You can recognise fake messages from your bank, a parcel service or a streaming provider by recurring patterns. Here is how to check the sender and links, and how to react correctly after a click.
"Your account has been temporarily blocked", "Your parcel is waiting, please pay a customs fee of 1.99 EUR", "Your payment method has expired": phishing messages rely on shock and time pressure. The goal is always the same, namely your login credentials, card details or TANs. The fakes are long past being clumsy in their language; even flawless, perfectly designed emails can be phishing. Fortunately, almost all attacks give themselves away in the same places.
You recognise phishing less by the design than by three checkpoints: first, the real sender address (not the display name), second, the actual link target (have it shown before clicking), third, the content: time pressure plus a demand to enter data or "verify" something. Remember a single rule: no bank, no savings bank (Sparkasse) and no reputable payment service will ever ask you by email, text message or telephone for your PIN, TAN or password. If you did click and enter data: change passwords immediately, inform your bank, have cards blocked via the blocking emergency number 116 116, and report the case to the Verbraucherzentrale's Phishing-Radar.
Common to all: there is an urgent reason to click, pay or enter data immediately, and consequences are threatened (blocking, deletion, fees, criminal proceedings).
The displayed name can be freely chosen and proves nothing. What matters is the address behind it. Tap or click on the sender name to display it in full. "Sparkasse" as the name with an address like service@sparkasse-sicherheit-24.com or a wild string of characters at a free email provider is a clear case. Watch for small deviations: extra words (paypal-kundenservice.net), transposed letters, unfamiliar endings. Caution: even a seemingly correct sender address can be technically faked. The sender check exposes many fakes, but it is not a real guarantee. That is why checkpoint 2 matters most.
On a computer, hover the mouse over the link without clicking: the real target appears at the bottom in the status bar. On a smartphone, press and hold the link until a preview of the URL appears. What matters is the part immediately before the first single ending: with sparkasse.de.sicherheit-check.com you do not end up at the Sparkasse but at sicherheit-check.com. Short URLs and QR codes obscure the target further; QR codes in emails or on stuck-on stickers (parking machines, charging points) are a separate point of entry ("quishing").
The safest habit: as a rule, do not click links from emails and text messages relating to accounts and payments. Open the app or type your bank's or provider's address into the browser yourself. If there really is a problem, you will see it after the normal login.
Reputable providers never ask you by email or text message to enter your PIN, TAN, passwords or full card details, to install "security apps" from outside the official stores, or to launch remote-maintenance software. The same applies by phone: hang up if an alleged bank employee needs TANs "to cancel a booking". That is exactly how instant transfers get authorised. When in doubt, call your bank yourself on the number you already know, never on the number from the message.
A click alone is rarely the catastrophe. It becomes critical if you entered data or installed something.
The scams are identical. In Austria, the Watchlist Internet continuously warns about current phishing waves; reports are also accepted by the reporting office of the BKA (via online report). In Switzerland, you can report suspicious messages to the Federal Office for Cybersecurity at antiphishing.ch; in the event of card misuse, the same applies everywhere: contact your own bank immediately and have cards blocked.
I only clicked but entered nothing. Am I safe? Usually yes. Still, keep an eye on your accounts and, to be safe, change the password of the affected service, especially on a smartphone if you downloaded something afterwards.
How do I recognise a fake text message from a parcel service? Genuine parcel services do not collect customs fees via a text-message link. Only check shipments in the official app or directly on the service's website.
Does the bank refund debited money? For unauthorised payments, in principle yes (§ 675u BGB). The bank may reduce or refuse a refund in the event of grossly negligent behaviour, for example when TANs were authorised by you. Document exactly what happened and seek advice.
We are an independent citizens' initiative (Bürgerinitiative) and provide general information. This text is not legal advice for an individual case. In the event of a dispute or uncertainty, contact your Verbraucherzentrale (consumer advice centre) or a lawyer.