ETIAS status:Not live·No official launch date yet; reporting points to 2027
ETIAS Pro markETIASPro
Scam watch

Scam emails fake EES registration to steal passport scans

Phishing emails are telling Schengen travellers they must submit a digital migration declaration online before arrival. They are a scam. EES registration happens at the border, not at a website, and there is no advance requirement.

By the ETIAS Pro editorial team4 min readHow we keep this accurate

Phishing emails claiming you must register for the EU’s Entry/Exit System online before travelling to Europe are a scam. Security researchers at Kaspersky reported the campaign on 5 October 2026. The emails direct travellers to a fake website that mimics the EU’s official EES portal and asks for passport scans, personal details and travel dates. There is no online pre-registration requirement for EES. Your data is captured at the border the first time you cross, not at a website before you leave home.

What do the emails claim?

The messages tell recipients that new Schengen rules require every tourist to submit a “digital migration declaration” at least five working days before arriving. Miss the deadline, they warn, and you face additional checks or could be refused entry.

That requirement does not exist. There is no digital migration declaration. The EES system records your facial image, fingerprints and travel-document data when you arrive at an external Schengen border, handled by the border officer. It has been operating that way since 10 April 2026. Nothing happens online in advance.

Why does this scam convince people?

EES is real, and it is new. It rolled out from October 2025 and generated widespread news about queue times and biometric checks. Anyone who has travelled to Europe since then knows the border process has changed. An email about “new registration requirements” lands in that context of genuine change, and can be hard to dismiss without stopping to think.

Kaspersky’s researchers found the fake website replicates EU branding with a multilingual interface in English, Turkish, Arabic, Chinese and Spanish. It prompts visitors to submit passport scans, travel dates and details of accompanying travellers. That data could then be used to contact victims by phone and extract further personal information.

The campaign also exploits the confusion between EES and ETIAS. ETIAS, the separate pre-travel authorisation, will genuinely require an online application before travel once it goes live. Press reporting points to a launch in 2027; no official date has been confirmed by the EU. Until ETIAS opens, there is nothing to apply for online. See the ETIAS status page for the current position.

Does EES actually need any advance action?

No, and it is worth being clear about this. When you first cross an external Schengen border, a border officer scans your passport chip, takes your fingerprints and captures a facial image. That is the EES registration. It happens at the desk on arrival, not at a website beforehand.

There is one official, voluntary option to pre-register part of your data: the “Travel to Europe” app, built by Frontex and free to download. Even that does not replace the fingerprint step, which is still taken in person. It is also only available at a handful of airports so far, and no one is asked or required to use it. Nothing legitimate charges a fee for EES access, and nothing sends you an email demanding action days in advance.

For how EES and ETIAS work differently and what each one requires from you, see our EES vs ETIAS guide.

What to do if you received one of these emails

  • Delete it without clicking any links. The email is a phishing attempt. There is no legitimate action to take from it.
  • If you already uploaded a passport scan, act fast. That data can be used in follow-up calls or identity fraud. Contact your bank to flag the exposure, keep any confirmation emails, and be wary of unexpected calls asking you to verify your “registration”.
  • Report it. In the UK, forward phishing emails to report.phishing@ncsc.gov.uk. Your national consumer protection or fraud service is the other avenue.
  • Pass the warning on. Kaspersky found the campaign targets English, Turkish, Arabic, Chinese and Spanish speakers. Wide reach. Anyone you know planning a Schengen trip deserves a heads-up.

The wider pattern

This is not the first scam to use genuine EU border changes as cover. Fake ETIAS websites have been active for years, taking money for an authorisation that nobody can issue yet. The EES phishing campaign is a variation: rather than selling a fake product, it collects valuable passport data directly. Both rely on the same gap between travellers knowing that rules have changed at the European border, and not knowing the details.

The practical protection is straightforward. For EES: no website or email can register you. It happens at the border. For ETIAS: the only place to apply will be the official EU site at travel-europe.europa.eu/etias, and applications are not open yet.

Get one email when ETIAS opens

Get one email when ETIAS applications open. No passport details. No payment before launch.

You’ll get a signup confirmation now, one email when ETIAS applications open, and a heads-up only if the official timeline materially changes. Unsubscribe or ask to be removed at any time. No passport details before launch. Privacy.

← All ETIAS news and updates