The Fake BPJS Benefit Reactivation Message
Scammers impersonate BPJS Kesehatan or BPJS Ketenagakerjaan, Indonesia's national health and employment insurance bodies, to harvest personal data under the guise of a mandatory reactivation. This walkthrough is a fictional, illustrative example built for training.
The scenario
An employee receives a WhatsApp message or email with the BPJS logo stating: 'Your BPJS Kesehatan participation has been temporarily suspended due to unverified data. Complete verification within 2x24 hours to avoid loss of benefits.'
The message explains that a routine data cleanup requires all participants to confirm their personal details, including full name, date of birth, family card number (KK), and BPJS membership number, through a provided link.
The link opens a page that closely mimics the look of the official BPJS Kesehatan or BPJS Ketenagakerjaan portal, with matching green or blue branding and a form requesting NIK (national ID number), KK number, mobile number, and sometimes bank account details for a claimed 'automatic contribution refund'.
After the form is submitted, the page shows a fake confirmation message thanking the user for 'reactivating' their benefits, delaying discovery of the scam. Some variants also prompt the victim to forward the message to coworkers, framed as a favor, which is really how the scam spreads inside an organization.
Red flags to spot
Threat of losing health or employment benefits within a strict deadline
BPJS does not suspend active, paid-up benefits over an unverified data campaign with a countdown timer. This pressure tactic is meant to bypass careful thinking.
Request for KK number and NIK via a web form
These are sensitive identity documents. Legitimate BPJS verification happens through the official app (Mobile JKN or BPJSTKU) or in person, not a link sent by WhatsApp or email.
Asking for bank account details tied to a 'refund'
BPJS does not process contribution refunds through a reactivation link. Any message combining benefit verification with a money request is a strong sign of fraud.
Link domain unrelated to bpjs-kesehatan.go.id or bpjsketenagakerjaan.go.id
Both agencies operate from official .go.id domains. A shortened URL or a domain with extra words like 'bpjs-verifikasi-online' is not official.
Instruction to forward the message to others
Legitimate institutional notices do not ask recipients to spread them peer to peer. This is a self-propagation tactic borrowed from chain messages, designed to reach more victims faster.
The lesson
Check your BPJS status only through the official Mobile JKN app (for BPJS Kesehatan) or BPJSTKU app (for BPJS Ketenagakerjaan), or by calling the official hotlines: 165 for BPJS Kesehatan and 175 for BPJS Ketenagakerjaan. Never submit your NIK, KK number, or bank details through a link sent unsolicited by WhatsApp or email. If a message asks you to forward it to colleagues, that alone is a strong signal to stop and report it instead.
These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.
Frequently asked questions
BPJS Kesehatan can suspend coverage for unpaid contributions, but this is reflected in your account and payment history, not triggered by an unverified-data campaign requiring you to click a link within hours.
Related pages
Fake E-Wallet Account Suspension Alert
A message claiming your e-wallet account is suspended pushes you to enter your PIN or OTP on a fake page to 'restore access'.
Learn moreFake WhatsApp Verification Code Request
Someone posing as a contact or HR asks you to forward the 6-digit code you just received by SMS, which actually hands over control of your WhatsApp account.
Learn moreMalicious QR Code (Quishing)
A QR code stuck over a parking meter or printed on a fake payment notice leads to a lookalike page that harvests login or card details.
Learn moreRun these patterns as real simulations
Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.
Request a demo