Giving Every Employee a Training Budget in a Few Clicks: The Government’s One-Stop Shop That Others Have Learned to Drain

August 28, 2026

Twenty-seven million euros. That is the estimated damage cited in criminal complaints filed by the Caisse des dépôts et consignations between March 2020 and May 2022, concerning fraud linked to the Personal Training Account. A figure disclosed by the government and extensively documented by Public Sénat, illustrating the scale of a phenomenon that largely flew under the radar while thousands of accounts were drained, often without the account holders realizing it.

The CPF mechanism, however, lived up to its initial promise: to simplify access to professional training, regardless of the employee’s status. Everyone accumulates rights in euros, which can be consulted and mobilized in a few clicks via the Mon Compte Formation app. A good idea, almost too simple. In the first half of 2022, the Caisse des dépôts received 32,400 reports related to this scheme. A volume that invites questions about the robustness of the system in the face of organized networks capable of sniffing out the flaw from the earliest months.

Key takeaways

  • How a system designed to simplify access to training became a windfall for scammers
  • From simple fraudulent SMS to organized networks with accomplices: the escalation of CPF-related crime
  • Why legislative safeguards are not enough against the rapid adaptation of fraudsters

An account gateway too easy to open, too hard to monitor

The most common scenario unfolds in three acts. A call, an SMS, or a message on social media promises the holder to “unlock” their training rights. Identity theft occurs and enrolments are made in training programs the consumer did not want, without their knowledge. The account drains to a fictitious organization, and the victim only realises weeks later, when they attempt to mobilize their rights themselves.

The phenomenon surged when the application was launched en masse. Reports of unwanted SMS messages linked to the CPF multiplied by 14 between the first half of 2021 and the first half of 2022. Fourteenfold in one year: this is what happens when a public gateway becomes suddenly accessible remotely, without anti-fraud barriers having had time to keep up with the pace.

The Caisse des dépôts, for its part, says it did not stay idle. Over the period in question, it increased the reports and delistings of dubious training organizations. But the balance of power remains lopsided: on one side, a system open to millions of beneficiaries; on the other, a handful of teams tasked with detecting fraud patterns that evolve relentlessly.

Structured networks, not mere opportunists

The case revealed in February 2025 by the General Directorate of Customs and Indirect Taxes scales up. In 2024, the Lyon JIRS public prosecutor’s office opened an information inquiry into alleged fraud connected with the CPF. This inquiry, conducted by the Office national anti-fraud, a service created on May 1, 2024 and attached to customs and the DGFIP, uncovered a system far more sophisticated than a simple SMS scam.

Training bodies recruited participants by offering, through various maneuvers, to unlock the funds of their CPF in exchange for computer hardware, mobile phones, or even cash — a system that led to a massive diversion of public funds managed by the Caisse des dépôts, with damages estimated at more than 15 million euros in a few years. The trainee himself became an accomplice, in exchange for a smartphone or a few notes, in a misappropriation of public funds whose criminal scope he did not always grasp.

The dismantling operation, carried out on January 28, 2025, required resources worthy of an organized-crime case. It mobilized more than 50 judicial customs officers from the ONAF, digital-forensics experts, and DREETS agents, with support from the Lyon RAID and the gendarmerie, including a canine unit trained to detect banknotes. Nine people were arrested, seven were charged with fraud, money laundering, and criminal association. The searches yielded nearly 1.27 million euros in assets, only a fraction of the total damage.

A judicial machine operating at full throttle

The sheer volume of CPF-related cases handled by the Caisse des dépôts speaks volumes about the scale of the phenomenon: the institution opened 1,132 judicial requisitions related to the CPF in 2024, up 40% from the previous year. This rise signals not so much a slackening of vigilance as a growing professionalization of fraud networks, able to renew their methods as soon as a safeguard is put in place.

The legislator has attempted to take back control. Law no. 2022-1587 of December 19, 2022, aimed at fighting CPF fraud, introduced a ban on all direct marketing of CPF holders by telephone, text message, email, or on an online social network service. On paper, abusive solicitation should have become a thing of the past. In practice, the Lyon case of 2025 shows that networks simply shifted to more direct methods, recruiting accomplices in person rather than luring them online.

For individuals, the Cybermalveillance.gouv.fr platform reminds a simple rule: no legitimate outreach concerns the CPF, and any such solicitation should be reported immediately. A detail worth knowing, because it changes the game for those still hesitating to act: CPF rights do not expire, contrary to the common belief exploited by fraudsters to create a false sense of urgency. Nothing obliges anyone to give in to the pressure of a message promising to “unlock” a stash that, in reality, will never expire.

Sindre Halvorsen

I write about space exploration, frontier science and the technologies that are quietly shaping the future. From Norway, I follow the missions, discoveries and ideas that connect life on Earth with what lies beyond it. My goal is to make complex subjects clear, useful and worth paying attention to.