Germany

Scams in Munich

Active scams and fraud schemes targeting people in Munich (1.5M population). These scams are tracked across Germany and are known to affect residents in the Munich area. Learn the warning signs, check what is trending, and find out where to report.

51 scams trackedPopulation: 1.5MπŸ‡©πŸ‡ͺ GermanyAll countries

Report fraud in Munich

Where to report scams

If you have been scammed in Munich, report it through the official Germany channels. Acting fast improves your chances of recovery and helps protect others in your area.

Scam index

Scams affecting people in Munich

51 scams tracked across Germany

Brand impersonation scams
↑ 60%

Amazon Prime membership phishing scam

Scammers send emails or texts claiming your Amazon Prime membership is expiring, has a billing problem, or needs verification, directing you to a fake Amazon login page that steals your credentials.

What to do first

Never click links in unexpected Prime renewal messages β€” go directly to amazon.com and check your membership status.

Targets

Amazon Prime members

Seen in

U.S.

Brand impersonation scams
↑ 60%

Amazon Web Services phishing scam

Phishing emails impersonate AWS, claiming account suspension, billing issues, or security alerts, directing cloud service users to fake login portals that steal credentials and compromise business infrastructure.

What to do first

Never click links in AWS notification emails β€” go directly to the AWS Management Console at console.aws.amazon.com.

Targets

Developers

Seen in

U.S.

Brand impersonation scams
↑ 60%

PayPal account limitation phishing scam

Phishing emails or texts claim your PayPal account has been limited or suspended due to suspicious activity, directing you to a fake login page that harvests your credentials.

What to do first

Never click links in PayPal alert emails β€” open a browser and go directly to paypal.com to check your account status.

Targets

PayPal users

Seen in

U.S.

Brand impersonation scams
↑ 60%

PayPal business account phishing scam

Targeted phishing emails impersonate PayPal Business communications, warning of compliance issues, tax form requirements, or payment holds to trick business owners into surrendering account credentials.

What to do first

PayPal will never ask you to submit tax documents or verify business details through an email link β€” always use the PayPal Business dashboard directly.

Targets

Small business owners

Seen in

U.S.

Brand impersonation scams
↑ 60%

Microsoft 365 renewal phishing scam

A phishing email claims your Microsoft 365 subscription is expiring and you must update your payment information, redirecting to a fake Microsoft login page.

What to do first

Check your subscription status directly at account.microsoft.com, never through email links.

Targets

Business professionals

Seen in

U.S.

Brand impersonation scams
↑ 60%

Azure billing phishing scam

IT administrators receive fake Azure billing alerts claiming unusual charges or failed payments, leading to credential theft through a fake Azure portal login.

What to do first

Verify billing directly at portal.azure.com β€” never use links from email notifications.

Targets

IT administrators

Seen in

U.S.

Brand impersonation scams
↑ 60%

Google Ads billing scam

Advertisers receive fake Google Ads billing notifications about failed payments or suspicious charges, leading to phishing pages that steal account credentials.

What to do first

Check your billing status directly at ads.google.com β€” never through email links.

Targets

Digital marketers

Seen in

U.S.

Brand impersonation scams
↑ 60%

Chrome extension malware scam

Malicious Chrome extensions disguised as useful tools steal browsing data, inject ads, or capture credentials from every website the victim visits.

What to do first

Review installed extensions regularly at chrome://extensions and remove any you do not recognize or no longer use.

Targets

Chrome users

Seen in

U.S.

Brand impersonation scams
↑ 60%

LinkedIn Premium account phishing scam

Phishing emails disguised as LinkedIn Premium upgrade offers or billing alerts trick users into entering credentials on fake login pages.

What to do first

Check your LinkedIn subscription status by logging in directly at linkedin.com β€” never through emailed links.

Targets

Professionals

Seen in

U.S.

Brand impersonation scams
↑ 60%

UPS tracking update phishing email

A phishing email mimics UPS tracking notifications with a fake tracking number and a link that installs malware or captures login credentials.

What to do first

Never click tracking links in emails β€” copy the tracking number and enter it directly at ups.com.

Targets

Online shoppers

Seen in

U.S.

Brand impersonation scams
↑ 60%

UPS shipping label email malware scam

A phishing email claims to contain a UPS shipping label attachment, but the file is malware disguised as a PDF or ZIP that installs a trojan or ransomware on the victim's computer.

What to do first

Never open unexpected attachments β€” UPS does not send shipping labels via unsolicited email.

Targets

Small business owners

Seen in

U.S.

Brand impersonation scams
↑ 60%

FedEx commercial invoice phishing scam

A phishing email targets businesses with a fake FedEx commercial invoice attachment that contains malware or links to a credential-harvesting portal.

What to do first

Verify any FedEx invoices by logging in to your FedEx Billing Online account at fedex.com.

Targets

Small business owners

Seen in

U.S.

Social media scams
↑ 76%

LinkedIn connection request phishing scam

Attackers send connection requests with phishing links disguised as shared documents or professional resources, leading to credential-harvesting pages.

What to do first

Never click links in LinkedIn connection requests from people you do not recognize.

Targets

Professionals

Seen in

U.S.

Social media scams
↑ 76%

LinkedIn verification badge scam

Phishing messages offer to help users get a 'verified' badge on LinkedIn, directing them to fake sites that steal credentials or charge fraudulent fees.

What to do first

LinkedIn's identity verification is done through the official app using a government ID and selfie β€” never through external links or payments.

Targets

Professionals

Seen in

U.S.

Misinformation scams
↑ 80%

AI-generated fake news site scam

Entire news websites are created using AI-generated content to look like legitimate local or national news outlets, publishing fabricated stories to drive traffic to ad-fraud pages or promote scam products.

What to do first

Check whether the news site has an About page with real editorial staff and contact information.

Targets

News readers

Seen in

U.S.

Fake antivirus scams
↑ 100%

fake Windows Defender alert scam

A webpage or popup imitates a Windows Defender notification, warning of detected threats and directing the user to call a support number or download a removal tool.

What to do first

Close the browser tab or force-quit the browser β€” real Windows Defender alerts never appear in a browser.

Targets

Non-technical users

Seen in

U.S.

Fake antivirus scams
↑ 100%

fake malware scan results scam

A website runs an animated fake scan of your computer, displaying fabricated threats to trick you into downloading software or paying for a premium cleanup service.

What to do first

Close the tab immediately β€” no legitimate website can scan your local files through a browser.

Targets

Non-technical users

Seen in

U.S.

Fake antivirus scams
↑ 100%

McAfee impersonator popup scam

A browser notification or popup mimics McAfee branding, claiming your subscription has expired or threats have been detected, and pushes you to renew through a fake payment page.

What to do first

Revoke notification permissions in your browser settings for any site you do not recognize.

Targets

Non-technical users

Seen in

U.S.

Email phishing scams
↑ 80%

password reset phishing scam

A fake password reset notification urges the recipient to click a link and enter their current credentials, which are captured by attackers.

What to do first

Never click password reset links you did not request β€” navigate directly to the service's website.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

invoice attachment malware scam

An email with a fake invoice attachment installs malware when opened, giving attackers access to the victim's computer and network.

What to do first

Never open attachments from unknown senders β€” verify invoices by contacting the vendor directly.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

two-factor authentication bypass phishing scam

Attackers use real-time phishing toolkits to capture both passwords and two-factor authentication codes simultaneously, defeating standard MFA protections.

What to do first

Use hardware security keys (FIDO2/WebAuthn) which are resistant to real-time phishing proxy attacks.

Targets

IT administrators

Seen in

U.S.

Email phishing scams
↑ 80%

reply-chain hijacking scam

Attackers compromise an email account and insert malicious messages into existing email threads, exploiting the trust established in ongoing conversations.

What to do first

Be cautious of unexpected attachments or links even in existing email threads.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

OneDrive sharing notification phishing scam

A fake OneDrive sharing notification email claims someone shared a document with you, but the link leads to a credential-stealing page.

What to do first

Verify the sender by contacting them through a separate channel before clicking any shared document link.

Targets

Business professionals

Seen in

U.S.

Email phishing scams
↑ 80%

Google Workspace admin phishing scam

IT administrators receive fake Google Workspace notifications about policy changes, license issues, or security alerts, leading to admin credential theft.

What to do first

Access the admin console directly at admin.google.com β€” never through email links.

Targets

IT administrators

Seen in

U.S.

Other cities in Germany