The Ministry of Justice, Administration, and Digital Transformation has warned Croatian citizens about fake messages spreading through electronic communication channels. Their goal may be to trick the recipient into opening a suspicious link, downloading an attachment, or providing personal and financial information.
Before reacting in any way, citizens are advised to carefully check the sender, the content of the message, and the web address it tries to direct them to. Particular suspicion should be raised by messages that create a sense of urgency, threaten penalties, account blocks, or loss of rights.
How to Recognize a Fraudulent Message
Scammers often try to induce fear so that the recipient reacts without further verification. Unusual phrasing, spelling errors, unknown phone numbers, and links whose address does not match the institution's official domain can also be suspicious.
Those sending fraudulent notifications often mimic the look of official websites, use the names of well-known institutions, and add state symbols. This form of identity theft can be used to take over user accounts or gain unauthorized access to money. Therefore, a convincing appearance does not mean the message was actually sent by the body whose name it bears.
Do Not Open Links or Send Data
If fake messages arrive, you should not respond to them or follow the instructions provided. It is not recommended to enter usernames, passwords, bank card numbers, personal identification numbers, or other sensitive data. Government institutions and banks will not suddenly ask for passwords, security codes, or full card details via a regular text message.
The best way to verify the authenticity of a notification is to go directly to the institution's official website. You should type the address into your browser yourself, rather than opening a link from the received message. Citizens can also contact the institution via publicly listed phone numbers or email addresses, rather than using the details from the suspicious notification.
What to Do If You Have Already Opened a Link
If you have opened a suspicious page but have not entered any data, close it immediately and do not download any offered files. It is recommended to check your device with updated security software and remove any downloaded content. If you use the same password across multiple platforms, it is essential to change it on all related profiles.
If the fake messages led to entering bank details or approving a financial transaction, contact your bank immediately. The bank can block your card, restrict account access, or apply other security measures. Report any unknown transactions and keep screenshots, sender numbers, and the link as potential evidence.
Reporting Can Help Stop the Spread of Fraud
The Ministry urges citizens to remain vigilant and not to forward suspicious content to others without warning. It is advisable to report fake messages to the relevant institutions or to the organization whose name is being misused. Timely reporting can help remove fraudulent websites and prevent the same attack from affecting more people.
The key is to avoid making decisions under pressure. Taking a few minutes to verify the sender, domain, and official contacts can prevent financial losses and data theft. Institutions also advise regularly updating devices, using unique passwords, and enabling two-factor authentication where possible.