Fake government or bank site
The coat of arms can be copied. The domain cannot: an extra letter, .net instead of .gob.es, caixabanc.com without the K.
Google ads, SMS and mail clone AEAT, Social Security, DGT, SEPE, Cl@ve, CaixaBank, Santander, BBVA, Correos. They want Cl@ve, the bank SMS or a โsmall feeโ to unlock a file.
Real tax office does not collect in Bizum or crypto. Police do not open a case from a PDF. The bank does not ask for a signing code via SMS.
You type the address or open the app you installed months ago. AEAT = sede.agenciatributaria.gob.es. See Official sites.
How the scam is built
Hurry + fake authority + a channel you do not control (link, PDF, AnyDesk, reverse Bizum, new IBAN). Check on the channel you already trust: the app you installed, the number on the card, a .gob.es address you type yourself.
What to do
- Do not tap the link in the message. Type the site or open the installed app.
- Never read out an SMS code. Never paste a 12-word seed in a chat.
- 017 INCIBE. Report at denuncias.policia.es or a police station.
- hola@safe.madrid โ no passwords, no ID photo.
safe.madrid summarises INCIBE, Police, CNMV and AEMPS alerts. It is not those agencies.