started · updated
Cybercrime targeting CPF accounts and e-commerce shoppers
Cybercriminals are employing increasingly sophisticated phishing and smishing tactics to target individuals in France. Two prominent methods have been identified: fraudulent claims regarding the ‘Mon Compte Formation’ (CPF) and fake delivery notifications for international e-commerce orders.
In CPF-related scams, fraudsters use urgent calls, SMS, or emails to claim that training rights are about to expire or offering illegal cash reimbursements. These tactics aim to trick users into signing up for fake training or revealing login credentials. Authorities note that training rights do not expire on a fixed date, and any claim of imminent expiration is a primary indicator of fraud.
Separately, smishing attacks are targeting buyers of platforms like Shein and Temu. Scammers send text messages claiming a package is held up by customs and requesting a nominal fee, typically between 1.50 and 3 euros, to release the shipment. These messages often use psychological pressure, threatening to return the package to the sender within 24 to 48 hours to force quick, unthinking decisions. According to Cybermalveillance.gouv.fr, phishing accounts for nearly 33% of all assistance requests in France.
Entities
Cybermalveillance.gouv.fr · Mon Compte Formation · Shein · Temu