CITIZENS' INITIATIVEIndependent consumer information, focus on Germany
Deutsch
Phishing & data theft

Spotting phishing: how to unmask fake emails and text messages

You can recognise fake messages from your bank, a parcel service or a streaming provider by recurring patterns. Here is how to check the sender and links, and how to react correctly after a click.

This article is for general information and does not replace legal advice in an individual case. Editorial review by a specialist lawyer (Fachanwalt) is still pending.

"Your account has been temporarily blocked", "Your parcel is waiting, please pay a customs fee of 1.99 EUR", "Your payment method has expired": phishing messages rely on shock and time pressure. The goal is always the same, namely your login credentials, card details or TANs. The fakes are long past being clumsy in their language; even flawless, perfectly designed emails can be phishing. Fortunately, almost all attacks give themselves away in the same places.

The short answer

You recognise phishing less by the design than by three checkpoints: first, the real sender address (not the display name), second, the actual link target (have it shown before clicking), third, the content: time pressure plus a demand to enter data or "verify" something. Remember a single rule: no bank, no savings bank (Sparkasse) and no reputable payment service will ever ask you by email, text message or telephone for your PIN, TAN or password. If you did click and enter data: change passwords immediately, inform your bank, have cards blocked via the blocking emergency number 116 116, and report the case to the Verbraucherzentrale's Phishing-Radar.

The typical scams

  • Bank and Sparkasse: an alleged account block, "confirm new terms and conditions", "your TAN procedure is expiring", a supposedly necessary "data reconciliation". The link leads to a rebuilt login page.
  • Parcel service: a text message or email from "DHL", "Hermes" or "the delivery service", saying a parcel cannot be delivered and a small fee is due. The tiny amounts serve only to grab your card details.
  • Streaming and online accounts: "Your payment method was declined", "Your account will be deleted in 48 hours". Popular with imitators of Netflix, Disney, Amazon and PayPal.
  • Authorities and public offices: fake tax refunds from the "Finanzamt" (tax office) or "Elster", supposed fines.
  • Messenger trick ("Hi Mum"): an unknown number pretends to be a child in distress and asks for an urgent transfer.

Common to all: there is an urgent reason to click, pay or enter data immediately, and consequences are threatened (blocking, deletion, fees, criminal proceedings).

Checkpoint 1: the real sender address

The displayed name can be freely chosen and proves nothing. What matters is the address behind it. Tap or click on the sender name to display it in full. "Sparkasse" as the name with an address like service@sparkasse-sicherheit-24.com or a wild string of characters at a free email provider is a clear case. Watch for small deviations: extra words (paypal-kundenservice.net), transposed letters, unfamiliar endings. Caution: even a seemingly correct sender address can be technically faked. The sender check exposes many fakes, but it is not a real guarantee. That is why checkpoint 2 matters most.

Checkpoint 2: the true link target

On a computer, hover the mouse over the link without clicking: the real target appears at the bottom in the status bar. On a smartphone, press and hold the link until a preview of the URL appears. What matters is the part immediately before the first single ending: with sparkasse.de.sicherheit-check.com you do not end up at the Sparkasse but at sicherheit-check.com. Short URLs and QR codes obscure the target further; QR codes in emails or on stuck-on stickers (parking machines, charging points) are a separate point of entry ("quishing").

The safest habit: as a rule, do not click links from emails and text messages relating to accounts and payments. Open the app or type your bank's or provider's address into the browser yourself. If there really is a problem, you will see it after the normal login.

Checkpoint 3: what is being demanded

Reputable providers never ask you by email or text message to enter your PIN, TAN, passwords or full card details, to install "security apps" from outside the official stores, or to launch remote-maintenance software. The same applies by phone: hang up if an alleged bank employee needs TANs "to cancel a booking". That is exactly how instant transfers get authorised. When in doubt, call your bank yourself on the number you already know, never on the number from the message.

After the click: damage control in the right order

A click alone is rarely the catastrophe. It becomes critical if you entered data or installed something.

  1. Entered data? Change the password of the affected account immediately, and everywhere else you use the same password. Activate two-factor authentication.
  2. Bank or card details affected? Inform your bank without delay and have cards and online banking blocked: central blocking emergency number 116 116, around the clock, from abroad +49 116 116. Check the transactions of the last few days and object to unauthorised bookings; for unauthorised payments the bank must in principle refund (§ 675u BGB, German Civil Code), except in cases of gross negligence, which is disputed on a case-by-case basis.
  3. Installed something? Put the device in flight mode, do nothing sensitive on it any more, and have it checked with up-to-date protection software or reset.
  4. File a criminal complaint: online via the online police station (Onlinewache) of the police in your federal state. This is helpful for reimbursement questions with the bank.
  5. Report it: forward the phishing email to phishing@verbraucherzentrale.nrw; the Verbraucherzentrale's Phishing-Radar evaluates the reports and warns the public about current waves. After that, delete the email.

In brief for Austria and Switzerland

The scams are identical. In Austria, the Watchlist Internet continuously warns about current phishing waves; reports are also accepted by the reporting office of the BKA (via online report). In Switzerland, you can report suspicious messages to the Federal Office for Cybersecurity at antiphishing.ch; in the event of card misuse, the same applies everywhere: contact your own bank immediately and have cards blocked.

Frequently asked questions

I only clicked but entered nothing. Am I safe? Usually yes. Still, keep an eye on your accounts and, to be safe, change the password of the affected service, especially on a smartphone if you downloaded something afterwards.

How do I recognise a fake text message from a parcel service? Genuine parcel services do not collect customs fees via a text-message link. Only check shipments in the official app or directly on the service's website.

Does the bank refund debited money? For unauthorised payments, in principle yes (§ 675u BGB). The bank may reduce or refuse a refund in the event of grossly negligent behaviour, for example when TANs were authorised by you. Document exactly what happened and seek advice.

Important note

We are an independent citizens' initiative (Bürgerinitiative) and provide general information. This text is not legal advice for an individual case. In the event of a dispute or uncertainty, contact your Verbraucherzentrale (consumer advice centre) or a lawyer.

Sources and legal foundations

  • Verbraucherzentrale: Phishing-Radar, aktuelle Warnungen (verbraucherzentrale.de/phishing-radar)
  • BSI: Wie erkenne ich Phishing in E-Mails und auf Webseiten? (bsi.bund.de)
  • Sperr-Notruf 116 116 (sperr-notruf.de)
  • polizei-beratung.de: Phishing
  • Watchlist Internet (watchlist-internet.at), antiphishing.ch (NCSC Schweiz)