In 2025, fraud driven by psychological manipulation in France surged by 34% to reach 516 million euros, accounting for over 40% of total payment method fraud. According to the Observatorium for the Security of Payment Methods (OSMP), affiliated with the Banque de France, young adults aged 20 to 24 recorded the highest victim rate at 9.6 per 1,000 inhabitants.
The Shift From Technical Hacking to Social Engineering
Security architectures are evolving, but threat actors are simply bypassing them. As banks pour capital into real-time pattern-recognition AI—such as Visa’s multi-billion dollar acquisition of BioCatch—fraudsters have pivoted hard toward social engineering. When an end user authorizes a transaction willingly from their own hardware, traditional machine learning models and anomaly-detection algorithms face a massive blind spot.
The numbers released by the OSMP on September 7, 2026, paint a stark picture. Total payment method fraud across all categories in France hit 1.24 billion euros in 2025. While the sheer volume of fraudulent transactions dropped by 8%, the monetary impact per successful strike intensified. Attackers are executing fewer attempts, but they hit harder when they do.
Anatomy of the Fake Bank Advisor Scam
The primary vector driving these figures is the “false bank advisor” scenario. Fraudsters spoof the phone numbers of legitimate financial institutions to create instant panic, pressuring victims into executing emergency “safe transfers.” According to the OSMP report, this specific tactic accounted for 376 million euros of the total losses.
This mechanics-first approach mirrors major cryptocurrency heists. The psychological playbook relies on artificial urgency and manufactured authority, short-circuiting rational thought regardless of the target asset class. The strategy targets mainstream bank customers just as effectively as digital wallet holders.
- Total Manipulation Fraud (2025): 516 million euros (+34% year-over-year).
- Market Share: Over 40% of all French payment method fraud (totaling 1.24 billion euros).
- Most Impacted Demographic: Young adults aged 20–24 (9.6 victims per 1,000 inhabitants).
- Fake Advisor Scam Subtotal: 376 million euros.
Demographic Shifts and the Digital-Native Paradox
Conventional cybersecurity wisdom assumes that older demographics bear the brunt of social engineering. However, data reported by franceinfo completely upends that stereotype. The 20-24 age cohort—individuals practically raised with smartphones—sustained the highest victim rates.
Tech-savviness offers zero immunity against well-crafted cognitive manipulation. The structural tactics mirror the infamous fake Coinbase advisor scams that drained 65 million dollars in just two months within the crypto ecosystem. The underlying technology changes, but human cognitive vulnerabilities remain static.
Enterprise-Grade Parallel: The Bybit Compromise
This vulnerability is not limited to retail banking customers. On February 21, 2025, cryptocurrency exchange Bybit suffered a massive cold-wallet exploit totaling 1.5 billion dollars in minutes. Investigators pointed to the Lazarus Group out of North Korea. Crucially, the smart contracts were secure, and hardware passwords remained uncompromised.

Instead, the vector hit a third-party developer at Safe{Wallet}, the multi-signature tool utilized by the exchange. Attackers injected malicious code directly into the interface. When authorized signers logged on to approve routine transfers, their hardware keys authenticated transactions that had been silently altered under the hood. The user interface lied to the human, proving that sophisticated manipulation scales all the way up to enterprise infrastructure handling billions.
The 30-Second Verdict for Digital Assets and Traditional Banking
Whether navigating traditional checking accounts or decentralized crypto wallets, the mitigation strategy remains strictly analog. Technical controls—ranging from end-to-end encryption to hardware keys—fail the moment interface presentation is compromised or the user is psychologically coerced. As the OSMP data demonstrates, no amount of NPU-driven fraud detection can entirely override the human element. The core rule of digital hygiene stands absolute: never confirm a transaction under the pressure of an uninitiated inbound call.