started · updated
Cybercriminals launch diverse phishing and WhatsApp fraud campaigns across Europe
Authorities and consumer protection agencies are warning of multiple sophisticated phishing and fraud campaigns targeting users in Germany, Italy, and Austria.
In Italy, the Polizia di Stato has identified a wave of “zero-click” WhatsApp attacks. In these incidents, criminals hijack accounts to send fraudulent money requests to contacts in the victim's address book without requiring the user to click any links. This exploit reportedly targets outdated versions of iOS and WhatsApp on Apple devices.
In Germany, the Verbraucherzentrale is warning of WhatsApp-themed phishing emails that threaten users with immediate account deactivation to trick them into clicking links and revealing personal data. Separately, police in Konstanz reported a case where a man was defrauded via a fake bank letter containing a QR code and spoofed phone calls from individuals posing as bank employees.
In Austria, a targeted phishing campaign is impersonating the Austrian Health Insurance Fund (ÖGK). Scammers use messages promising a specific refund of 2,998 euros to lure victims to fake login portals designed to steal banking credentials and trigger unauthorized transfers.
In response to rising fraud, WhatsApp is testing a “Scam Alert” feature for Android beta users. The tool uses machine learning to identify suspicious linguistic patterns in messages from unknown contacts and provides in-chat warnings.
Entities
Bundesamt für Sicherheit in der Informationstechnik · Deutsche Rentenversicherung · Meta · Polizia di Stato · Verbraucherzentrale · WhatsApp · Österreichische Gesundheitskasse