Tarragona
Barcelona
Tarragona
Barcelona
Add APD as a preferred Google source for free.
Stay informed with the latest current news.
The Cybersecurity Agency of Catalonia has warned of a campaign of fraudulent SMS messages impersonating the General Treasury of Social Security to steal personal and banking data. The messages warn of supposed pending payments and push victims to regularize their situation through a link that directs them to a website that imitates the official portal.
The hook of the fraud is that the message appears to resolve a transaction with Social Security when in reality it seeks to get the user to hand over sensitive information on a fake page. The Catalan agency warns that the domain used in these notices is not official and asks not to provide data or access the link received by SMS.
The main recommendation is not to act in haste.
The Cybersecurity Agency of Catalonia insists that this type of message uses urgency as a pressure mechanism to prevent the victim from checking if the communication is authentic. It also recalls that any transaction with Social Security must be done only through official channels.
In similar digital fraud campaigns, the deception begins with a notification that appears administrative and ends up leading to the capture of banking data, as happened with a false tax refund. The pattern is repeated by impersonating public bodies to give the message an appearance of legality.
The SMS messages inform of a debt or a pending payment and refer the user to a page that reproduces the image of the TGSS portal. This step is key in the scam because the victim believes they are in a legitimate environment when in reality they are handing over information to third parties.
In addition to the link by message, the fraud relies on the appearance of the site to which it redirects, a common technique in online identity theft. The Catalan agency emphasizes that the domain detected in this campaign does not belong to the General Treasury of Social Security.
The entity has disseminated a specific instruction for those who have already fallen for the scam.
“If you have entered data on a suspicious page, contact your bank immediately and change the passwords for the affected services” – Cybersecurity Agency of Catalonia
That notice places the priority on limiting as soon as possible the possible fraudulent use of stolen information. Changing passwords and immediate contact with the bank are the two measures that the agency expressly points out in the face of this attempted impersonation.
The Cybersecurity Agency of Catalonia asks to contact the banking entity immediately and change the affected passwords if the user has already entered data on the suspicious page.
Redactor
AI-assisted or AI-generated content and images
This article has been produced with the assistance of artificial intelligence tools and reviewed by the editorial team prior to publication. Some images may have been generated using AI or consist of recreations for illustrative purposes.
