Security researchers have detected an active Schengen visa scam designed to steal personal data and passport scans from international travelers. Kaspersky’s Global Research and Analysis Team identified phishing emails sent under the guise of European Union migration authorities. The campaign targets tourists speaking English, Arabic, Turkish, and several other languages ahead of planned trips to Europe.

Deceptive EU Portal Tactics

The deceptive messages claim that travelers must submit a digital migration declaration five working days before arrival. Scammers direct recipients to a fraudulent website that mimics the official Entry and Exit System of the European Union. Furthermore, the notifications falsely warn that missing the deadline could result in strict border inspections or temporary entry bans.

To build false trust, the fraudulent portal explicitly tells visitors that immigration officials never request payment information by email. The website replicates official European Union branding and provides multilingual interfaces in English, Turkish, Arabic, Chinese, and Spanish. As a result, victims are prompted to submit passport scans, travel dates, and companion details.

Mechanics of the Schengen Visa Scam

Fraudsters exploit urgency because travelers often invest weeks into paperwork and fear unexpected issues at border control checkpoints. In this Schengen visa scam, attackers gather comprehensive travel profiles to execute follow-up identity theft or financial fraud over phone calls. Experts note that the real Entry and Exit System began operating in April 2026 without requiring advance online declarations.

“Cybercriminals rely on creating a sense of urgency. They know travelers may have spent weeks preparing their visa applications and fear problems at the border. Travelers should remember that they do not currently need to register for the EES online in advance.”

Georgy Kucherin, Senior Security Researcher at Kaspersky GReAT

Recommended Security Precautions

Security teams advise travelers to inspect website URLs carefully for strange domains, typographical errors, or extraneous characters before submitting sensitive documents. Travelers should avoid opening unexpected attachments or clicking links sent through unsolicited travel correspondence. Direct verification with consulates remains the safest path to confirm entry requirements.

Additionally, experts recommend using digital connectivity tools like an eSIM obtained through verified apps while traveling abroad. Device owners should also install dedicated protection software to guard personal identities against evolving online fraud schemes.

Threat Assessment and Verification

Recognizing the operational patterns of a Schengen visa scam helps international tourists protect sensitive records from unauthorized access. The security firm continues monitoring fraudulent portals that imitate governmental systems across European borders.