Russia Faces a New Fraud Risk as the EES Scam Targets Travellers Who Must Now Protect Their Passport Data
Image generated with Ai
A reported EES Scam targets Russian travellers applying for Schengen visas through emails demanding passport scans and a fictitious migration declaration. An original cybersecurity bulletin published on 25 September 2026 describes messages impersonating a European migration authority and threatening border problems. The immediate concern is disclosure of personal information, rather than a newly imposed entry requirement. Official European guidance confirms that the claimed compulsory declaration five working days before arrival is not part of the published registration process.
What the Verified Evidence Establishes
The evidence supports a travel security story centred on reported impersonation and genuine border procedures. The following shares are an editorial assessment of this article’s emphasis, not official statistics, victim rates or measured tourism effects. They total 100% and reflect the strongest verified material available.
Advertisement
Advertisement
| News Component | Share of Story | Officially Verified Finding | Relevance to Travellers | Official Source |
|---|---|---|---|---|
| Border requirements | 40% | EES registration is free | Check demands against genuine requirements | UK government guidance |
| Passport security | 30% | Copied passport details can enable identity misuse | Protect document information | Northern Ireland government guidance |
| Digital preparation | 20% | Sweden permits voluntary app registration within 72 hours | Distinguish authorised preparation from impersonation | Swedish embassy guidance |
| Future authorisation | 10% | ETIAS launch remains scheduled for late 2026 | Await confirmed application instructions | Official European guidance |
These findings establish the applicable procedures and the need to verify document requests. The original campaign report is separate evidence, rather than a government investigation. Neither it nor the official sources reviewed establishes a decline in bookings, widespread disruption or a confirmed hotel database breach. Unavailable loss totals cannot establish that nobody suffered harm.
How the Reported EES Scam Targets Travellers
The bulletin describes fake multilingual websites copying EU branding and requesting personal details, companions’ information, arrival and departure dates, and passport scans. Emails claim recipients must submit a digital migration declaration five working days before arrival. They threaten extra checks or temporary refusal of entry and include reassuring security language. The EES Scam report provides no quantified financial losses or victim count. It also does not establish how recipients’ contact details were obtained.
Advertisement
Advertisement
This matters because visa applicants must already distinguish between legitimate administrative requests and fraudulent demands. Passport protection forms part of trip preparation, even when transport and accommodation remain unaffected. Official cybersecurity guidance identifies claimed authority, urgency and threatening consequences as common phishing techniques. Phishing means deceptive messages designed to obtain information or draw recipients towards fraudulent websites. A demand can seek personal information without requesting immediate payment. The absence of a payment screen therefore does not establish that a website is safe. Knowing a person’s name or travel plans does not prove that a sender represents a border authority. The report does not establish the campaign’s present scale or whether every identified website remains active.
Understanding the Context Behind the Development
Digital Border Checks Created a Changing Travel Context
EES began on 12 October 2025, followed by full implementation on 10 April 2026 across 29 European countries. It replaces passport stamps for eligible short-stay travellers with electronic crossing records. Biometric checks use physical identifiers, such as fingerprints and facial images, to help verify identity. On 27 July 2026, an official update recorded more than 145 million entries and exits since launch. These are cumulative border movements across participating countries, not unique visitors or fraud victims. The July total uses the system’s launch as its baseline; it cannot produce a campaign victim rate. The September bulletin came later; its publication date does not establish when the campaign began. When an EES Scam Targets Travellers through border terminology, that overlap provides context, not proof that the policy caused the fraud.
Advertisement
Advertisement
Sweden’s Voluntary App Requires a More Careful Warning
Swedish guidance confirms that the Travel to Europe app supports voluntary submission of passport details, a facial image and an entry questionnaire within 72 hours before entering or leaving Schengen. Therefore, advance digital preparation is not automatically fraudulent. The relevant questions concern the channel, published procedure and destination. Swedish police identify availability for arrivals at Arlanda, Bromma, Landvetter, Sturup and Skavsta. Travellers must still complete applicable border checks. Children under 12 do not provide fingerprints, although their personal details still require registration. Optional preparation may assist processing but does not guarantee admission or remove border officers’ checks. These official procedures explain why the reported mandatory five-day demand requires correction. They do not establish a definitive cause of the targeting or prove a breach of government systems.
What Travellers Should Do Next
Russian visa applicants receiving unexpected document requests should verify them before responding. The finding that an EES Scam Targets Travellers does not itself justify cancelling a journey. Existing passport, visa and destination restrictions remain applicable. EES generally covers eligible non-EU visitors staying for up to 90 days within any 180-day period. Crossing into another participating country does not restart the short-stay allowance, which applies across the area collectively. Nationality, residence documentation and exemptions affect registration. EU citizens and nationals of Iceland, Liechtenstein, Norway and Switzerland are exempt. Certain residence permits and long-stay visas also provide exemptions, depending on the issuing country and document. Check documentation supporting any exemption. A visa requirement remains separate from the digital border record, and travellers should check individual circumstances with the relevant consular or border authority.
- Verify independently: Use contact details published by the relevant authority, not those inside a suspicious message.
- Protect passports: Avoid uploading scans through unsolicited email links.
- Check the procedure: Confirm whether an official app supports your destination and crossing point.
- Allow processing time: Initial registration can extend border checks.
- Respond to exposure: Contact your bank after disclosing banking details and change any compromised passwords.
- Report the attempt: Follow the official phishing or fraud reporting process available in your country.
Official cybersecurity guidance supports these protective steps. If a suspicious message reaches a workplace device, inform the technical support team. The reviewed evidence supports verification and reporting rather than blanket changes to bookings. Travellers should monitor official requirements while continuing to meet the conditions applicable to their own journey.
EES Scam Targets Travellers as Europe Prepares Further Digital Checks
The next announced development is ETIAS, a separate authorisation system for eligible visa-exempt visitors. Official guidance checked on 5 October 2026 schedules operations for the final quarter of 2026, with the exact launch date awaiting announcement. Applications are not currently being collected. Unlike EES, which records border crossings, ETIAS will involve advance authorisation. Travellers requiring a Schengen visa should not mistake that future process for a replacement visa route.
For the travel industry, the evidence supports a communication priority rather than a measurable demand shock. Businesses can explain which published procedure applies to each traveller without forwarding unverified demands. This is analysis, not a newly announced commercial obligation. The reported targeting concerns Russian applicants; the underlying border rules cover a wider international audience. Nationalities have different entry conditions, so that wider relevance does not establish equivalent exposure to this campaign elsewhere.
Verified Rules Remain the Basis for Safe Travel
The reported EES Scam highlights the value of checking border demands before sharing passport information. Genuine registration remains free, while Sweden offers a separate voluntary preparation route. The evidence establishes reported impersonation and published travel procedures, but not widespread tourism disruption, quantified losses or a confirmed hotel data breach. Travellers should protect documents, verify requests independently and continue meeting applicable visa and entry conditions. Travel businesses can support that process through accurate customer guidance. Future digital requirements must follow official announcements. The next practical priority is monitoring the confirmed ETIAS launch information without confusing it with existing border registration rules.
Advertisement