Sellers Sign Away Payment After Clicking Payment Link Sent by Leboncoin Buyer

August 29, 2026

A SEPA direct debit mandate is a document that authorizes a company to automatically debit money from a bank account, either on a one-off basis or on a recurring schedule. It is this tool, normally reserved for legitimate subscriptions, that scammers today hijack to trap sellers on Leboncoin. The principle is as simple as it is formidable: instead of receiving payment for the item they’ve just sold, some internet users sign without realizing an authorization that allows a stranger to draw directly from their account, again and again. In this back-to-school season, a period when classifieds explode with clothes, school supplies and everyday items people want to unload, this type of fraud is seeing a worrying resurgence.

The trap that reverses the flow of money

On paper, the scene seems completely ordinary. A seller posts an ad, a buyer shows interest and, for speed, offers to send a secure payment link. The seller, eager to close the sale, clicks without suspicion. It is precisely at that moment that the mechanism reverses: instead of generating an incoming transaction, the link redirects to a form that discreetly obtains an authorization to debit. The seller believes they are getting paid, while in fact they have just opened the door to their bank account for a stranger.

This deception works because it taps into a very human reflex: trust placed in an interface that looks, almost indistinguishably, like a legitimate payment service. Scammers reproduce logos, colors and legal notices that instantly reassure. The seller notices nothing abnormal, fills in the requested fields, and moves on, convinced that money will land in their account within hours.

Direct Debit Mandate: the signature you never see coming

Direct debit fraud is nothing new: it has circulated since 2014, the year the euro-based direct debit standard was introduced across Europe. But it remains devastatingly effective, because fraudulent withdrawals are designed to slip under the radar. Unlike a sudden and large debit that would immediately alert the victim, these withdrawals are often regular, discreet and of small amounts. An innocuous label, a few euros here and there, and the game is done: most people involved do not check their bank statement line by line every month.

The classic scheme mirrors the codes of a completely legitimate registration. The victim receives an email mentioning a subscription or service confirmation, accompanied by the famous SEPA mandate to validate. In the minds of many users, signing a mandate resembles a trivial administrative formality. It is precisely this apparent banality that makes the trap so effective: no one imagines that a simple electronic signature could open the door to repeated debits for months.

Leboncoin never sends you to an external bank

This type of scam is not unique to a single platform. On Vinted, for instance, the mechanism is almost identical: scammers systematically try to lead the victim out of the official app, usually via a link received by email or SMS, with the sole aim of depriving them of any buyer or seller protection. The rule recalled by the most seasoned resellers is encapsulated in one sentence: as long as the money, messages and shipment stay within the app, the scam cannot succeed. Once you leave, you are no longer protected by anything.

The same principle applies to Leboncoin. No reputable peer-to-peer platform redirects its users to an external bank form to complete a payment. If a buyer insists on sending a link outside the official messaging system, that’s already a serious alarm signal to heed. Cybersecurity guides classify this type of fraud among the most common traps on second-hand platforms, which handle millions of users daily and thus represent countless potential targets for fake payment links.

The reflexes that block the scam before it debits

The first line of defense, and perhaps the simplest to implement, is to systematically check the URL before entering any banking information. A fraudulent site can be an almost perfect replica of the official site, but the address in the address bar never lies. An extra character, an unusual extension, or a slightly altered domain name should immediately set off the alarm.

If, despite this, banking data has already been entered on a fake site, don’t delay. The course of action is clear: contact your bank immediately to block the payment, monitor the withdrawals in the following weeks closely, change your password immediately, enable two-factor authentication wherever possible, and file a complaint. Taken promptly, these steps can considerably limit the financial damage.

Finally, vigilance also comes from understanding the mechanism itself. Knowing that a payment link can actually conceal a direct debit mandate changes the way you approach an online transaction. It is no longer just about whether the link is secure, but about understanding what it actually makes you sign.

Behind a simple click can lurk more than a trivial transaction: an authorization that turns a seller into a regular payer, without them realizing it for weeks. Staying within the secure confines of official platforms, checking every link received, and never yielding to the rush of a sale that seems too fast remain the best defenses against these increasingly sophisticated scams. The next time a buyer seems unusually eager to pay via an external link, the question to ask is no longer whether it’s a good deal, but who, at heart, will actually cash the money.

Sindre Halvorsen

I write about space exploration, frontier science and the technologies that are quietly shaping the future. From Norway, I follow the missions, discoveries and ideas that connect life on Earth with what lies beyond it. My goal is to make complex subjects clear, useful and worth paying attention to.