactions after the block
Full refund, €0 out of pocket
CMF Art. L. 133-19
Gross negligence proven by the bank (PIN written on the card, approval given knowingly...)
No refund
CMF Art. L. 133-19, case law
Transfer you authorized to a fraudster (fake bank details, fake advisor)
No automatic refund: out-of-court remedies (recall of funds) and legal action
Legally an authorized transaction
Your rights by situation (cards, EEA)
⚠️
The tricky case: transfer fraud
If you entered and approved the transfer (fake bank details from a contractor or notary, a fake advisor directing a transfer to a “safe account”), the transaction is legally authorized. The refund is not automatic. Your bank can attempt a recall of funds (SEPA recall), with no guarantee. Since October 9, 2025, Verification of Payee (VoP, EU Regulation 2024/886) has required euro area banks to check that the name entered matches the IBAN before any transfer. Take these mismatch warnings very seriously, and verify any new bank details by calling the payee on their usual number.
For cards, once you have been refunded, your bank goes after the merchant's bank through the chargeback process of the Visa, Mastercard, or Cartes Bancaires (CB) networks, CB being France's domestic card scheme. The loss is passed down the chain, usually to the merchant that accepted the fraudulent payment. You don't have to wait for the outcome of this interbank battle to get your money back.
Template dispute letter for your bank (secure message or certified mail with return receipt)
Subject: Dispute of unauthorized transaction(s) -
refund request (Art. L. 133-18 CMF)
Dear Sir or Madam,
I have found the following transaction(s) on my account
No. [...], which I neither initiated nor authorized:
- [date] - [description] - [amount] EUR
Under Articles L. 133-18 and L. 133-24 of the French
Monetary and Financial Code, I request an immediate refund
of these amounts, no later than the end of the first
business day following this report, and that my account
be restored to its prior state (including resulting fees
and overdraft interest).
I blocked my card on [date] at [time]
(reference: [...]).
Sincerely,
[Last name, first name, address, date, signature]
✅
What the bank cannot hold against you
Not “you approved it with 3DS, so the money is gone”: the Cour de cassation requires proof of gross negligence, assessed case by case. Not “file a police report first”: a police report is not a legal condition for the refund. And no processing fee for handling your dispute of an unauthorized transaction.
🎯 Quick question
What is the maximum time you have to dispute an unauthorized card transaction (within the EEA)?
Chapter 6. Protecting your family: parents, teens, and yourself.
Fraudsters target first the people who are less comfortable with digital tools or more deferential to authority: our parents and grandparents for the fake bank advisor scam, our teenagers for classified-ad and gaming scams. Protecting your family means combining tools (the right settings on the right products) with a family script rehearsed in advance. Under stress, people don't think; they recite.
👵
For an elderly parent
A card with systematic authorization (every payment checks the balance, so no overdraft is possible), low limits, notifications copied to a relative's phone if the bank allows it, and a formal power of attorney rather than sharing the PIN, which counts as gross negligence.
🧑🎓
For a teenager
A youth bank account or a reloadable prepaid card: a weekly limit, gambling sites blocked, visibility for parents. Add some simple lessons. Never “lend” your account (the risk of becoming a money mule, which is a criminal offense), and never buy outside secure platforms.
👨👩👧
For the whole family
Agree on a secret family code word. Any urgent request for money by message (“Mom, I broke my phone, here's my new number”) must be confirmed with that word or by calling back on the usual number. The family emergency scam falls apart against this simple ritual.
🛡️
For yourself
A password manager, two-factor authentication everywhere, an email address used only for online shopping, a phone kept up to date. This basic digital hygiene closes 90% of the ways in.
🔑
The three-step rule to stick on your fridge
Hang up. Breathe. Call back. When any call or message mentions money, the bank, or an emergency, hang up without explaining yourself. Take a minute to breathe and let the pressure subside, then call the official number yourself (bank, relative, government office). No genuine banking emergency is decided in a minute.
33700: forward scam texts and report fraudulent calls (free).
Info Escroqueries: 0 805 805 817 (the national police's toll-free fraud line, Monday to Friday).
cybermalveillance.gouv.fr: diagnosis and help after a hack or phishing attack.
Perceval (service-public.fr): report card fraud online when you still have your card.
THESEE: file an online police report for internet scams (fake sellers, blackmail, fake tech support).
One last piece of advice: talk openly about fraud with the people around you. Shame is the scammers' best ally, because many victims say nothing and miss out on remedies that actually work. Telling your family about an attempted fraud inoculates everyone, and the next time the “advisor” calls, someone will recognize the script by the second sentence.
🎯 Quick question
What is the main benefit of a “family code word” agreed on in advance?