On 30 May 2019, at the end of the day, the phone of a BNP Paribas customer displayed a call from his bank advisor — her name, her number. On the line, a voice introduced herself as the advisor’s assistant: the account was under cyberattack, the registered transfer beneficiaries had had to be deleted, they now needed to be re-registered, right away. The customer complied, with his own codes, in his own app. “On 31 May 2019, Mr [J] found that several fraudulent transfers had been made for an amount of 54,500 euros,” the Cour de cassation, France’s highest civil court, would write five years later (our translation).
The fourth and final installment of season 1 of our “Anatomy of an attack” series, after France Travail, the ANTS and Brest University Hospital, this case file has one distinguishing feature: it dissects not an incident but a modus operandi — the “faux conseiller bancaire” (fake bank advisor) scam, which has become the dominant form of vishing in France. And it rests on two exhibits few frauds can offer: a Cour de cassation ruling published in the bulletin, which narrates the scam sentence by sentence and settles the sore question — who pays? — and the trial of an entire network before the Paris criminal court in 2026. Around these two exhibits: the figures of the Observatory for the Security of Payment Means (OSMP) at the Banque de France, and the findings of Cybermalveillance.gouv.fr, the French national victim-assistance scheme.
One framing point, and an essential one: this fraud “hacks” nothing. No malware, no vulnerability. The fraudster gets things done for him — he obtains from his victim that she validate the operations herself, with her own security devices. That is precisely what makes it so effective, and so contested in court.
Key takeaways
- The playbook: an alert SMS (smishing), then a call displaying the bank’s real number (spoofing), an “attack in progress” storyline, and a victim who validates the operations herself — or hands her card to a courier. This sequence is not a researcher’s reconstruction: it is established by the Cour de cassation ruling of 23 October 2024 and by the case tried in Paris in 2026.
- The law: “No gross negligence within the meaning of article L. 133-19 of the monetary and financial code can be imputed to an account holder who, contacted by telephone by a person posing as an employee of his bank whose number was displayed, uses at that person’s request the personalized security device” to delete and re-register beneficiaries (Cass. com., 23 October 2024, no. 23-16.267, published in the bulletin, our translation). The bank, which refused to reimburse €54,500, lost.
- The scale: €382 million of fraud by manipulation in 2024, i.e. 32% of the total amount of payment fraud, after “two years of very significant progression between 2021 and 2023” (OSMP, 2024 report). And “fake bank advisor fraud continues its strong progression (+159%)” in 2025 (Cybermalveillance.gouv.fr, 26 March 2026).
- The criminal case: eleven defendants tried in Paris in March 2026 over a network that took close to €740,000 from about a hundred victims — 148 offenses in one year. According to press reports, the judgment of 6 May 2026 imposed up to six years’ imprisonment; it remains open to appeal.
- Upstream: the call is only credible because the victim’s data leaked beforehand. The OSMP cites “the multiplicity of data-leak cases involving consumer-facing companies, allowing malicious actors to target their victims and lend credibility to their attack scenarios”. This fraud is the commercial downstream of the mega-breaches this series has dissected.
- The lesson: the same manipulation — borrowed legitimacy, urgency, a victim who executes — targets corporate finance teams under other names: CEO fraud, fake supplier, fake IT support. The defense is behavioral before it is technical.
The case in numbers
€382M
of fraud by manipulation in 2024 — 32% of all payment fraud in France
OSMP (Banque de France), 2024 annual report, 09/09/2025
+159%
growth in fake bank advisor fraud in 2025, despite prevention campaigns
Cybermalveillance.gouv.fr, 2025 activity report, 26/03/2026
€54,500
in transfers validated by the victim himself in the case ruled on in cassation — no gross negligence
Cass. com., 23/10/2024, appeal no. 23-16.267
≈ €740,000
taken from about a hundred victims by the network tried in Paris — 148 offenses in one year
AFP, 26/03/2026; judgment reported by the press, 06/05/2026
Timeline
Timeline
How events unfolded
31 May 2019
€54,500 gone: the case that will make caselaw
"On 31 May 2019, Mr [J] found that several fraudulent transfers had been made for an amount of 54,500 euros from his account held on the books of BNP Paribas" (our translation). The previous day, a call displaying his advisor's number had convinced him to "delete and then re-register transfer beneficiaries" to thwart a supposed cyberattack.
Source — Cass. com., 23/10/2024, no. 23-16.267
2021-2023
Fraud by manipulation explodes
"After a clear progression between 2021 and 2023 (+47%)" (our translation), fraud by manipulation becomes the main growth driver of payment fraud: fraudsters bypass the strong authentication required by PSD2 by manipulating the customer "during a telephone conversation, often by impersonating the payment service provider".
Source — OSMP, 2024 annual report, 09/09/2025
April 2022 - April 2023
148 offenses for the fake-courier network
Over one year, investigators link 148 offenses committed across France: an alert SMS, a call from a fake anti-fraud department, a bank card slipped into an envelope "to destroy it", a courier dispatched to the victim's home. Damage: close to €740,000 from about a hundred victims, many of them elderly.
Source — AFP (via France 24), 26/03/2026
1 October 2024
The Naegelen law starts cutting off spoofed calls
The caller-ID authentication mechanism (MAN) takes effect: "Calls presenting landline numbers without being authenticated have been cut off since 1 October 2024" (our translation). The goal: stop fraudsters from displaying the bank's number.
Source — OSMP, 2024 annual report, 09/09/2025
23 October 2024
The Cour de cassation shields the spoofing victim
Ruling published in the bulletin: "No gross negligence within the meaning of article L. 133-19 of the monetary and financial code can be imputed to an account holder who, contacted by telephone by a person posing as an employee of his bank whose number was displayed, uses at that person's request the personalized security device to delete and then re-register transfer beneficiaries with the aim of avoiding malicious operations" (our translation). The bank must reimburse.
Source — Cass. com., 23/10/2024, no. 23-16.267, published in the bulletin
Late January 2025
The MAN extends to mobile numbers — but spoofing survives
"Calls presenting mobile numbers without being authenticated have been cut off since late January 2025" (our translation). The Observatory nevertheless reports "certain cases of spoofing, including on landline numbers, said to have materialized in 2025 after the deployment of the MAN".
Source — OSMP, 2024 annual report, 09/09/2025
9 September 2025
€382 million: the OSMP takes the measure
The Banque de France publishes the Observatory's 2024 report: "the share of fraud by manipulation stabilized in 2024 at 32% of the total amount of fraud, i.e. 382 million euros" (our translation). The fake bank advisor scam is its central figure.
Source — OSMP, 2024 annual report, 09/09/2025
26 March 2026
The trial opens in Paris — and the barometer spikes
Eleven defendants appear before the Paris criminal court over the 148-offense network. The same day, Cybermalveillance.gouv.fr publishes its 2025 review: "fake bank advisor fraud continues its strong progression (+159%)" and "phone number spoofing shows a 517% increase" (our translation).
Source — AFP (via France 24); Cybermalveillance.gouv.fr, 26/03/2026
6 May 2026
Up to six years in prison
According to press reports, the Paris criminal court sentences the alleged ringleader, tried in absentia, to six years' imprisonment and a €100,000 fine, with an arrest warrant issued; eight other members of the network are "found guilty of organized-gang fraud", with sentences of six months to four years. A first-instance judgment, open to appeal.
Source — Press (Actu Roubaix; Bladi.net citing BFMTV), 06/05/2026
Act 1: the ruling that narrates the fraud — Cour de cassation, 23 October 2024
The facts, as established by the courts
Vishing stories abound in the press; it is far rarer for a modus operandi to be fixed, word for word, by France’s highest judicial court. That is the case here. The ruling handed down on 23 October 2024 by the commercial chamber of the Cour de cassation (appeal no. 23-16.267, published in the bulletin) sums up the facts in two clinically precise sentences: “On 31 May 2019, Mr [J] found that several fraudulent transfers had been made for an amount of 54,500 euros from his account held on the books of BNP Paribas (the bank)” (our translation). And: “Mr [J] alerted the bank the same day, maintaining that he had been contacted by telephone by a person posing as an employee of the institution asking him to add, using his personal security credentials, five persons to the list of transfer beneficiaries.”
The detail of the script appears further into the ruling, through the findings taken over from the lower courts. The caller had introduced herself as the assistant of the customer’s bank advisor. She had explained that it had been necessary to “delete transfer beneficiaries to thwart a cyberattack” and that they now had to be re-registered. Staying on the line, the customer “had received on his mobile phone messages inviting him to validate additions of beneficiaries, which he had done by entering his confidential code” (our translation). Finally, he was told he would “no longer have access to [his] account” and would receive “by post a new account identifier and a new password” — the trick that buys the fraudsters several days of silence.
And above all, the centerpiece: “the calling number appearing on Mr [J]‘s mobile phone was displayed as being that of Ms [Y], his BNP advisor” (our translation). Spoofing — the impersonation of the calling number — is not an expert’s hypothesis here: it is a judicial finding. The victim “believed he was dealing with an employee of the bank”, and believed he was validating a protective operation “on his app, which the bank presented as a secure operation”.
”No gross negligence”: the decision
There remained the question that decides everything, for tens of thousands of victims: who bears the loss? The framework is set by the French monetary and financial code: unauthorized operations must be reimbursed by the bank — except for the carve-out of article L. 133-19, IV: “The payer bears all the losses caused by unauthorized payment operations if these losses result from fraudulent conduct on his part or if he has intentionally, or through gross negligence, failed to fulfil the obligations set out in articles L. 133-16 and L. 133-17” (our translation). Everything therefore turns on two words: the customer’s “gross negligence”.
The bank argued exactly that: “the payer who validates remotely, and without verifying it, an operation of which he is not the author commits gross negligence”, its appeal contended, listing the clues that should have alerted a “normally attentive user”. The Versailles court of appeal had ordered it to reimburse the €54,500; it sought to have that ruling quashed.
The commercial chamber rejected the appeal, in two steps. First, the burden of proof, recalled at the outset: “it is incumbent on the payment service provider to prove gross negligence on the part of its customer” (our translation). Then the heart of the reasoning, which gives this ruling its reach: “the modus operandi using ‘spoofing’ put Mr [J] at ease and lowered his vigilance, which was lower, faced with a telephone call supposedly coming from his bank to inform him of the hacking of his account, than that of a person receiving an email, who would have had more time to notice any anomalies revealing its fraudulent origin” (our translation). Conclusion: “the court of appeal was entitled to deduce that Mr [J]‘s gross negligence was not established.”
The headnote published in the bulletin turns it into a principle: “No gross negligence within the meaning of article L. 133-19 of the monetary and financial code can be imputed to an account holder who, contacted by telephone by a person posing as an employee of his bank whose number was displayed, uses at that person’s request the personalized security device to delete and then re-register transfer beneficiaries with the aim of avoiding malicious operations” (our translation).
Two honest readings of this decision. For spoofing victims, it is a shield: validating operations yourself under the influence of a call spoofing your bank’s number is not, in itself, gross negligence — reimbursement is owed. But it is not a blanket immunity: gross negligence still exists in the statute, courts have found it in other configurations — typically where victims responded to phishing emails riddled with obvious anomalies — and every case turns on its facts. The ruling says one precise thing: the sophistication of the trap is imputed to the trapper, not to the trapped.
Act 2: the fake-courier network — the Paris trial
The 2024 ruling showed the fraud from the victim’s side, one case at a time. The trial that opened on 26 March 2026 before the Paris criminal court showed it as an industry. Eleven defendants, suspected of belonging to a fake bank advisor network, stood trial over close to €740,000 taken from about a hundred victims: the investigation linked 148 offenses committed across France between April 2022 and April 2023 — around €2,600 per fraudulent operation (AFP, 26 March 2026).
The modus operandi described at the hearings is a variation on the same playbook, with one extra physical step. An SMS alerted the victim to a supposed fraudulent purchase and urged her to call back a number starting with 01. On the line, a fake anti-fraud agent persuaded her to place her bank card in an envelope “to destroy it” — then a courier came to collect it at her home, PIN obtained as well. Accounts were then emptied through ATM withdrawals and purchases of valuable goods. Investigators described “a pyramid organization of the network, headed by an instruction-giver known under the pseudonym ‘padrino’ (‘godfather’ in Italian), who most likely ran the operations from Morocco” (our translation), via Telegram, with distributed roles — call handlers, couriers, buyers, front men — and internet calling services displaying French landline numbers. Calls often targeted hours when branches were closed, preventing any check with the bank. “At first, I didn’t want to tell my family for fear of looking like an idiot,” a victim and civil party who had lost €4,100 told AFP (our translation).
The judgment came on 6 May 2026, according to press reports: the alleged ringleader, tried in absentia, was sentenced to six years’ imprisonment and a €100,000 fine, with an arrest warrant issued against him; eight other members of the network were “found guilty of organized-gang fraud” (escroquerie en bande organisée), with sentences ranging from six months to four years’ imprisonment, partly suspended. The available reports do not specify the outcome for the two remaining defendants. The usual caveat applies: this is a first-instance judgment, open to appeal; no public information about any appeals was available when this article was published.
One sentence heard at the trial deserves to be kept: “But who is going to pay?”, asked that retired civil party. The criminal answer — prison terms — does not answer the civil question — reimbursement. That is the whole point of Act 1: for victims who handed over their card or validated operations under manipulation, the fight continues at the bank counter, article L. 133-19 in hand.
The attack chain: the documented playbook
Attack chain
How the intrusion unfolded
Defensive reconstruction — every link you understand is a link you can break.
Upstream: stolen data that scripts the call
The fake advisor guesses nothing: he knows. Cybermalveillance.gouv.fr notes that he "often has a great deal of information" about his target — "identity, address, bank card details, even account number" (our translation) — sourced from phishing or data breaches. The OSMP points to "the multiplicity of data-leak cases involving consumer-facing companies, allowing malicious actors to target their victims and lend credibility to their attack scenarios".
The pretext: an alert SMS (smishing)
In the case tried in Paris, everything starts with an SMS flagging a supposed fraudulent purchase and urging the victim to call back a number starting with 01, presented as the bank's anti-fraud department (AFP, 26/03/2026). The OSMP documents the spoofing of SMS sender labels (OAdC), which makes the message look like the bank's.
The call "from the bank": the displayed number is spoofed
Spoofing consists in "deceiving the recipient about the origin of the calls received (for example, by displaying the number of the bank advisor, of the bank's switchboard or of its card-blocking service)" (OSMP, our translation). In the case ruled on in cassation, "the calling number appearing on Mr [J]'s mobile phone was displayed as being that of [his] advisor".
Manufactured urgency: an "attack in progress" to thwart
The script established by the ruling of 23 October 2024: the caller explains that it was necessary to "delete transfer beneficiaries to thwart a cyberattack" and that they must "now be re-registered" — immediately, over the phone. At the Paris trial, the press noted that calls often targeted hours when bank branches were closed, to prevent any verification.
The victim acts herself: strong authentication or card handover
This is the signature of the fraud, summed up by the OSMP: "having the fraudulent operations validated by the victims themselves", or taking over their strong-authentication tools. The victim types her code into her own "secure" app; or slips her card into an envelope "to destroy it", PIN included.
Collection: couriers, withdrawals, purchases — then laundering
In the network tried in Paris, a courier picked up the envelope at the victim's home, then accounts were emptied "via ATM withdrawals or the purchase of valuable goods" (AFP). The prosecution described "a pyramid organization", run via Telegram, with distributed roles — call handlers, couriers, buyers, front men — around €2,600 per fraudulent operation, 148 times in a year.
What strikes you, laying the cassation ruling and the Paris case side by side, is the stability of the playbook. The variations — transfers validated in the app on one side, a card handed to a courier on the other — dress up the same backbone: borrowed legitimacy (the displayed number, the banking vocabulary, the accurate personal data), manufactured urgency (the “attack in progress”, the suspicious purchase), and a transfer of the action onto the victim. The OSMP put it better than anyone: this fraud “consists either in having the fraudulent operations validated by the victims themselves, or in the fraudsters taking over the strong-authentication tools to carry out fraudulent operations directly” (our translation). The strong authentication imposed by PSD2 closed the door on fraudsters; so they set about having the door opened from the inside.
Upstream: why the call is so credible
A call that names you, knows your bank, your advisor, sometimes your recent operations or your IBAN, does not come out of nowhere. Cybermalveillance.gouv.fr says it plainly in its fact sheet on this fraud: the scammer “often has a great deal of information” about his target — “identity, address, bank card details, even account number” (our translation) — obtained through phishing, account hijacking or data breaches. And the OSMP explicitly ranks among the drivers of fraud by manipulation “the multiplicity of data-leak cases involving consumer-facing companies, allowing malicious actors to target their victims and lend credibility to their attack scenarios thanks to the personal information collected”.
This is where this deep dive joins the previous ones. The 43 million people affected by the France Travail breach — civil records, phone numbers, identifiers —, the user data exposed via the ANTS, the IBANs taken from telecom operators and health payment intermediaries: all of it is the raw material of the fake advisor. A data breach is not an abstract harm that fades with the press release; it has a commercial downstream, and that downstream calls you on the phone. When the fraudster recites your file, the line between “my bank” and “someone who bought my data” becomes inaudible — which is exactly what the ruling of 23 October 2024 records: the trap “put [the victim] at ease and lowered his vigilance”.
The scale: €382 million, and defenses on the rise
The reference measurement is the OSMP’s, the observatory backed by the Banque de France: “After two years of very significant progression between 2021 and 2023, the share of fraud by manipulation stabilized in 2024 at 32% of the total amount of fraud, i.e. 382 million euros” (our translation). The 2021-2023 progression: +47%. The Observatory’s definition covers precisely our subject: “cases where the fraudster manipulates the customer during a telephone conversation, often by impersonating the payment service provider (fake bank advisor or fake anti-fraud department fraud)”. And this statistic is a floor: by construction it excludes scams where the victim believes she is paying a legitimate third party — fake investments, fake shops — which thrive alongside.
The 2024 stabilization owes much to the defenses deployed. The Naegelen law imposed the caller-ID authentication mechanism (MAN): “Calls presenting landline numbers without being authenticated have been cut off since 1 October 2024” (our translation), mobile numbers since late January 2025. On the SMS side, the AF2M industry body manages lists of protected and banned sender IDs, fed “on the basis of the reports sent by individuals to 33700”, the national SMS-reporting number. On the banking side, the OSMP recommends protecting sensitive numbers (a “Do Not Originate” scheme) and studying a single anti-fraud number, on the model of the UK’s 159.
But the autopsy would be incomplete without the 2025-2026 finding: the species adapts faster than the predator retreats. On 26 March 2026 — the very day the Paris trial opened —, Cybermalveillance.gouv.fr published its 2025 review: “despite the communication efforts of the sector’s players, fake bank advisor fraud continues its strong progression (+159%)”, with developments such as “phishing via fake card-blocking numbers and the use of the WhatsApp messaging service” (our translation). And “phone number spoofing shows a 517% increase, despite the regulatory and technical mechanisms (the ‘Naegelen’ law) put in place to curb it”. The same review notes the rise of subcontracted “field” teams, “commissioned for example, in the case of a fake bank advisor scam, to collect payment cards at people’s homes through ‘fake couriers’” — the model tried in Paris, now a service offering. The OSMP itself reports spoofing cases “said to have materialized in 2025 after the deployment of the MAN”. Technical barriers displace the fraud; they do not extinguish it, because its raw material is not technical: it is trust.
What a business should take away
1. The fake advisor has a corporate cousin: he calls your accounting team
Replace “your account is under attack” with “these transfers must be regularized before noon”, and the fake advisor becomes CEO fraud or fake supplier fraud — same levers (borrowed authority, urgency, confidentiality), larger amounts. Finance and HR departments are targets with IBANs, and the data needed to make the call credible — org chart, the company’s bank, its suppliers — sits in the same breaches and on the same social networks. Treat vishing as a treasury risk, not as a consumer-affairs story.
2. The countermeasure is not recognizing the voice, but breaking the channel
The central teaching of the cassation ruling: the inbound channel proves nothing. The displayed number can lie; tomorrow, the voice itself will lie, cloned by AI. The only robust verification is the outbound callback: hang up, then call back yourself on a known, verified number — the one on the back of the card, in the contract, in the internal directory. In a company, this rule must be written, named and enforceable: our wire-transfer anti-fraud procedure guide (in French) details the validation and callback circuit that would have stopped every scenario described in this case file.
3. What your bank (or ours) will never ask
The rule fits in one sentence from Cybermalveillance.gouv.fr, worth displaying as is: “Never will an advisor from your bank ask you to give him your password, confirmation codes, or to carry out validation actions on your banking app because of supposed fraud in progress” (our translation). Nor to send your card by courier, nor to “move funds to a secure account”. Any request of that kind, however legitimate it appears, is an immediate stop signal — and “do not, under any circumstances, validate operations you did not initiate, even if the person claims it is to cancel them”.
4. You cannot patch a human — you train one
Fake advisor fraud crosses no firewall: it crosses a brain under pressure. And the reflex of hanging up in the face of a plausible emergency is not decreed in a policy document; it is acquired through repetition — exactly as phishing simulations build the reporting reflex against booby-trapped emails. Training teams on voice and written manipulation scenarios (fake bank, fake IT support, fake executive), measuring reporting rates, debriefing without blame: that is the human counterpart of the MAN and the 33700 blocklists. Find the incidents from this series and 100+ others in our database of cyberattacks in France.
Verdict
The autopsy of the fake bank advisor scam yields an unusual diagnosis: here is an attack entirely documented by the judicial institution — a bulletin-published ruling for the script and the law, a criminal trial for the industrial organization — and which nevertheless keeps growing, +159% in 2025, in the face of the technical defenses deployed to contain it. The reason lies in its nature: it exploits no vulnerability and no malware, but the hardest thing there is to patch — a person’s trust in their bank, fueled by personal data stolen elsewhere.
The first three installments of this series told the story of compromised information systems; this one tells the story of what becomes of the data that leaves them. Between the breach at France Travail and the retiree slipping her card into an envelope, there is a logistics chain — smishing, spoofing, call handlers, couriers — that the courts have dismantled piece by piece. The Cour de cassation set the civil rule: the sophistication of the trap is imputed to the trapper. The criminal court set the penal rule: up to six years in prison. There remains the defensive rule, which belongs to you alone: no inbound channel proves the identity of the person speaking. Hang up, call back. It is a three-second reflex — and it can be trained.
FAQ
What is the fake bank advisor scam? A phone scam in which the fraudster impersonates the bank — often displaying its real number (spoofing) — and manipulates the victim into validating fraudulent operations or handing over her card. The OSMP classifies it as fraud by manipulation: €382 million in 2024.
Can my bank refuse to reimburse me? Only if it proves your “gross negligence” (article L. 133-19, IV of the monetary and financial code) — and the burden of proof is on the bank. Since the ruling of 23 October 2024 (no. 23-16.267), being deceived by a call displaying your bank’s number is not gross negligence, even if you validated the operations yourself.
How do I recognize a fake advisor? By his requests: validating operations “in order to cancel them”, sharing codes or passwords, handing your card to a courier — “never will an advisor from your bank” ask for that (Cybermalveillance.gouv.fr). The displayed number proves nothing: hang up and call your bank back yourself.
What should I do immediately in case of fraud? Block the card at once (0 892 705 705 in France), alert the bank through an official channel, contest the operations in writing, keep the evidence (SMS, numbers, times), file a complaint (Perceval or Thésée), report the SMS to 33700.
Is spoofing still possible despite the Naegelen law? Yes, at the margins: the MAN cuts off unauthenticated calls (landline numbers since October 2024, mobiles since January 2025), but the OSMP was informed of spoofing cases in 2025 after its deployment, and Cybermalveillance.gouv.fr measures a 517% rise in number spoofing in 2025 — fraudsters are also migrating to WhatsApp and fake card-blocking numbers.
Are businesses affected? Yes: the same manipulation, applied to finance teams, is called CEO fraud or fake supplier fraud. The countermeasures are identical: systematic callback to a known number, dual validation of transfers, and regular team training.
Sources:
- Cour de cassation, commercial chamber, 23 October 2024, appeal no. 23-16.267, published in the bulletin (ECLI:FR:CCASS:2024:CO00586): legifrance.gouv.fr — courdecassation.fr — archived version (accessed 05/09/2026)
- French monetary and financial code, article L. 133-19: legifrance.gouv.fr — archived version (accessed 05/09/2026)
- Banque de France, Observatory for the Security of Payment Means (OSMP), 2024 annual report, presented on 9 September 2025: banque-france.fr — PDF — archived version (accessed 05/09/2026)
- Cybermalveillance.gouv.fr, 2025 activity report and threat overview, press release of 26 March 2026: PDF — archived version; fact sheet “Que faire en cas de fraude au faux conseiller bancaire ?”: cybermalveillance.gouv.fr — archived version (accessed 05/09/2026)
- AFP, “Faux conseillers bancaires : onze prévenus jugés pour un butin de 740.000 euros”, 26 March 2026, via France 24; see also MoneyVox and France 3 Île-de-France, 26 March 2026 (accessed 05/09/2026)
- Press reports of the judgment of 6 May 2026: Actu Roubaix — archived version; Bladi.net, citing BFMTV (accessed 05/09/2026)
Note: the facts of the case decided by the Cour de cassation are cited as established by the civil courts, which anonymize the parties ([J], [Y]); BNP Paribas is mentioned only in its capacity as a party to the proceedings, as in the ruling itself, which ordered it to bear the costs after rejecting its appeal. The convictions handed down in Paris on 6 May 2026, as reported by the press, stem from a first-instance judgment open to appeal; anyone whose case has not been finally adjudicated benefits from the presumption of innocence. Nothing in this article allows victims to be identified, and the modus operandi details cited come exclusively from court decisions, public reports and hearing coverage — reproduced for descriptive and defensive purposes. Quotes from French sources are our translations.
Exhibits
The case exhibits
Cour de cassation (commercial chamber)23 October 2024
Exhibit 01
“Mr [J] alerted the bank the same day, maintaining that he had been contacted by telephone by a person posing as an employee of the institution asking him to add, using his personal security credentials, five persons to the list of transfer beneficiaries. (our translation)”
Cour de cassation (commercial chamber)23 October 2024
Exhibit 02
“No gross negligence within the meaning of article L. 133-19 of the monetary and financial code can be imputed to an account holder who, contacted by telephone by a person posing as an employee of his bank whose number was displayed, uses at that person's request the personalized security device to delete and then re-register transfer beneficiaries with the aim of avoiding malicious operations. (our translation)”
Observatory for the Security of Payment Means (Banque de France)9 September 2025
Exhibit 03
“After two years of very significant progression between 2021 and 2023, the share of fraud by manipulation stabilized in 2024 at 32% of the total amount of fraud, i.e. 382 million euros. […] Essentially, these are cases where the fraudster manipulates the customer during a telephone conversation, often by impersonating the payment service provider (fake bank advisor or fake anti-fraud department fraud). (our translation)”
French monetary and financial codeVersion in force (from the transposition of PSD2, 2018)
Exhibit 04
“The payer bears all the losses caused by unauthorized payment operations if these losses result from fraudulent conduct on his part or if he has intentionally, or through gross negligence, failed to fulfil the obligations set out in articles L. 133-16 and L. 133-17. (our translation)”