Phishing in banking

Phishing in banking is a fake message in a bank's name that leads the customer to a copied login page or asks for a TAN. The phishing radar of the German consumer centers lists new ones each week in the name of Sparkassen, Volksbanken, DKB and comdirect. Dated events on fraud and digital identity are in the calendar below.

What bank phishing looks like

The BSI, Germany's federal cyber security agency, describes phishing as messages from attackers who pose as trustworthy organizations, banks among them, to steal passwords and personal data. The usual pretexts are account details that must be confirmed, a credit card about to expire or a forced password change. The channel can be email, SMS (smishing), a QR code in a letter or email (quishing) or a phone call (vishing).

The phishing radar of the consumer center in North Rhine-Westphalia shows the pattern in practice: an account that will be restricted within 72 hours unless the customer updates it, a photoTAN app that "expires" and must be renewed, a security update for a TAN app that has to be activated by a deadline. The messages lead to copied pages that ask for login or bank data.

From phished login to payment

A stolen password is not enough to pay at a European bank, because strong customer authentication asks for a second element. Phishing pages therefore ask for the TAN as well, or prompt the customer to approve a request in the banking app. In the 2025 report on payment fraud by the EBA and the ECB, manipulation of the payer rose from 65 to 74 percent of the value of fraudulent credit transfers between 2023 and 2024, a category the report links to phishing, smishing and vishing.

Passkeys close the first part of that route. The passkeys in banking page explains why: the key is bound to the bank's real domain, so a copied login page receives nothing it can reuse.

Who pays after a phishing attack in Germany

A payment that the fraudster initiates with phished data is unauthorized. The bank refunds it under section 675u of the Civil Code, and the customer carries the full loss only after fraud, intent or gross negligence under section 675v.

The Payment Services Regulation adds a refund for a related case. According to the European Parliament, if a scammer poses as an employee of the customer's bank and gets the customer to approve a payment, the bank must refund the full amount, as long as the customer reports the fraud to the police and informs the bank.

Upcoming events on fraud and digital identity in Germany

What should a bank customer do after a phishing message?

The BSI advises not to click links or scan QR codes in suspicious messages, to check the request through another channel and to report criminal cases to the police. The consumer center advises checking bank notices only in the official banking app or on the bank's known website. For a card or online banking access at risk, the fraud prevention in Germany page names the blocking hotline 116 116.

What are smishing and quishing?

Smishing is phishing by SMS, often in the name of a parcel service or an online shop. Quishing uses a QR code that leads to a fake login form. The BSI notes that virus scanners often do not flag QR codes.

Phishing in banking and Finance Loop

Finance Loop is the meeting place for the fraud, security and digital banking teams that defend customers against phishing. Finance Loop announced KI Exchange 2026 in Hamburg, whose program included fraud detection with AI.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.