Free transport, stolen data: the scammers travel first class
It is yet another Facebook scam, but one that works far too well. For several weeks now, hundreds of French people have been falling for a tempting promise: a free or heavily discounted pass for public transport. And the catch?

As the holidays approach, between fake Christmas deals and a Black Friday that now stretches into a full cyber-month, a well-honed scam is gaining ground on social media: the promise of a free, or nearly free, pass for public transport.
A gift from heaven? No. A well-oiled trap.
For several weeks now, hundreds of French people have been taken in by fake Facebook pages impersonating local transport operators: STGA in Angoulême, TAN in Nantes, RTM in Marseille, RATP in Paris, and so on.
How does the free transport pass scam work?
The scam is simple, but diabolically effective:
"Get your free pass for 2025, limited offer!"
"Head over to our platform to validate your entitlement!"
One click later, you land on a page that imitates an official site perfectly. The logo, the colors, the administrative tone, it is all there. And you are asked for:
- your name,
- your address,
- your phone number,
- and your bank card details, "to validate the offer".
And that is it, game over.
Your data is gone. Either resold to other cybercriminal groups, or used directly to charge you amounts ranging from 1 euro to several hundred, often delayed, to avoid triggering your bank's alerts.
The amount demanded is calibrated so as not to wake anyone up. In Corrèze, two pages called "Public transport in Brive-la-Gaillarde" promised twelve months of travel on the Libéo network for 2.35 euros. Nobody calls their bank over 2.35 euros. But to pay 2.35 euros, you have to enter a full card number, an expiry date and a security code. What is being sold is not the pass. It is your card.
Why it works (too) well
Because the scammers have figured out the weak point: local trust.
When an ad appears on Facebook with your operator's logo, administrative language and the promise of a discount, you let your guard down. Especially in a time of crisis, when every bit of saving counts. And especially when:
- the page is recent, but sponsored (and therefore perceived as "reliable");
- the comments under the post are themselves fake ("thanks STGA, just signed up!");
- and nobody takes the time to check whether the offer actually exists.
This is what I call, in my book Être en cybersécurité, the illusion of legitimacy through familiarity: the more an attack resembles something familiar, the more dangerous it is.
Many people tell themselves "but you can tell it is fake". Maybe. But you can mostly tell after the fact.
And that is exactly the problem. The emotion, the thrill of a good deal, short-circuits common sense. Yet in cybersecurity, what matters is not what you know, but what you do under pressure, in the moment.
I go into this at length in my book, with a simple rule: the more generous an offer looks, the more it deserves to be checked.

How many fake pages are really out there?
You think you are dealing with a local amateur who copied his transport operator's logo. It is an industry.
The Spanish fact-checking outlet Maldita.es, working with the European Fact-Checking Standards Network (EFCSN), counted 1,075 fraudulent Facebook pages spread across 60 countries between July 2024 and July 2025, all built on the same free transport script. The investigation started from an initial Spanish finding: 59 fake pages impersonating the networks of 47 Spanish cities and islands.
Two figures deserve a pause.
The first: France is the most targeted country in the world, ahead of Spain, the United Kingdom and Italy. Barcelona holds the record for a single city, with more than twenty different pages posing as its transport network.
The second: 590 of these pages pointed to domains hosted with the same Russian provider, JSC Selectel, and the investigation also documented links with Russia and Vietnam. This is not a series of independent scams that happen to look alike. It is a production line, with a template, a host and a distribution channel.
And it has not slowed down. In Colmar, a page promised six months of free transport. In Rouen and Évreux, the Astuce and Atoumod networks were copied. Kicéo, the Vannes network, had to warn its users on 8 June 2026. The Imagine Le Bus network in Épinal did so in July 2026. A year after the investigation, the line is still running.
Why do these pages stay online?
This is the question everyone asks and nobody answers: how does a page created last week, with no followers, impersonating a public transport operator, reach tens of thousands of people?
The answer: because it pays.
Maldita decided to test the official channel. On 9 and 10 June 2025, the team reported 58 fraudulent posts to Meta as illegal content, using the mechanisms provided by the European Digital Services Act (DSA). A week later, 93% were still online. Meta's first response was systematically to remove nothing; only after appeal did the platform acknowledge that at least 6.8% should be taken down. Five days after they were filed, 62% of the appeals had still not been decided.
This is not an isolated miss. On 21 May 2026, BEUC and 29 consumer associations from 27 countries filed a complaint against Meta, TikTok and Google with the European Commission and national authorities. Between December 2025 and March 2026, those associations had reported, in thirteen countries, close to 900 ads suspected of breaching European law. 27% were taken down. 52% of the reports were rejected or ignored. Meta dismissed close to 43% of the ads submitted to it.
Then comes the why. In November 2025, Reuters published internal Meta documents: the group expected its fraudulent ads and banned products to bring in around 16 billion dollars of revenue in 2024, close to 10% of its turnover. A document dated December 2024 puts at 15 billion the number of "high risk" ads displayed every day across its platforms. And the internal threshold for banning an advertiser is set at 95% certainty of fraud: below that, the suspected advertiser is not excluded, it is charged higher advertising rates. Meta disputes these conclusions and calls them a selective view of its efforts.
Top floor: in April 2026, Maldita documented 170 blue-badge Facebook accounts that ran more than 67,000 fraudulent ads in Europe in the first quarter. The badge is sold by the platform, and it serves as collateral for the scam.
In other words, the user who gets trapped was not careless. They saw a paid ad, pushed by an algorithm, on a page carrying a purchased badge, still online despite the reports. They did not break through a security wall. The door was opened for them.
How can you protect yourself from the transport pass scam?
Here are a few simple tips, drawn straight from Être en cybersécurité, to avoid falling for this kind of scam:
1. Never take a Facebook link at face value. Type the site's URL yourself or go through a search engine. RATP, STGA and TAN do not need paid ads to give you gifts. If an offer is real, it is displayed prominently on their official site.
2. No operator will ever ask for your bank card for a "free" pass. That is an immediate red flag. If you have to validate an entitlement, it will be through a secure portal, often with your user ID, not with your card.
3. Check the official pages. A real RATP or STGA page has thousands of followers, years of history, sometimes a verified blue badge, and above all, no mistakes in the graphics. Another simple and effective reflex: an official page carries the operator's name, not a generic label such as "Public transport pass for your city". Fraudulent profiles, for their part, often top out at a few dozen followers.
4. Use a virtual card or a secondary account for online purchases. Even if you fall into a trap, you limit the damage. It is one of the pillars of a smart defense strategy. I detail this method in Être en cybersécurité, in the chapter "Online financial hygiene".
5. Report the fake pages. To Facebook. To the transport operator. To consumer associations. Every report counts, even when the platform drags its feet: it is also what feeds the complaints filed in Brussels.
A problem wider than it looks
This scam is not an isolated case. It is part of a heavy trend: localized phishing, which rests on the impersonation of institutional identities. We have already seen the same mechanism with:
- fake CAF emails;
- fake CPAM or Pôle Emploi campaigns;
- bogus préfecture "fines".
By playing on the authority of a public service, cybercriminals switch off your natural defenses. This is no longer a dodgy email from a Nigerian prince. It is a well-presented message, in your language, with the name of your city.
The figures follow. In its 2025 activity report, published in March 2026, Cybermalveillance.gouv.fr records more than 500,000 victims assisted, up 20% in a year. Phishing ranks first among the threats, accounting for a third of all assistance requests across every audience. Among private individuals alone, it represents about 33% of requests, up 71%, far ahead of account hacking (11%) and data breaches (6.6%, but up 107%).
And the money moves exactly where you would expect. In the first half of 2025, according to the Banque de France's Observatory for the Security of Payment Means, payment fraud reached 618 million euros, up 7%, while bank card fraud fell to 211 million euros, down almost 10%, with a fraud rate at an all-time low (0.048%, against 0.053% a year earlier).
Look closely at those two curves. The card is better protected than it used to be, and overall fraud rises anyway. Technology has stopped being the weak link. The weak link is the person who enters their own details, of their own free will, on a page they believe is official.
Knowing is not enough, you have to act
Digital security is not a diploma. It is a discipline.
And faced with these increasingly targeted attacks, it is the least vigilant users who become the point of entry. Do not be that weak link.
Take the time to train yourself, to equip yourself, to understand.
That is exactly why I wrote Être en cybersécurité: to give you simple reflexes, concrete scenarios, and the tools to stop being at the mercy of the next trap.
The book is available online, in all good bookshops and on etrecyber.fr.
In this holiday season, the best gift you can give yourself is perhaps that of vigilance.
And of clear-sightedness.
Sources
- International network of fake transport pages, 1,075 pages across 60 countries between July 2024 and July 2025, links with Russia and Vietnam: Maldita.es, 16 July 2025.
- Investigation coordinated by the European Fact-Checking Standards Network: EFCSN, 31 July 2025.
- Initial finding in Spain, 59 pages across 47 cities: Maldita.es, 12 June 2025.
- Reports filed with Meta under the DSA and share of posts left online: Maldita.es, 19 June 2025.
- Complaint by BEUC and 29 consumer associations against Meta, TikTok and Google, 21 May 2026: BEUC.
- Internal Meta documents on revenue from fraudulent ads, Reuters investigation of November 2025: Marketing Brew and eMarketer.
- Blue badge and fraudulent ads in Europe in the first quarter of 2026: Maldita.es, 8 April 2026.
- 2025 activity report and threat landscape: Cybermalveillance.gouv.fr, 26 March 2026.
- Top 10 cyber threats targeting private individuals in 2025: Cybermalveillance.gouv.fr.
- Phishing in 2025, the leading threat across all audiences: Cybermalveillance.gouv.fr.
- Payment fraud statistics for the first half of 2025: Observatory for the Security of Payment Means, Banque de France.
- Alert on fake free public transport passes: UFC-Que Choisir.
- French cases: Kicéo in Vannes, 8 June 2026, Imagine Le Bus in Épinal, July 2026, Libéo in Brive, Astuce in Rouen and Atoumod in Évreux, Trace in Colmar, STGA in Angoulême.
- Phishing quick-reference sheet: Cybermalveillance.gouv.fr.
Frequently asked questions
How do you spot this fake transport pass offer?
It spreads through Facebook pages that are recent but sponsored, imitating the logo and tone of a local operator, and redirects to a page asking for your personal and bank details. Two simple clues: an official page carries the operator's name (RATP, RTM, TAN) and not a generic label such as "Public transport in your city", and it has thousands of followers where fraudulent profiles often show a few dozen. A genuine offer would be posted on the official website, without paid advertising.
Can a transport operator ask for my bank card for a free pass?
No. No operator asks for a bank card for a pass presented as free. Any request for card details in this context is an immediate red flag. Be wary of micro-payments too: in Brive, fake pages promised twelve months of travel on the Libéo network for 2.35 euros. What is being sold is not the journey, it is your card number.
What is the risk of entering your information on these pages?
Your data can be resold to other cybercriminal groups or used to make charges, often delayed and ranging from 1 euro to several hundred euros, to avoid triggering your bank's alerts.
How many fake transport pages are really out there?
The Spanish fact-checking outlet Maldita.es, together with the European Fact-Checking Standards Network (EFCSN), counted 1,075 fraudulent Facebook pages across 60 countries between July 2024 and July 2025. France comes first among the targeted countries, ahead of Spain, the United Kingdom and Italy. The wave has not receded: Kicéo in Vannes warned its users on 8 June 2026, and the Imagine Le Bus network in Épinal did so in July 2026.
Why does Facebook not take these pages down?
Because reporting works badly. Maldita reported 58 fraudulent posts to Meta under the European Digital Services Act in June 2025: a week later, 93% were still online. In May 2026, BEUC and 29 consumer associations filed a complaint after reporting close to 900 suspect ads, of which only 27% were removed.
How do you protect yourself from this kind of scam?
Type the official URL yourself or go through a search engine, never use your real card on these pages (prefer a virtual card or a secondary account), check how old and how authentic the pages are, and report the fake ones to Facebook, to the operator and to consumer associations.
Why do we talk about localized phishing?
Because the attack relies on impersonating institutional identities the victim knows (local transport operator, CAF, CPAM, préfecture). By playing on the authority of a public service and on familiarity, it switches off your natural defenses. Phishing remains the leading threat handled by Cybermalveillance.gouv.fr, accounting for a third of all assistance requests across every audience in 2025.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
