🇩🇪

Germany

Scam and fraud reporting in Germany

If you've been scammed or suspect fraud in Germany, report it quickly — fast action improves your chances of recovering money and helps authorities track the scheme. The Verbraucherzentrale and your local police are the main starting points.

51 scams tracked3 reporting channelsAll countries

If you have been scammed

  • 1Save the phishing email, fake shop URL, payment confirmation, or suspicious message before it is deleted.
  • 2If banking credentials were exposed, contact your bank immediately and change passwords for affected accounts.
  • 3File a criminal complaint (Strafanzeige) at your local police station or online, and report to the appropriate consumer-protection body.
  • 4Change passwords on any compromised accounts and enable two-factor authentication.

Think it might be a scam?

  • 1Use the Verbraucherzentrale Fakeshop-Finder at verbraucherzentrale.de/fakeshopfinder to check whether an online shop is legitimate.
  • 2Verify any business through the Handelsregister (commercial register) at handelsregister.de.
  • 3Contact the organisation directly using a number from their official website, not the one you were given.
  • 4Check BSI alerts at bsi.bund.de for current phishing campaigns and cyber threats targeting German consumers.

Scam index

Scams affecting people in Germany

51 scams tracked

Brand impersonation scams
↑ 60%

Amazon Prime membership phishing scam

Scammers send emails or texts claiming your Amazon Prime membership is expiring, has a billing problem, or needs verification, directing you to a fake Amazon login page that steals your credentials.

What to do first

Never click links in unexpected Prime renewal messages — go directly to amazon.com and check your membership status.

Targets

Amazon Prime members

Seen in

U.S.

Brand impersonation scams
↑ 60%

Amazon Web Services phishing scam

Phishing emails impersonate AWS, claiming account suspension, billing issues, or security alerts, directing cloud service users to fake login portals that steal credentials and compromise business infrastructure.

What to do first

Never click links in AWS notification emails — go directly to the AWS Management Console at console.aws.amazon.com.

Targets

Developers

Seen in

U.S.

Brand impersonation scams
↑ 60%

PayPal account limitation phishing scam

Phishing emails or texts claim your PayPal account has been limited or suspended due to suspicious activity, directing you to a fake login page that harvests your credentials.

What to do first

Never click links in PayPal alert emails — open a browser and go directly to paypal.com to check your account status.

Targets

PayPal users

Seen in

U.S.

Brand impersonation scams
↑ 60%

PayPal business account phishing scam

Targeted phishing emails impersonate PayPal Business communications, warning of compliance issues, tax form requirements, or payment holds to trick business owners into surrendering account credentials.

What to do first

PayPal will never ask you to submit tax documents or verify business details through an email link — always use the PayPal Business dashboard directly.

Targets

Small business owners

Seen in

U.S.

Brand impersonation scams
↑ 60%

Microsoft 365 renewal phishing scam

A phishing email claims your Microsoft 365 subscription is expiring and you must update your payment information, redirecting to a fake Microsoft login page.

What to do first

Check your subscription status directly at account.microsoft.com, never through email links.

Targets

Business professionals

Seen in

U.S.

Brand impersonation scams
↑ 60%

Azure billing phishing scam

IT administrators receive fake Azure billing alerts claiming unusual charges or failed payments, leading to credential theft through a fake Azure portal login.

What to do first

Verify billing directly at portal.azure.com — never use links from email notifications.

Targets

IT administrators

Seen in

U.S.

Brand impersonation scams
↑ 60%

Google Ads billing scam

Advertisers receive fake Google Ads billing notifications about failed payments or suspicious charges, leading to phishing pages that steal account credentials.

What to do first

Check your billing status directly at ads.google.com — never through email links.

Targets

Digital marketers

Seen in

U.S.

Brand impersonation scams
↑ 60%

Chrome extension malware scam

Malicious Chrome extensions disguised as useful tools steal browsing data, inject ads, or capture credentials from every website the victim visits.

What to do first

Review installed extensions regularly at chrome://extensions and remove any you do not recognize or no longer use.

Targets

Chrome users

Seen in

U.S.

Brand impersonation scams
↑ 60%

LinkedIn Premium account phishing scam

Phishing emails disguised as LinkedIn Premium upgrade offers or billing alerts trick users into entering credentials on fake login pages.

What to do first

Check your LinkedIn subscription status by logging in directly at linkedin.com — never through emailed links.

Targets

Professionals

Seen in

U.S.

Brand impersonation scams
↑ 60%

UPS tracking update phishing email

A phishing email mimics UPS tracking notifications with a fake tracking number and a link that installs malware or captures login credentials.

What to do first

Never click tracking links in emails — copy the tracking number and enter it directly at ups.com.

Targets

Online shoppers

Seen in

U.S.

Brand impersonation scams
↑ 60%

UPS shipping label email malware scam

A phishing email claims to contain a UPS shipping label attachment, but the file is malware disguised as a PDF or ZIP that installs a trojan or ransomware on the victim's computer.

What to do first

Never open unexpected attachments — UPS does not send shipping labels via unsolicited email.

Targets

Small business owners

Seen in

U.S.

Brand impersonation scams
↑ 60%

FedEx commercial invoice phishing scam

A phishing email targets businesses with a fake FedEx commercial invoice attachment that contains malware or links to a credential-harvesting portal.

What to do first

Verify any FedEx invoices by logging in to your FedEx Billing Online account at fedex.com.

Targets

Small business owners

Seen in

U.S.

Social media scams
↑ 76%

LinkedIn connection request phishing scam

Attackers send connection requests with phishing links disguised as shared documents or professional resources, leading to credential-harvesting pages.

What to do first

Never click links in LinkedIn connection requests from people you do not recognize.

Targets

Professionals

Seen in

U.S.

Social media scams
↑ 76%

LinkedIn verification badge scam

Phishing messages offer to help users get a 'verified' badge on LinkedIn, directing them to fake sites that steal credentials or charge fraudulent fees.

What to do first

LinkedIn's identity verification is done through the official app using a government ID and selfie — never through external links or payments.

Targets

Professionals

Seen in

U.S.

Misinformation scams
↑ 80%

AI-generated fake news site scam

Entire news websites are created using AI-generated content to look like legitimate local or national news outlets, publishing fabricated stories to drive traffic to ad-fraud pages or promote scam products.

What to do first

Check whether the news site has an About page with real editorial staff and contact information.

Targets

News readers

Seen in

U.S.

Fake antivirus scams
↑ 100%

fake Windows Defender alert scam

A webpage or popup imitates a Windows Defender notification, warning of detected threats and directing the user to call a support number or download a removal tool.

What to do first

Close the browser tab or force-quit the browser — real Windows Defender alerts never appear in a browser.

Targets

Non-technical users

Seen in

U.S.

Fake antivirus scams
↑ 100%

fake malware scan results scam

A website runs an animated fake scan of your computer, displaying fabricated threats to trick you into downloading software or paying for a premium cleanup service.

What to do first

Close the tab immediately — no legitimate website can scan your local files through a browser.

Targets

Non-technical users

Seen in

U.S.

Fake antivirus scams
↑ 100%

McAfee impersonator popup scam

A browser notification or popup mimics McAfee branding, claiming your subscription has expired or threats have been detected, and pushes you to renew through a fake payment page.

What to do first

Revoke notification permissions in your browser settings for any site you do not recognize.

Targets

Non-technical users

Seen in

U.S.

Email phishing scams
↑ 80%

password reset phishing scam

A fake password reset notification urges the recipient to click a link and enter their current credentials, which are captured by attackers.

What to do first

Never click password reset links you did not request — navigate directly to the service's website.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

invoice attachment malware scam

An email with a fake invoice attachment installs malware when opened, giving attackers access to the victim's computer and network.

What to do first

Never open attachments from unknown senders — verify invoices by contacting the vendor directly.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

two-factor authentication bypass phishing scam

Attackers use real-time phishing toolkits to capture both passwords and two-factor authentication codes simultaneously, defeating standard MFA protections.

What to do first

Use hardware security keys (FIDO2/WebAuthn) which are resistant to real-time phishing proxy attacks.

Targets

IT administrators

Seen in

U.S.

Email phishing scams
↑ 80%

reply-chain hijacking scam

Attackers compromise an email account and insert malicious messages into existing email threads, exploiting the trust established in ongoing conversations.

What to do first

Be cautious of unexpected attachments or links even in existing email threads.

Targets

Office workers

Seen in

U.S.

Email phishing scams
↑ 80%

OneDrive sharing notification phishing scam

A fake OneDrive sharing notification email claims someone shared a document with you, but the link leads to a credential-stealing page.

What to do first

Verify the sender by contacting them through a separate channel before clicking any shared document link.

Targets

Business professionals

Seen in

U.S.

Email phishing scams
↑ 80%

Google Workspace admin phishing scam

IT administrators receive fake Google Workspace notifications about policy changes, license issues, or security alerts, leading to admin credential theft.

What to do first

Access the admin console directly at admin.google.com — never through email links.

Targets

IT administrators

Seen in

U.S.

Multi-channel phishing scams
↑ 275%

video call then credential harvest scam

Scammers set up a video call posing as IT support, a vendor, or colleague, then share a screen link or chat message during the call that leads to credential theft.

What to do first

Never enter credentials while sharing your screen in a video call.

Targets

Business professionals

Seen in

U.S.

Online shopping scams
↑ 166%

Amazon fake return refund scam

Scammers contact Amazon sellers or buyers claiming a return was never received or a refund is owed, manipulating the process to keep both the product and the money.

What to do first

Sellers should photograph and weigh all outgoing shipments and use tracking with signature confirmation.

Targets

Amazon sellers

Seen in

U.S.

Online shopping scams
↑ 166%

eBay counterfeit luxury item scam

Sellers list counterfeit luxury goods — handbags, watches, sneakers — as authentic on eBay, often with stolen photos from legitimate retailers.

What to do first

Use eBay's Authenticity Guarantee program for eligible categories like watches, sneakers, and handbags.

Targets

Luxury shoppers

Seen in

U.S.

Fake app scams
↑ 11%

fake QR scanner app scam

Malicious QR code scanner apps request excessive permissions and display aggressive ads or install malware, despite smartphones having built-in QR scanning capability.

What to do first

Use your phone built-in camera QR scanning feature rather than downloading a third-party scanner app

Targets

Smartphone users

Seen in

U.S.

Fake app scams
↑ 11%

fake fitness tracker app scam

Fraudulent fitness and health apps collect sensitive biometric and health data under the guise of step counting or workout tracking, then sell or exploit this data.

What to do first

Use fitness apps from established developers like Apple Health, Google Fit, Strava, or Fitbit

Targets

Smartphone users

Seen in

U.S.

Dating verification scams
↑ 41%

video chat verification scam

A dating match insists on verifying identity through a specific video chat app that requires payment or downloads malware onto your device.

What to do first

Suggest a mainstream video app like FaceTime, Zoom, or Google Meet — a legitimate person will agree.

Targets

Online daters

Seen in

U.S.

Dating verification scams
↑ 41%

premium membership phishing scam

A message claiming to be from a dating app offers a free premium membership upgrade via a link that leads to a phishing page designed to steal your login credentials.

What to do first

Only upgrade your dating app membership through the official app or website — never through external links.

Targets

Online daters

Seen in

U.S.

QR code scams
↑ 27%

QR code on flyer phishing scam

Scammers distribute flyers with QR codes offering fake deals, free products, or prize claims that lead to phishing websites designed to steal personal and financial information.

What to do first

Be skeptical of unsolicited flyers with QR codes, especially those promising free items or large prizes.

Targets

General public

Seen in

U.S.

QR code scams
↑ 27%

business card QR code scam

Scammers distribute fake business cards with QR codes at networking events or public places that lead to malware downloads or credential-harvesting phishing sites.

What to do first

Search for the person and company online independently rather than scanning the QR code.

Targets

Professionals

Seen in

U.S.

QR code scams
↑ 27%

EV charging station QR code scam

Fraudulent QR code stickers are placed on electric vehicle charging stations, directing drivers to fake payment sites that steal credit card information instead of activating the charger.

What to do first

Use the charging network's official mobile app rather than scanning QR codes on the station.

Targets

EV owners

Seen in

U.S.

Remote worker scams
↑ 20%

VPN phishing scam targeting remote workers

Phishing emails impersonate corporate IT departments and direct remote workers to fake VPN login pages that capture their corporate credentials.

What to do first

Never click VPN login links in emails — always access your corporate VPN through the official application or bookmark.

Targets

Remote workers

Seen in

U.S.

Remote worker scams
↑ 20%

Slack impersonation scam targeting remote workers

Scammers gain access to a Slack workspace or create convincing fake Slack notifications to trick remote workers into clicking malicious links or sharing credentials.

What to do first

Never click links in Slack notification emails — open Slack directly through the app or bookmark.

Targets

Remote workers

Seen in

U.S.

WiFi and hotspot scams
↑ 15%

evil twin airport WiFi scam

An attacker sets up a WiFi network with the same name as a legitimate airport hotspot, intercepting all data transmitted by connected users including passwords and financial information.

What to do first

Confirm the exact network name and authentication process with airport staff before connecting.

Targets

Travelers

Seen in

U.S.

WiFi and hotspot scams
↑ 15%

coffee shop man-in-the-middle scam

An attacker on the same coffee shop WiFi network intercepts communications between your device and the router, capturing sensitive data or injecting malicious content.

What to do first

Always use a VPN on public WiFi — it encrypts all traffic and prevents interception.

Targets

Remote workers

Seen in

U.S.

WiFi and hotspot scams
↑ 15%

Bluetooth proximity attack scam

An attacker exploits Bluetooth connections in crowded public spaces to send malicious files, access device data, or push unwanted notifications to nearby phones.

What to do first

Set your Bluetooth to non-discoverable or turn it off entirely when not actively using it.

Targets

Travelers

Seen in

U.S.

WiFi and hotspot scams
↑ 15%

WiFi Pineapple attack scam

A WiFi Pineapple device is used to automatically impersonate saved WiFi networks on your device, tricking it into connecting and exposing your data to the attacker.

What to do first

Regularly clear saved WiFi networks from your device, especially open networks from hotels, airports, and cafes.

Targets

Business travelers

Seen in

U.S.

WiFi and hotspot scams
↑ 15%

event venue fake network scam

A fake WiFi network at a conference, concert, or sporting event mimics the venue's official network to capture data from thousands of attendees simultaneously.

What to do first

Check the event program, app, or organizer's website for official WiFi network details before connecting.

Targets

Travelers

Seen in

U.S.

AI deepfake scams
↑ 19%

AI-generated news anchor scam

Scammers create fake news broadcasts using AI-generated anchors who report fabricated stories designed to promote fraudulent products, investments, or political disinformation.

What to do first

Cross-reference any news clip with the official website of the network it claims to represent.

Targets

Seniors

Seen in

U.S.

Warranty scams
↑ 13%

warranty expiration phishing email scam

Phishing emails claiming your product warranty is about to expire direct you to fraudulent websites designed to steal login credentials and payment information.

What to do first

Never click links in unsolicited warranty expiration emails and instead log in to your account directly on the manufacturer website

Targets

Consumers

Seen in

U.S.

Ponzi and pyramid schemes
↓ 3%

crowdfunding Ponzi scheme

Scammers use crowdfunding platforms or create their own to collect funds for fictional projects, using new contributions to pay fake returns to early backers before disappearing.

What to do first

Research the project team independently and verify their identities and past work before backing a campaign

Targets

Investors

Seen in

U.S.

Cryptocurrency scams
↓ 8%

Coinbase account suspended phishing scam

Phishing emails or texts claim your Coinbase account has been suspended due to suspicious activity, directing you to a fake login page that steals your credentials and two-factor codes.

What to do first

Never click links in emails or texts about account issues — log in directly at coinbase.com to check your account status.

Targets

Cryptocurrency investors

Seen in

U.S.

Cryptocurrency scams
↓ 8%

Coinbase withdrawal verification phishing scam

Fake emails alert users to a large withdrawal from their Coinbase account and prompt them to 'cancel' the transaction through a phishing link that captures their credentials.

What to do first

Check your account directly at coinbase.com — if there is no pending withdrawal, the email is fake.

Targets

Cryptocurrency investors

Seen in

U.S.

Fake ticket scams
↓ 18%

music festival ticket fraud

Scammers sell fake wristbands or digital passes for popular music festivals, often using stolen images of real wristbands to appear legitimate.

What to do first

Use only the official festival resale or transfer platform to purchase secondhand passes

Targets

Concertgoers

Seen in

U.S.

Fake airdrop scams
↓ 27%

Discord airdrop bot scam

Malicious bots in crypto Discord servers send automated DMs about fake airdrops, directing users to phishing sites that steal wallet credentials or drain connected wallets.

What to do first

Disable DMs from server members in your Discord privacy settings for crypto-related servers

Targets

Crypto users

Seen in

U.S.

Fake airdrop scams
↓ 27%

layer-2 bridge exploit airdrop scam

Fake airdrops impersonate layer-2 scaling solutions and direct users to fraudulent bridge interfaces that steal deposited funds instead of bridging them to another network.

What to do first

Use bridge interfaces only from the official project website and verify the URL through multiple trusted sources

Targets

DeFi participants

Seen in

U.S.

Fake invoice scams
↓ 7%

subscription service invoice scam

A fake invoice for a software subscription or SaaS product is sent to businesses, mimicking real services like cloud storage, CRM tools, or collaboration platforms.

What to do first

Maintain a central registry of all software subscriptions and cross-reference every invoice against it.

Targets

Small business owners

Seen in

U.S.

Fake invoice scams
↓ 7%

cloud hosting invoice scam

A fake invoice claiming to be from AWS, Google Cloud, or another hosting provider demands payment for services, targeting companies that use multiple cloud vendors.

What to do first

Verify all cloud invoices by logging directly into your provider's billing console — AWS, Google Cloud, and Azure all have online billing dashboards.

Targets

Small business owners

Seen in

U.S.

Cities

Scam reports by city in Germany

Other countries