Warning: active campaign
Our teams have observed, since late April 2026, a surge in fraudulent emails impersonating court registries, bailiffs, and RPVA platforms, specifically targeting French law firms and notarial practices.
The typical scenario:
- Email mimicking the official formatting of a court registry
- PDF attachment containing a malicious macro
- Or a link to a fake portal requesting RPVA credentials
Immediate recommendations:
- Raise awareness amongst your staff: no authentication is ever carried out via a link in an email
- Check the actual sender address (not just the display name)
- Enable MFA on all critical accounts if not already done
- Report and delete without clicking
If in doubt, our teams can provide a free rapid analysis. Contact us.
Warning signs to look out for
- senders impersonating a court registry, a colleague, the RPVA, or a regular supplier;
- fake case notifications or procedural alerts, with an attachment or link to "consult urgently";
- addresses that are close but incorrect (domain altered by one character), an urgent tone, an unusual request for a bank transfer or credentials.
The 5 key reflexes
- Check the sender: the actual address, not just the display name.
- Do not click if in doubt — type the official address yourself.
- Enable MFA on your email and sensitive tools.
- Report any suspicious message to your service provider and, if necessary, on signal-spam.fr.
- Inform the firm: a swift internal alert prevents a colleague from falling into the same trap.
If in doubt or in the event of an incident, contact us: we can help assess the threat and respond accordingly.