Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [CRIME]
2 clusters · 13 sources · 30 days · First seen · Last updated
Expanding phishing and scam tactics in German-speaking areas
Overview
German consumer protection agencies initially issued warnings regarding phishing attacks targeting Sparkasse customers. These attacks utilized urgent emails, such as ‘Update dringend erforderlich!’, to trick users into visiting fraudulent websites designed to steal login credentials under the guise of necessary security updates.
As the situation progressed, the scope of the warnings expanded to include financial institutions and consumer protection agencies across Germany, Austria, and Switzerland. The scams evolved to include fraudulent calls and subject lines like ‘Ihre sichere freigabe für online-banking’, often threatening to block banking apps to pressure victims into providing data or confirming fraudulent transfers.
Recent developments indicate a diversification of tactics. Security researchers have identified a wave of tech-support scams utilizing fraudulent Google Ads on hundreds of legitimate websites. These ads employ malicious scripts to freeze user screens and display fake security warnings, directing victims to fraudulent hotlines. Additionally, in Switzerland, the Federal Office for Cybersecurity (BACS) has warned of physical phishing tactics involving fake Swiss Post collection notices left in mailboxes. These notices contain QR codes that lead to fraudulent websites designed to steal personal information and credit card data.
Authorities emphasize that because many transfers are now processed in real-time, immediate action is critical. Recommended emergency procedures include contacting banks to block access or cards, changing passwords, preserving evidence such as messages and receipts, and reporting incidents to the police.
Entities
Sparkasse · Verbraucherzentrale · Google Ads · Netskope · Margot Brands Limited
Timeline
-
2 days ago
[TECHNOLOGY] 9 sourcesCybersecurity alerts: Google Ads scams and physical phishing tacticsCybercriminals are using Google Ads to run tech-support scams on hundreds of websites and leaving fake Swiss Post notices in mailboxes to steal data via QR codes.
-
about 1 month ago
[CRIME] 4 sourcesSparkasse customers warned of pushTAN phishing attacksGerman consumer advocates warn Sparkasse customers of phishing emails using urgent pushTAN update claims to steal online banking credentials.
Sources
ad-hoc-news.de · blogspan.net · borncity.com · chip.de · futurezone.de · it-boltwise.de · mimikama.org · rantlos.de · schweiznews.ch · spidersweb.pl · swr3.de · teltarif.de · wmn.de
This summary has been updated 1 time: see revision history