TrendLife

TrendLife found half the Medicare texts flooding phones are confirmed phishing

    TrendLife found half the Medicare texts flooding phones are confirmed phishing
    iStock

    This article discusses a scam that impersonates Aetna. Aetna and its services are not involved in the scam. All brand names are trademarks of their respective owners.

    A text arrives claiming to be from Medicare or an insurer: benefits are “enclosed,” a request is “pending,” or your account needs to be “verified.” It looks official enough to be worth a reply. TrendLife researchers pulled 12,740 messages that reference Medicare from internal data sources, cleaned out duplicates and unrelated hits, and sorted what was left into categories, to find out how much of this traffic is actual fraud, and what to do about it to stay safe.

    Half of these texts are confirmed phishing. The other half hasn’t been proven either way

    After removing 180 genuine provider and clinic reminders, and setting aside 8,043 political-fundraising texts as protected speech unrelated to fraud, 4,517 messages remained in scope. Of those, 2,287 (50.6%) are confirmed phishing: messages impersonating Medicare, CMS, or an insurer to harvest personal data. The remaining 2,230 (49.4%) are gray-zone lead generation, unsolicited but not fraudulent in the criminal sense, for things like insurance plans, surveys, and prescription discounts.

    Being flagged by a scam-detection feed isn’t the same as confirmed fraud, and TrendLife researchers kept that distinction rather than treating every unsolicited Medicare text the same way. Not every pushy Medicare text is trying to steal from you. But phishing texts and gray-zone marketing look almost identical on the surface. That’s why the specific red flags below matter more than a general sense of suspicion.

    The single largest category impersonates Medicare, CMS, or an insurer directly

    These texts make up the single largest category: 1,773 messages, 39.3% of everything in scope. A recurring example, sent from the display name “PNational”: “[name], You have been notified of a Medicare Request. Verify Details Here: [scam link] Reply Stop to End.” Aetna is impersonated the same way, under the display name “Aetna Medicare.” A display name like “PNational” or “Aetna Medicare” is just text, not verified identity, and anyone can send a message that claims to be from your insurer.

    A close second: texts promising benefits you never applied for

    Extra Benefits / Allowance Lure made up 514 messages, 11.4% of the in-scope total, and is the second-largest confirmed-phishing category. These lead with a version of: “Hi, you paid in for decades. Now get back what’s yours with Medicare Allowance benefits.” and push toward a phone call rather than a link. Together, these two categories make up the confirmed-phishing half of the dataset. A text offering something extra for money you already paid into feels earned, which is exactly what makes the request for information that follows feel reasonable instead of suspicious.

    The domain generating the most “malicious” flags wasn’t a phishing site at all

    TrendLife researchers didn’t stop at the scam-feed label. They ran WHOIS, hosting, and live landing-page checks on a parallel dataset of 4,832 detections, of which 3,921 were flagged. One domain, medicareinfo[.]org, made up 79.7% of all detections, 3,850 of those 3,921 flagged entries. It turned out to be an 11-year-old domain, registered in 2014, hosted on corporate infrastructure, and run by a licensed insurance agency with a named agent and state license on file. That’s not what a throwaway phishing kit looks like.

    Meanwhile, the domains actually used in the impersonation-phishing texts above, PNational’s and Aetna’s, generated close to zero hits in that same malicious-domain feed. When TrendLife researchers compared the two lists, only about 2% of the entries overlapped. The most-flagged domain on a blocklist and the text message actually trying to steal your information are often not the same thing, and the biggest name on a blocklist isn’t necessarily the biggest risk to you personally.

    At least four separate operators are running the same script

    By tracing shared hosting and DNS accounts across the scam-relevant domains, TrendLife researchers found at least two separate impersonation-phishing operators, the PNational cluster and the Aetna cluster, one large affiliate lead-generation network spanning seven domains, and the licensed lead-gen operator behind medicareinfo[.]org. No shared registrar, nameserver, or hosting ties these groups together. Recognizing one operator’s texts won’t protect you from the next one, because what holds across all of them isn’t a shared sender or domain. It’s the script: urgency, a claim about your benefits, and a push to click or call.

    How to stay safe

    1. Don’t click links or call numbers in an unsolicited Medicare text, even if it names your real insurer. Display names aren’t verified, Anyone can send a message that looks like it’s from your insurer.

    2. Verify by using the number on your Medicare or insurance card, not one from the message.

    3. Use Trend Micro ScamCheck to analyze suspicious links and texts before engaging.

    4. Remember that Medicare doesn’t initiate contact by text about your benefits. A message claiming your benefits are “enclosed” or a request is “pending” is the red flag, not the reassurance.

    5. Be skeptical of “extra” or “allowance” offers tied to money you already paid in. Real benefit changes come through your plan directly.

    6. Report suspicious texts to 1-800-MEDICARE (1-800-633-4227).

    These Medicare phishing texts can look exactly like something your insurer would send. The name on the message changes. The sender changes. But the script doesn’t: urgency, a claim about your benefits, and a push to act. Once you can recognize it, you’re one step ahead of the scammers.

    Post a comment

    Your email address won't be shown publicly.

    0 Comments

      Copyright © 2026 Trend Micro Incorporated. All rights reserved.

      This website uses cookies for website functionality, traffic analytics, personalization, social media functionality and advertising. Our Cookie Notice provides more information and explains how to amend your cookie settings.