Cookies Notice

This website uses cookies to help you have a better user experience. Cookies are not used to collect personal information. For more information, please see our cookies policy.

Rate this page
Rate this content

False notification notices impersonating the social security authorities

Recurring campaigns have been detected, which tend to occur during specific time periods (the most recent ones were detected in November–December 2024 and March–April 2025), in which the Social Security or one of its agencies (such as TGSS, INSS or ISM) is impersonated.

How is it done?

By sending emails that appear to be notifications prompting recipients to access their electronic notifications, but which turn out to be fake.

Who is it aimed at?

The recipients are usually individuals or legal entities holding RED authorisations. It is usually these authorisations that alert us to the detection of these fraudulent emails.

Why?

By clicking on the link, the perpetrators behind these campaigns could obtain information about passwords or online credentials and impersonate the recipients.

What do we recommend?

Being wary of these emails, which contain links to fake websites, purport to be from the Social Security administration and ask you to enter passwords or access codes.

How can you tell if they are fraudulent?

They often contain spelling mistakes, unfinished or poorly worded sentences, outdated or pixelated logos, very short and incorrect deadlines for taking action, and they urge people to act quickly and urgently.

Recommendations and resources

If in doubt, call the official Social Security telephone numbers to check whether the communication is genuine or not. Further information is also available on the website of the National Cybersecurity Institute (INCIBE).

Complementary Content
${loading}