A new wave of fraudulent SMS messages is spreading across Czechia: scammers are impersonating the public health insurance company VZP, demanding that recipients urgently pay off a supposedly outstanding debt. The messages direct victims to a fake website, vzp-govcz-e-vzp.casa, instead of the real VZP address, vzp.cz, the insurer's security department warns.
The wording of the fake message sounds convincing enough: "Good day, you have an unpaid contribution on record. Please settle it as soon as possible." On a small smartphone screen, the fraudulent web address is easy to overlook, and the fake page itself is so well made that even experienced internet users could fall for it.
The SMS itself poses no danger — the real threat lies in the link it contains. The fake VZP website asks victims to log in using their Bank ID and only then supposedly reveals the "debt" details. In reality, all the scammers want is access to the victim's bank account.
Once they gain that access, criminals can drain the account completely or even take out a loan in the victim's name at their own bank. VZP's head of security, Jan Svoboda, stressed: "VZP never sends SMS messages of this kind demanding immediate payment via a link."
The insurer advises against clicking on links in suspicious messages and warns never to enter personal or banking details on such sites under any circumstances. A suspicious message can simply be ignored, and its sender blocked.
VZP clients can check whether they actually owe anything through the official "Moje VZP" mobile app or by visiting an insurance branch in person. If personal data has already been entered on the fake website, it is essential to contact your bank and the police immediately.
Experts note that although the current attack is being carried out under the VZP name, scammers may well start using the names of other Czech organizations in the future — from banks to state institutions.
This scheme is known as smishing — SMS-based fraud, the mobile equivalent of email phishing. Experts advise against giving in to time pressure or clicking links in messages, and recommend always checking the exact web address in the browser and accessing your insurance account only through the official app or website. Bank ID should only be used on verified platforms — being asked to log in via Bank ID after clicking a link from an SMS should immediately raise a red flag.
Read also: Savings accounts in Czechia: bank rates for 2026
Source: novinky.cz