We have collectively learned to be wary of the parcel stuck in customs. The message has become a running joke: "Your parcel could not be delivered, please pay the €1.99 fee." Even the least tech-savvy among us now spot it at a glance.
Fraudsters know this. So they have moved house.
Since 2024, and far more markedly in 2025 and 2026, an entire family of text-message scams has shifted onto much more effective ground: health. A fake reminder for a specialist appointment, a supposed carte Vitale update, test results "now available," a Mon espace santé notification, a follow-up from your health insurer. The register has changed, and so has the mechanism.
Because these messages no longer play on greed or on the fear of a fine. They play on something far deeper: the reflex to comply with the healthcare system. When you receive a message that appears to come from a medical laboratory, you don't ask yourself "is this a scam?" You ask yourself "what did I forget?"

Why health has become the ideal playing field
Three factors have converged.
The first is how commonplace legitimate medical texts have become. Since online booking became widespread, everyone genuinely receives reminder texts: from the dental practice, the radiology centre, the medical biology lab, the physiotherapist. These messages are short, terse, often sent from a short code or an unfamiliar alphanumeric sender, and frequently contain a link. In other words: the fraudulent message doesn't need to look like anything exceptional. It only needs to look like the norm.
The second is the rollout of Mon espace santé. Opened automatically for the vast majority of insured people, this digital health record remains poorly understood in practical terms. Plenty of people know they have an account without knowing exactly what it contains, who can upload a document to it, or what an official notification looks like. That fuzziness is precisely the space in which phishing thrives.
The third is the value of the data harvested. A health scam isn't only after a bank card number. It's after a social security number, a date of birth, sometimes a copy of a proof-of-entitlement certificate. These elements then feed far more profitable frauds: account openings, identity theft, credit applications, or resale on criminal marketplaces.
A compromised bank card can be blocked in ten minutes and replaced in a week. A social security number, on the other hand, stays with you for life.
The five most common scenarios in 2026
1. The carte Vitale "update"
This is the flagship scenario. The message announces that your carte Vitale is about to expire, must be renewed, or that your entitlements will be suspended unless you update it. A link leads to a page mimicking the Ameli interface, asking for your personal details, your social security number, bank details "for reimbursements," and then a bank card "for the €1 postage fee."
The takeaway is simple and definitive: the carte Vitale does not expire and renewing it is never chargeable. The Assurance Maladie states this explicitly on its website. Updating a card is done at a terminal in a pharmacy or at a service point, never via a link received by text.
2. Fake test results
"Your results are available, view them here." The message sometimes arrives a few days after a genuine blood test — pure coincidence, or simply a mass effect: when you send hundreds of thousands of texts, some inevitably land on people genuinely waiting for results.
Real laboratories generally send an identifier and direct you to a portal requiring a code provided on your printed report. They never ask for a bank card number, nor for any "processing fee."
3. The fake Mon espace santé notification
More sophisticated, it mimics the institutional tone: "A new document has been added to your medical record." The aim is to capture the account credentials, which give access to a complete medical history — ideal raw material for blackmail or later social engineering.
Worth remembering: access to Mon espace santé happens exclusively through the official app or the official website, with a temporary code sent when the account is created. No legitimate notification asks you to re-enter a password via a link in a text.
4. The fake specialist appointment
"Your appointment on 12/09 is confirmed. To cancel: [link]." This format is particularly insidious because it asks for nothing: it pushes you to click in order to cancel something you never booked. The impulse is corrective, not greedy. And it works.
5. The fake health insurer or top-up cover
A message announcing a pending reimbursement, an overpayment to reclaim, or an imminent cancellation of your policy. The name of a real insurer is often used. Here too, the promise of money owed — and not requested — disarms vigilance.
The three-question method
Faced with a text like this, there's no point memorising a list of fraudulent numbers: they change every hour. Better to apply a stable reading grid.
Question 1: is this message asking me to act urgently? Suspension of entitlements, expiry within 48 hours, final reminder. Urgency is the fraudster's main tool, because it short-circuits verification. No French health organisation suspends entitlements by text with a two-day deadline.
Question 2: is this message asking me for data the sender already has? Your health insurance fund knows your social security number. Your laboratory knows your name. A legitimate organisation doesn't ask you again for what it already holds on file. When a message demands your entire administrative identity, it isn't verifying: it's collecting.
Question 3: am I using the link provided, or my own route in? This is the most robust principle in all of everyday digital security. Never enter a service through the door someone holds open for you. Close the text, open the official app or type the address yourself. If the information is real, it will be there. If it isn't, the matter is settled.

What automatic filters can (and can't) do
By 2026, messaging apps have improved considerably. Google Messages now sorts some suspicious texts into a separate folder and displays warnings about dubious links; iOS has been filtering unknown senders into a distinct tab for several versions. These protections are good at detecting mass, repetitive campaigns sent from burnt numbers.
They are far less good at detecting three things:
- Short, targeted campaigns, sent to only a few thousand numbers, which don't have time to be reported before producing their effect.
- Messages without a link, which simply invite you to call a number back. The vector then becomes the voice, and the social engineering plays out live.
- Messages that slot into an existing thread, when a legitimate alphanumeric sender is spoofed and the fraudulent text appears in the same conversation as the genuine ones.
This last point deserves to be properly understood: a fraudulent text can appear in the message thread of a real organisation, because the displayed sender name is no guarantee of authenticity. The appearance of continuity is a technical illusion, not proof.
For people who receive a lot of solicitations and manage several lines, a dual-SIM phone at least allows compartmentalisation: one line reserved for administrative and banking matters, another shared more widely. It isn't protection against scams, but it makes anomalies far easier to read.
Reporting: the channels that actually exist in France
Reporting is not a symbolic gesture. It feeds databases used by operators to cut off sending numbers and shut down fraudulent domains.
| Channel | What it's for | How |
|---|---|---|
| 33700 | Official platform for reporting unwanted texts and calls, run by the telecoms industry | Forward the text to 33700, then send the sender's number when prompted |
| Signal Conso / Phishing Initiative | Reporting phishing sites for blocking | Copy the URL without visiting it |
| Cybermalveillance.gouv.fr | Diagnosis, advice and connection with service providers | Guided online journey |
| Assurance Maladie (Ameli) | Reporting misuse of its visual identity | Section dedicated to attempted fraud |
| Perceval | Reporting fraudulent use of a bank card | Online service on service-public.fr |
33700 remains the most useful everyday step: it's free, it takes thirty seconds, and it's what enables sending numbers to be taken out of service quickly.
I clicked. Now what?
Clicking a link is not, in itself, catastrophic. The danger begins when you enter data. So the response should be graduated.
If you entered nothing: close the page, delete the message, report it. The residual risk is low.
If you entered credentials: immediately change the password for the service concerned, as well as for any other account where the same password was reused. This is the moment to point out that a password manager makes this operation trivial rather than agonising — and above all lets you stop reusing a password from one service to another for good.
If you entered banking details: call your bank's card-blocking line without delay, then report the transaction on Perceval. The European payment services directive strictly frames reimbursement in cases of unauthorised transactions: the bank must refund you unless it can demonstrate gross negligence on your part, which requires a genuine demonstration from them, not a mere assertion.
If you disclosed your social security number and personal details: there is no undo button. Monitor your reimbursement statements on your Ameli account for several months, and notify your health insurance fund. Note the date and time of the incident: these details matter should you later file a complaint.
Getting into the habit of keeping a written record of these incidents — in a simple dedicated notebook kept near the desk or in an encrypted file — saves you from reconstructing the facts from memory six months later, when an organisation asks for specifics.

The special case of vulnerable relatives
Statistically, these scams target people under medical care more heavily: chronic patients, older people, pregnant women, families with young children. Not out of calculated cruelty, but through simple mechanics: they are the ones for whom a health-related text is plausible at any time.
Three simple measures, with no surveillance and no talking down to anyone:
- Set a single rule rather than a list of prohibitions. "We never fill in a form that arrived by text" is memorable. "Watch out for dodgy .fr links" is not.
- Set up an emergency number. A designated contact you call before doing anything, without judgement. The shame of "having been taken in" is the number one cause of silence, and therefore of things getting worse.
- Reduce the exposure surface. On a phone intended for simple use, a large-button senior phone with no web browser simply removes the clickable-link vector altogether. This isn't a step backwards: it's a deliberate reduction of the attack surface.
To help a relative learn without dramatising things, an accessible guide to cybersecurity often works better than a family lecture, because it moves the authority outside the relationship.
Key takeaways
Health scams by text are neither more technically sophisticated nor harder to spot than their predecessors. They are simply better calibrated psychologically. They don't ask you to believe in an improbable windfall: they ask you to believe in ordinary administration.
The defence fits in a single sentence, which applies to the carte Vitale just as it does to your bank, your health insurer or your child's school: no real piece of information depends on the link someone sends you. It already exists somewhere, in a space you can reach by your own means. Taking the thirty seconds to verify by that route is enough to defeat almost all of these campaigns.
And when doubt lingers, the cheapest reflex remains forwarding to 33700 before doing anything else. A thirty-second report rarely protects the person sending it — but it often protects the thousands of people about to receive the same message within the hour.
Sources and official resources: Assurance Maladie (ameli.fr), Cybermalveillance.gouv.fr, service-public.fr (Perceval), the 33700 platform, Mon espace santé (monespacesante.fr).



