itsme scam email, fake SMS, code or approval

If you receive an itsme scam email, phishing SMS, reactivation link, code request or unexpected approval, stop before confirming. The useful test is simple: did you personally start the login, signature, payment or account change now shown in itsme? If a caller, SMS or copied portal pushes you to approve it, refuse the action and verify through the official service opened by you.

Information updated : 2026-09-10

Editorially reviewed : 2026-09-02

Editorial Trust

Last update
2026-09-10
Sources checked
2026-09-17
Content status
page reviewed with visible sources
Official sources cited
5
Editorial responsibility
StopArnaques

StopArnaques is an independent Belgian service. It is not a public authority and does not speak on behalf of the organisations cited.

Report a correction

What you need to understand

  • How to recognise a fake itsme validation, an SMS asking you to reply YES, or an unofficial portal.

The scenario, step by step

  • The fraudster asks the victim to approve an itsme action they never started: a login, identification, signature, or an operation linked to a third-party service.
  • The pretext may be a reactivation, a new device, an eBox document, or a refund. The link then leads to a portal that imitates itsme or a public service.
  • A real itsme notification can also appear at the end of a scam started elsewhere. The fact that it is genuine does not make the displayed operation legitimate.

What the fraudster is trying to get

  • Approval of a login or operation started by the fraudster.
  • Identity and banking details entered on a fake portal.

Common variations

  • A supposedly expired or blocked account.
  • A request to reply YES or confirm a new device.
  • A fake adviser who stays on the line during the validation.

Warning signs in your case

  • Request to approve an action you did not start
  • SMS asking you to reply YES or share a code
  • Portal other than itsme.be

What a legitimate service would do

  • An itsme request must match an action you have just started yourself.
  • The app shows the service and the action to confirm: if they do not match, the request must be refused.

Belgian context and fraud chain

  • itsme is used as a digital identity with many Belgian services. A request visible in the app can therefore concern a bank, an administration, or another partner; you need to check the service and the action shown, not just recognise the app.
  • The most dangerous scenario does not always rely on a fake app. The fraudster may trigger a real itsme request after preparing a login or operation on another device.

Decision points to check

  • Ask yourself one simple question: did I start this action myself in the last few seconds? If the answer is no, refuse the request without trying to help the caller.
  • Read the name of the service and the type of operation in itsme. Identification, login, and signature are not interchangeable and should never be validated on a third party’s instruction alone.
  • Go back to the relevant service by opening its app or official domain. Do not try to fix a supposed account problem through the link you received.

How to check without taking a risk

  • Do not reply to the message and do not use the link, QR code, or number it contains.
  • Open the official app or website yourself, then check whether the same request appears in your personal space.
  • If in doubt, contact the organisation using a number found on its official website, a reliable invoice, or your bank card.

What to do immediately

  • Do not approve anything in the app if you did not start anything yourself.
  • Go back to the official itsme app.

If you already clicked, paid, or replied

  • Stop the exchange and do not try to negotiate with the sender.
  • Change the access details shared through the official service. Contact the bank immediately if a payment, card, IBAN, or validation is involved.
  • Keep the exchanges, payment references, and observed addresses for reporting, without publicly sharing personal data.

What to do after an incident

  • After an unwanted validation, immediately identify the service mentioned in the app and contact it through its official channel. The useful measure depends on what was actually approved.
  • Secure the email address and phone number linked to your accounts if their access details may have been shared. A password change must be done from the official domain, not from a tracking link.
  • If the operation involved a bank or a payment, warn the bank without waiting to see a loss appear. Keep the time and confirmation screens without publicly exposing personal data.

Limits and level of proof

  • An authentic itsme notification only proves the technical origin of the notification, not the legitimacy of the action that triggered it.
  • A public information page cannot determine remotely which account was affected; that information must be checked in the history of the relevant service.

Analysis grid for itsme fraud

  • To review an itsme fraud case, separate four questions: who is contacting you, through which channel, what action is being requested, and which independent element can confirm it. One reassuring answer does not cancel out the other inconsistencies.
  • The priority signals in this case are: request to approve an action you did not start; SMS asking you to reply yes or share a code; portal other than itsme.be. Their combination matters more than the isolated presence of a word, a logo, or a typo.
  • Always compare the message with the real status of the service. For itsme fraud, a request that is absent from the app, the account, or the official contact should remain unexecuted until confirmed.

When to ask for immediate help

  • In an itsme fraud case, contact the relevant service without delay if a code, validation, payment, card, identity document, or remote access has already been shared. Describe the exact action rather than only saying that you were hacked.
  • If no sensitive action was taken, keep the useful elements, block the contact, and use the detector to document the signals. This difference avoids confusing prevention, a confirmed incident, and a simple unsolicited message.

What to do now

  • If you have not acted, do not click further and open the named service's official channel yourself.
  • If you clicked, close the page, enter nothing else and note what information was shown or requested.
  • If you shared a code, card, password or payment, contact your bank or the relevant official service immediately.
  • Keep the message, time, link used and any useful screenshots. Share them only with an official reporting channel or a trusted helper.

Limits of this page

  • This page does not prove that a message is safe and does not replace your bank, the police, Safeonweb, a platform or a public service.
  • A scam may be new, very well written or described with too little context. Use the result as decision support, not as absolute certainty.
  • Before taking a final action, checking through the official channel matters more than the appearance of the received message.

Check through an official channel

  • Type the service address yourself or open the official app. Do not use a phone number, link or QR code from the suspicious message to verify the situation.
  • When money, card details, a code or account access are involved, the safety action comes first. The analysis can then help organise the evidence.

How to read the result

  • A low number of signals does not mean that everything is safe. It only means that this page or analysis did not find decisive evidence with the information available.
  • Focus on the requested action: paying, sharing a code, installing an app, approving a bank action or leaving an official platform. That action matters more than a logo, sender name or polished wording.
  • If the situation feels urgent, step away from the received message first. Then check calmly through a channel you already trusted before the message arrived.

Belgian reading of this situation

  • For the unexpected itsme approval, focus on the relevant Belgian next step: open the official channel yourself, contact the bank, use Safeonweb or preserve evidence.
  • The right decision for the unexpected itsme approval depends on what has already happened. Reading a message is not the same as clicking, paying, sharing a code or granting remote access.

itsme scam email, SMS and approval angle

  • This page targets itsme scam, itsme scam email, fake SMS, code request and unexpected approval. The deciding question is whether you personally started the login, signature or confirmation now shown in itsme.
  • Do not approve an action because a caller, SMS, email or copied portal tells you to. Open the official service yourself and refuse any request that does not match your own action.

Frequently asked questions

How can I check an itsme fraud request without clicking?

Do not approve anything in the app if you did not start anything yourself. Then compare the request with your official space and test the text or link in the StopArnaques detector.

Which signs should make me stop?

Stop the interaction if you see, among other things: a request to approve an action you did not start, an SMS asking you to reply yes or share a code, or a portal other than itsme.be. A familiar visual identity never makes up for an unusual request.

Does the detector replace official verification?

No. The detector helps you understand the risk and the observed signals. For a banking, administrative, or account-related operation, always confirm with the official service through an independent channel.

Useful official sources

Test another suspicious message

I already took action

I already took action

Prepare my next steps