[REVISION HISTORY]
European phishing, scams and passwordless push
Updated 3 times since CLSTR started tracking revisions of this situation.
What changed
2026-08-04 14:33 UTC → 2026-08-06 13:33 UTC ·
added
removed
In late May, Portugal’s tax authority warned that of fraudulent emails mimicking IRS amendment requests were circulating, requests, while Cabo Verde’s Casa do Cidadão Verde flagged a fake traffic‑fine notice. The same week, notice; France and Spain saw tax‑refund phishing campaigns promising up to €230, directing victims to counterfeit agency sites. €230. June brought a wave of French banking scams centred on a €69 fake charge and a parallel fuel‑aid phishing email offering €108.72. Authorities urged use of strong authentication (SécuriPass, 2FA) and password‑manager tools. use. The French government also prepared mandatory e‑invoicing for large firms, warning of new fraud vectors, firms and introduced launched the Fraudstop 24‑hour Fraudstop hotline to streamline for card‑blocking and fraud reporting. Belgium’s Testachats survey revealed found 86 % of respondents had faced encountered phishing, prompting the launch of a national reporting point and the Fraudstop number (078 170 170). point. July saw Portugal’s CNCS rolled roll out the MCiber registration platform for public entities and warned of issue phishing emails spoofing the agency. In July, warnings. Bitdefender promoted a summer security suite amid a surge of French data breaches, while and a Prime Video phishing scam targeted French users with a €69.90 renewal lure. France announced the imminent shutdown of the Bloctel do‑not‑call register would close on 11 August 2026, replacing it with to be replaced by an opt‑in consent regime that limits regime. From 11 August 2026, French law will ban commercial telemarketing to calls unless consumers give explicit, revocable permission. Belgian banks reinforced consent lasting no more than one year. Companies must retain proof of consent for three years. Violations carry fines up to €75,000 for individuals and €375,000 for firms, and contracts concluded after illegal calls will be void. Oversight is shared by DGCCRF, CNIL and ARCEP; the decree was published on 25 July action plan by lowering 2026. The measure raised concerns in Morocco about potential job losses, while Germany has operated a similar consent‑based ban since 2009. Belgian banks lowered daily transfer limits to €5,000, adding added a four‑hour cooling‑down before limit increases, and integrating itsme’s new facial‑verification step. integrated itsme facial verification. Portugal’s Social Security and energy provider EDP issued alerts about warned of sophisticated SMS and door‑to‑door phishing attempts. Across the region, passkey‑based passwordless authentication continued to expand, complemented by QR‑code and short‑lived WPS Wi‑Fi pairing, underscoring a coordinated European push against phishing, scam‑related fraud, and insecure credential practices.
Versions
- 2026-08-06 13:33 UTC European phishing, scams and passwordless push
- 2026-08-04 14:33 UTC European phishing, scams and passwordless push
- 2026-07-30 08:30 UTC European phishing, scams and passwordless push
- 2026-07-25 18:41 UTC European phishing, scams and passwordless push
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.