SCAM: YES

Risk:High — A fake pending-insurance-payment notice uses a misleading login domain to capture credentials or payment information.

Install the app:Open the app and verify suspicious content in one scan.

Online Scam Prevention for Fake Insurance Payments

When this applies

Use this online scam prevention walkthrough when a parent, grandparent or other family member receives a file or message claiming an insurance payment is waiting to be credited and asking them to sign in. The wording may say: “Pojistná platba čeká na připsání…” (“An insurance payment is waiting to be credited…”) and provide login links. The visible address may resemble `auth.vzp.cz.otterco.com`, but its controlling domain is `otterco.com`; `vzp.cz` only appears inside the subdomain. Explain it simply: “The address contains a familiar name, but the website belongs to the domain at the end. We will check the insurance account without using this link.”

Decision steps in order

  1. Tell your family member not to click the link, open another attachment, reply or enter any information.
  2. Inspect the full address together. If it ends in `otterco.com`, do not treat it as an official `vzp.cz` destination.
  3. Look for missing context: the message does not clearly identify the sender, explain which policy or payment it concerns, or provide safe official navigation.
  4. Verify the claim independently. Type the insurer’s known address yourself, use a saved official bookmark, or call the number printed on the insurance card or policy documents.
  5. Ask the insurer whether any payment is genuinely pending. Do not use phone numbers, login buttons or contact details supplied in the suspicious message.
  6. Mark the message as phishing and remove it only after preserving a screenshot if the insurer, bank or workplace security team requests evidence.

What to do if you already responded

If credentials were entered, change the password through the independently opened official site and change it anywhere else it was reused. Contact the insurer immediately and review the account for altered contact, payment or recovery details. If card or bank information was submitted, call the bank using the number on the card and request fraud protection. If a file was downloaded, do not reopen it; disconnect the device from sensitive accounts and have it checked by a trusted technical professional.

Most common warning signals

What to do now

  1. Do not click the login link or open further attachments.
  2. Check whether the full hostname ends in `otterco.com`.
  3. Verify the alleged payment through a separately opened official channel.
  4. Change exposed or reused passwords immediately through the official site.
  5. Call the bank if any card or banking information was submitted.
  6. Report the message as phishing and retain a screenshot if needed.

Install ScamBuster AI

Open the app and verify suspicious content in one scan.

Install ScamBuster AI

Further reading

FAQ

Is auth.vzp.cz.otterco.com an official VZP address?

No. In `auth.vzp.cz.otterco.com`, the controlling domain is `otterco.com`; the familiar-looking `vzp.cz` text is part of the subdomain and can be chosen to mislead visitors.

What if my parent clicked the link but entered nothing?

Close the page and do not revisit it. If nothing was entered or downloaded, verify the payment separately through a known official channel and watch for follow-up messages.

What should we do after entering login details?

Treat the credentials as exposed. Change the password through the independently accessed official account, replace it anywhere it was reused, and contact the insurer to check for account changes.