# Fake health insurance and Vitale card texts: the health scam that thrives at the start of the school year

> Every autumn, a wave of text messages supposedly sent by France's Assurance Maladie or your top-up health insurer demands that you "update" your Vitale card. Here's how the scam works and the practical habits that keep you safe.

- Source: https://www.envoyer-sms-gratuit.com/en/blog/2026-09-01/arnaques-sms-mutuelle-carte-vitale-tiers-payant
- Published: 2026-09-01 (1 September 2026)
- Author: L'équipe Envoyer SMS Gratuit
- Language: en
- Categories: Guide
- Tags: Cybersécurité, SMS, Protection des données, Seniors, Smartphone, France 2026, Guide

---
Early September. The kids are back at school, the company's supplementary health insurance switched providers on the 1st of the month, and you have three prescriptions to renew before the end of the week. Your phone buzzes: "Assurance Maladie: your Vitale card is about to expire. Order your new card before 15/09 to avoid suspension of your reimbursements: [link]".

You have no reason to find that odd. You know something is changing in your health cover, you just don't know exactly what. That grey area is precisely what the fraudsters exploit.

The fake health text message scam is nothing new, but it has a formidable seasonality: it spikes in September and January, the two moments when people in France genuinely do receive letters from their health insurer, their employer or their local health fund. The fake message doesn't slip into silence — it slips into the noise.

![Person in a yellow jumper holding a smartphone with a blank white screen, sitting next to a cat on an armchair](/images/blog/2026-09-01-arnaques-sms-mutuelle-carte-vitale-tiers-payant/hero.jpg)

## Why healthcare is an ideal hunting ground

Most smishing campaigns rest on three pillars: an organisation everyone knows, a modest sum of money, and an unpleasant consequence if you do nothing. The health sector ticks all three with embarrassing ease.

**Everyone is concerned.** Unlike a fake bank text — which misses its target nine times out of ten because you aren't a customer of the bank in question — a message mentioning the Assurance Maladie reaches 100% of recipients. The fraudsters don't even need to know anything about you.

**The administrative vocabulary is opaque.** Vitale card, direct billing, electronic claim transmission, compulsory company health cover, flat-rate contribution, long-term illness status… Few people genuinely understand these mechanisms. Faced with a message that uses the right words, the natural reflex isn't doubt but deference.

**The consequence is scary without being dramatic.** "Your reimbursements will be suspended" is not a bailiff's threat. It's just annoying enough that you want to sort it out right away, and not serious enough that you'd call your partner or your accountant before clicking.

Add to this the fact that the Assurance Maladie, via Ameli, does send real text messages — for screening appointments, vaccination reminders or to flag that a document is available. So users have no simple rule such as "Ameli never sends texts". The line is blurred, and blur always favours the attacker.

## The four scenarios you'll come across this year

### 1. The "new Vitale card" to order

This has been the dominant scenario since the rollout of the digital Vitale card in the dedicated app was announced. The message claims your physical card is expiring, or that you must "migrate" to the digital version, and offers you a form.

What the form asks for, in order: surname, first name, date of birth, social security number, postal address, then — three screens in, once you're already invested — a payment of "processing fees" of between €1.50 and €4.90. The sum is trivial, and that's the whole point: it exists purely to capture your bank card number, its expiry date and its security code.

> Remember: the Vitale card has **no expiry date** and issuing one is **entirely free**. Any request for payment linked to a Vitale card is, by definition, a scam.

### 2. The fake health insurance refund

"Your supplementary health cover: a reimbursement of €47.82 is pending. Enter your bank details to receive it." The amount with two decimal places is a remarkably effective piece of staging: it gives the impression of a real calculation, drawn from an actual statement.

Here the fraudster isn't asking for money — they're promising it. That inversion switches off a good chunk of your vigilance. The bank details collected are then used either for fraudulent direct debits, or to build identity-theft files, or simply to be resold.

### 3. The "direct billing update"

A more technical variant, often sent at the start of the school year when group contracts change. The text invites you to "reactivate electronic claim transmission between your insurer and your health fund". The destination site mimics a member portal and asks for your health insurer login credentials.

These credentials have a particular value: a member portal contains your care history, your dependants, your bank details, sometimes your employer's information. It's a complete identity file, far richer than a single bank card number.

### 4. The fake screening or fake appointment notice

Rarer but on the rise: a text announcing an organised screening programme (bowel cancer, breast cancer) with a link to "confirm your participation". It exploits the fact that Santé publique France and the Assurance Maladie really do run campaigns of this kind. The aim is identical: harvesting personal health data, to be resold or used for later, more targeted scams.

![Hand holding a black smartphone with a blank green screen against a light grey background](/images/blog/2026-09-01-arnaques-sms-mutuelle-carte-vitale-tiers-payant/body-1.jpg)

## How to spot the fake in ten seconds

There are a few reliable markers, provided you know where to look. The first reflex is never to read the text: it's to look at **where the link leads**.

| What you see | What it means |
|---|---|
| A shortened link (bit.ly, tinyurl, cutt.ly) | A public body never uses a URL shortener |
| A domain like `ameli-remboursement.info` | The real domain is `ameli.fr`, full stop |
| `.ameli.fr.securite-xyz.com` | The real domain name is what comes before the last dot: here, `securite-xyz.com` |
| A sender using a standard mobile number | Official bodies use a sender name or a short code |
| A request for payment, even of €1 | No administrative health procedure is paid for by text message |

The third row of the table is the most important and the least well known. Fraudsters build addresses that contain the genuine organisation's name to fool the eye. The mechanical rule: **read the domain name from right to left**, starting at the `.fr` or `.com`. Whatever sits just before it is the site's true owner.

On a small screen, that reading is a chore — and it's meant to be. Many people who receive administrative messages every day end up reading this correspondence on a [large-screen tablet](https://www.amazon.co.uk/s?k=tablette+grand+%C3%A9cran+seniors&tag=ds0608-21), where the full address stays legible without squinting — a trivial detail that prevents a good share of careless mistakes.

## The specific trap for older people and their carers

Older people combine three vulnerability factors on this particular topic: they genuinely are heavy users of the health system, they really do receive a lot of letters from their health fund and insurer, and they were brought up to answer official bodies.

The problem isn't naivety. A retiree who receives three reimbursement statements a month has no structural reason to consider a fourth message suspicious. They're applying a legitimate routine to an illegitimate message.

A few practical adjustments for an elderly relative:

- **Set one single, absolute rule**: "we never click on a link received by text, ever, whoever the sender is". A rule with no exceptions is infinitely more effective than a list of criteria to weigh up.
- **Install the official Vitale card app or the Ameli app** together, from the app store, and explain that everything now goes through it.
- **Write their health fund's phone number on something physical**, next to the phone. A [large-print notebook](https://www.amazon.co.uk/s?k=carnet+notes+grands+caract%C3%A8res&tag=ds0608-21) kept beside the handset solves half of these situations: instead of clicking, the person calls.
- **Check that the hardware is readable.** Many misreadings come from a screen that's too dim or text that's too small. A pair of magnifying reading glasses next to the phone is sometimes more useful than antivirus software.
- **Agree on a systematic "second opinion"**: any message about money or health triggers a call to the carer before any action is taken. No blame, no judgement — just a shared reflex.

The goal isn't to turn a relative into a cybersecurity expert. It's to reduce the number of decisions they have to make alone, under pressure, on a six-inch screen.

## What this data is really worth

People massively underestimate the value of a social security number. Unlike a password, it can't be changed. Unlike a bank card, it can't be cancelled. It follows you for life and encodes your sex, your year and month of birth, and the department where you were born.

Combined with your name, address and date of birth, it makes it possible:

- to open accounts with organisations that verify identity poorly;
- to lend credibility to a later attack — a fraudster who calls you back quoting your social security number instantly becomes "official" in your eyes;
- to fuel far more targeted fraud campaigns, where the message no longer says "dear customer" but gives your name, your town and your health fund.

That's the blind spot for many victims: they feel they've "lost nothing" because no payment was taken. In reality, they've handed over the raw material for the next scam — the one that will arrive in three or six months and which, this time, will be perfectly convincing.

![Man holding a smartphone horizontally with both hands, blank white screen, against a light grey background](/images/blog/2026-09-01-arnaques-sms-mutuelle-carte-vitale-tiers-payant/body-2.jpg)

## The right channels, once and for all

The best defence against a fake message isn't spotting it more easily: it's knowing the real route by heart, so you never have to assess a text message again.

**For anything to do with the Assurance Maladie**, there's a single entry point: the `ameli.fr` website or the Ameli app, opened from your bookmarks or from your phone's app store. Never from a link you've received. Calling 36 46 gets you an adviser if you have any doubt.

**For your supplementary health insurance**, the phone number is printed on your direct-billing card, the one [in your wallet](https://www.amazon.co.uk/s?k=portefeuille+porte-cartes&tag=ds0608-21). It's the only source of information nobody can tamper with remotely.

**For the Vitale card**, remember three facts that are enough to rule out 100% of scams of this type:

1. It doesn't expire.
2. It's free.
3. It's ordered from your Ameli account or at a pharmacy, never via a link.

**To report a scam**, forward the text to **33700**, the official service run by French mobile operators in cooperation with the authorities. You'll get an automatic reply asking for the sender's number: send it on. Reporting is free and feeds into blocking lists. Cybermalveillance.gouv.fr also offers a guided support process if you've already handed over information.

## If you've already filled in the form

Don't panic, but be methodical, in this order.

**If you gave your bank details**: call your bank immediately to block the card, or use the card-freeze function in your banking app — that's often faster than a phone call. Then watch for micro-debits of a few cents, often tests carried out before a larger operation.

**If you gave your health insurer or Ameli login details**: change the password from the official site, and change it everywhere you reused it. If you have no idea where that might be, now is the moment to adopt a [password manager](https://www.amazon.co.uk/s?k=cl%C3%A9+s%C3%A9curit%C3%A9+gestionnaire+mots+de+passe&tag=ds0608-21), or at the very least a password notebook kept in a drawer — an old-fashioned solution, but infinitely better than three identical passwords.

**If you only gave identity details**: there's nothing to "fix" technically, but bear it in mind over the following months. Treat as suspicious any call or message that quotes your details precisely and asks you to do something. A well-informed fraudster is not a legitimate contact.

**In every case**: file a complaint, online or at a police station. Even if your individual case goes nowhere, it feeds the statistics that trigger group investigations. And your bank will ask for it before refunding anything.

## The real reflex, the one that costs nothing

It fits in one sentence: **you never handle a health matter by text message**.

This isn't about vigilance or technical expertise. It's about the channel. A message received on your phone isn't a source of information, it's a notification — at best, a reminder to check elsewhere. Once that reflex is embedded, the quality of the fake message becomes irrelevant: whether it's crude or perfectly imitated, it ends up in the same place, forwarded to 33700 and then deleted.

The rest — the spelling mistakes, the logos, the odd turns of phrase — are useful clues, but they're clues the fraudsters fix every year. The channel, on the other hand, won't change.

{/* image-sources: https://images.pexels.com/photos/30105021/pexels-photo-30105021.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/9558936/pexels-photo-9558936.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 https://images.pexels.com/photos/8217435/pexels-photo-8217435.jpeg?auto=compress&cs=tinysrgb&dpr=2&h=650&w=940 */}
