"Your test results are available": the scam texts exploiting your health records in 2026

Back to the blog
29 September 202612 min read

"I was waiting on a blood test done that morning. At 5 p.m., a text told me my results were online and that I needed to identify myself to view them. I typed in my social security number, my date of birth, and my bank card number because the page mentioned 'non-reimbursable processing fees'. It was only when I re-read it that I noticed the odd web address."

This account, gathered during a conversation with a patients' association, sums up rather well why health-themed scam texts work so effectively. It isn't a message that comes out of nowhere: it's a message you're expecting. You really did have a blood test, you really do have a hospital appointment, you really do have an insurer who reimburses you. The fraudster doesn't create the expectation — they slip into it.

And unlike the fake parcel delivery text, this one isn't just after your bank card. It's also after your administrative identity: social security number, date of birth, doctor's name, sometimes even health information. That's fuel for long-term fraud, far more profitable than a €39 debit.

Hand holding a lit smartphone in the dark, showing a text message conversation and the keyboard

Why healthcare has become prime smishing territory

Context does 80% of the work

A fraudulent text rarely succeeds because of how it's written. It succeeds because it lands at the right moment. And when it comes to health, the opportunities are numerous and regular:

  • a lab test whose results genuinely do arrive by notification within 24 to 48 hours;
  • an appointment reminder from a hospital or specialist, now standard practice in most facilities;
  • a reimbursement from your health insurer or a supplementary cover statement;
  • an update to your carte Vitale, a subject technical enough that nobody knows exactly what's normal;
  • the opening or activation of Mon espace santé, which many users can't quite remember doing.

What these five situations have in common: people don't know the official channel by heart. They don't know whether their lab sends a text with a link or just a code. They don't know whether the French health insurance system communicates by text message. That grey area is the fraudster's workspace.

Health data sells for more

Let's be clear: a stolen bank card number has a short shelf life. A stop order, a replacement card, and the matter is closed within ten days. Your social security number, by contrast, never changes. Combined with your name, date of birth and address, it allows someone:

  • to open administrative applications in your name;
  • to make a future scam text entirely convincing, since it will quote accurate details;
  • to feed targeted campaigns aimed at vulnerable or elderly people.

The CNIL classifies health data as sensitive data under the GDPR, with an enhanced protection regime precisely because its misuse is so hard to reverse.

The five most common scenarios in 2026

1. The fake test results

The message announces that your results are available and invites you to click to "authenticate yourself". The page mimics a laboratory portal, sometimes with a genuine logo lifted from the internet. It asks for your name, date of birth and social security number — then, at the pivotal moment, a payment of a few euros in "platform fees".

No medical analysis laboratory in France charges you by bank card, via a text message, to view your own results.

How it actually works: most labs send an access code or a link to a portal where you already created an account when your sample was taken, and where you're typically asked for an identifier handed to you on site plus your date of birth. Never any bank details.

2. The fake summons or appointment reminder

A more insidious variant: "Your appointment on 3 October at 2:20 p.m. has been cancelled, reschedule here." The urgency is emotional rather than financial. The link leads to a form that harvests your full identity, sometimes your bank card as a "no-show deposit" — a system that genuinely exists on certain appointment booking platforms, which makes the argument plausible.

The right reflex: never reschedule from the link. Call the reception desk back on the number shown on your paper appointment letter or on the facility's website.

3. The fake insurance reimbursement

"A reimbursement of €148.32 is pending, please provide your IBAN." The amount is deliberately precise, down to the cents, because a round figure arouses suspicion. This scenario already targeted recipients of family benefits and pension funds; it has since spread to supplementary health insurers, whose names are numerous and poorly known to the general public.

A useful reminder: an insurer who owes you money already has your IBAN. Any request for bank details by text is, by definition, suspicious.

4. The carte Vitale "due for renewal"

This is probably the oldest and most persistent one. The text announces that your carte Vitale is expiring and offers an online order for a few euros. The French health insurance system regularly points out on Ameli that the carte Vitale has no expiry date requiring a paid renewal, and that its procedures go through your ameli account, never through a link received by text asking for a bank card.

5. The fake "Mon espace santé"

A relatively recent public scheme, Mon espace santé remains hazy for many users: some have activated it, others haven't, and most no longer remember. Fraudulent messages play on that: "Your health space will be closed within 48 hours unless activated." The right response is to go through the service's official address typed by hand into your browser, never through the link.

Young woman with curly hair reading a message on her smartphone by a window

The sorting table: genuine health message or smishing?

ClueLegitimate messageFraudulent message
Request for bank cardNever to view a result or a reimbursementVery frequent, for a "small amount"
Request for IBANNot by text messageYes, "to speed up the transfer"
LinkOften absent, or pointing to a domain known to belong to the facilityLong domain, with hyphens, unusual extension
Sender numberShort code, or the facility's nameMobile number starting 06/07, or spoofed sender name
Imposed deadlineNo ultimatum"Within 24 hours", "within 48 hours", "final reminder"
Social security numberNever requested in plain text in a form opened from a text messageRequested on the very first screen
SpellingCorrect, sober administrative phrasingOften correct these days too: no longer a reliable criterion

That last point deserves emphasis. The argument "it was badly written, you could tell" no longer holds. The 2026 campaigns are written in clean French, sometimes better than that of genuine messages from institutions. The decisive criterion remains the nature of the information being requested, never the quality of the language.

The display trap: when the sender's name is the right one

One phenomenon has defined the year: fraudulent messages that appear in the same conversation thread as genuine messages from an organisation, because the displayed sender name has been spoofed. Supplementary pension funds have experienced this on a large scale, and healthcare facilities are not spared.

The practical consequence: a conversation thread is no longer proof of authenticity. A fraudulent text can show up under your laboratory's name, right beneath a genuine message received the week before. It's unsettling, and it's the main change of recent months.

Two concrete safeguards:

  1. Never judge a text by its header. Judge it by what it asks for.
  2. Always go back to the channel you control: the official app, the website typed by hand, the number on the paper appointment letter.

On that last point, keeping your appointment letters and medical reports in a ring binder with clear plastic sleeves dedicated to the household's health is not at all old-fashioned: it's the only place holding phone numbers that nobody can spoof remotely.

What French health services actually do

What does exist

  • Appointment reminders by text, short, with no link or with a link to the platform where you booked the appointment.
  • Notifications that results are available, with an identifier handed to you in person at the laboratory.
  • Information messages from the health insurance system, notably during vaccination or screening campaigns — with no request for bank details.
  • Alerts from your ameli account pointing to the official website.

What does not exist

  • A fee to view your own results.
  • A request for an IBAN or card number by text message.
  • A threat to close your medical file within 24 hours.
  • A phone call immediately after the text to "verify your identity": that text-plus-call combination is a hallmark of organised fraud, regularly documented by the Banque de France in its work on manipulation-based scams.

I clicked: what to do next

The order matters more than the speed, but both help.

If you didn't enter anything

Simply opening a page is generally not enough to compromise an up-to-date phone. Close the tab, enter nothing, and delete the message after reporting it. Take the opportunity to check that your operating system is up to date: security updates patch precisely the flaws exploited by malicious pages.

If you entered bank details

  1. Block the card immediately with your bank, or via the interbank loss-and-theft service.
  2. Check transactions from the last seven days, including small amounts of €1 or €2 that serve as tests.
  3. Dispute in writing: in the event of an unauthorised payment, the French Monetary and Financial Code provides for reimbursement by the bank, unless it can demonstrate gross negligence.
  4. File a complaint or submit an online pre-complaint, and report the incident on the Cybermalveillance.gouv.fr platform.

If you entered your social security number

There is no way to "cancel" it, but some measures are useful:

  • monitor your ameli account and report any unfamiliar reimbursement;
  • be wary for several months of highly detailed messages: they'll build on what you gave away;
  • notify the organisation concerned, which keeps incident records.

In every case: report it

Forward the message to 33700, the unwanted-text reporting service set up by French operators, then reply to the confirmation text with the sender's number. Fraudulent links themselves can be reported on the Phishing Initiative platform.

Hands holding a smartphone showing a text message conversation on screen, in dim light

Reducing your exposure before the next campaign

Separate your channels

The principle is simple: the more widely your main number circulates, the more it receives. Using a secondary number for commercial forms, one-off sign-ups and comparison platforms lets you keep your main number for family, bank and doctor. A pay-as-you-go SIM card with no contract or a second eSIM line is more than enough for this.

Turn on the filters already built into your phone

Android and iOS both include filtering for unknown senders and detection of suspicious messages, strengthened in France in recent months. These tools aren't perfect, but they remove a good deal of the noise from view. On older phones that don't offer them, a desk phone stand may seem trivial — it is — but above all it helps older people read a message calmly, with a steady screen, before reacting.

Check known data breaches

Health data does leak, in France too: several incidents involving laboratories and third-party payment operators have been made public in recent years. Periodically checking whether your email address appears in a compromised database helps you understand why fraudulent messages know you so well. For households wanting to get organised about all this, a password manager and, more simply, a practical cybersecurity guide for individuals are often worth more than yet another app.

The case of vulnerable relatives

Health-themed scenarios primarily target people under medical care, and therefore often the elderly. Two measures have an immediate effect:

  • write down, on a piece of paper stuck to the fridge, the three numbers to call back when in doubt: the laboratory, the GP, the bank;
  • agree on a single rule: no bank details, ever, by text or by phone, even if the caller names the doctor.

For people who struggle to read small screens, an illuminated reading magnifier makes the link address visible before the click — which, in practice, stops more fraud than any amount of prevention messaging.

In summary

Health smishing doesn't rely on gullibility but on the legitimacy of the expectation. You really are waiting for a result, a reimbursement, an appointment. The fraudster simply steps into the space.

Three sentences to remember:

  • No French health service asks for a bank card or an IBAN by text message.
  • The sender's name and the quality of the language no longer prove anything.
  • Always go back to the channel you control: official app, website typed by hand, number printed on a paper document.

The rest — reporting to 33700, blocking the card, filing a complaint — is just mechanics. What protects you is the reflex of never letting a message dictate the order of operations.

Sources and useful resources: Ameli (Assurance Maladie), CNIL, Cybermalveillance.gouv.fr, Banque de France (observatory for the security of payment methods), the French operators' 33700 service.

#smishing#arnaque#Sécurité#données personnelles#fraude#Vie privée#Mobile#2026#Conseil Sécurité

Related articles

Envoyez votre SMS gratuitement

Service 100% gratuit et sans inscription. Envoyez vos SMS vers la France en quelques secondes.

Envoyer un SMS