ZUS Issues Urgent Warning Over Sophisticated SMS Phishing Scam
Poland’s Social Insurance Institution (ZUS) has issued a critical alert regarding deceptive text messages claiming minor payment arrears, designed to trick citizens into clicking malicious links and...
Poland’s Social Insurance Institution (ZUS) has issued a critical alert regarding deceptive text messages claiming minor payment arrears, designed to trick citizens into clicking malicious links and compromising sensitive personal data.
Table Of Content
The mechanics of the new ZUS impersonation scam
The scam relies on a simple yet effective premise: a text message alleging a small, outstanding health insurance contribution. By using a low, seemingly plausible amount, criminals lower the recipient’s natural suspicion.
The message creates a false sense of urgency, warning of heavy financial penalties while providing a direct link for immediate payment. Clicking these links redirects users to fraudulent sites mimicking official ZUS or banking portals, where scammers attempt to harvest login credentials or credit card information.
A proactive approach to verifying suspicious messages
ZUS emphasizes that it never sends text messages containing links to external websites. This was recently highlighted by a resident of Zielona Góra, who successfully avoided being defrauded by choosing to verify the suspicious text directly at a local ZUS office instead of clicking the provided link.
This incident serves as a clear reminder that taking a few minutes to verify a notification with official channels is the most effective way to protect against financial loss and identity theft.
Tactics used by cybercriminals beyond text messages
Beyond SMS phishing, ZUS warns that criminals are increasingly employing fake investment schemes, unsolicited phone calls, and even unauthorized home visits. Regardless of the method, the goal remains the same: inducing panic and forcing the victim to act impulsively.
Essential steps to protect your data
If you receive a suspicious message, do not act under pressure or follow any instructions provided in the text. Experts recommend checking every financial notification twice and verifying the sender’s details.
You can report suspicious messages by forwarding them to the official number 8080, which helps security systems block fraudulent domains. Additional reports can be made via CERT Polska or the mObywatel application’s security module.


