For many consumers, online fraud has long been a part of everyday digital life. The shows that one in four consumers in Germany has already been affected by online fraud. Among the biggest threats is —the theft of sensitive data such as email addresses, passwords, or bank account information.

The "Federal Cybercrime Situation Report 2025" also illustrates just how prevalent this scam is: In 2025 alone, 382,470 phishing emails were recorded. This figure makes it clear that phishing remains one of the most commonly used methods by cybercriminals.

At the same time, attack methods are changing rapidly. In addition to traditional emails, scammers now rely on QR codes, text messages, phone calls, and artificial intelligence to deceive their victims.

During the 2026 SCHUFA Protection Weeks, we’ll show you which phishing scams are particularly prevalent right now, how to spot them, and how you can effectively protect yourself against data misuse and financial loss.

  • Phishing is one of the biggest threats to consumers in Germany. Nearly half of all security inquiries reported to the BSI are related to phishing, account misuse, or identity theft.
  • One in four consumers in Germany has already been a victim of online fraud. Phishing is one of the most common methods used to obtain personal data and login credentials.
  • Phishing doesn't just affect individuals. The 2025 Bitkom study shows that, within a year, 22 percent of German companies suffered losses due to phishing attacks.
  • The consequences are often noticeable. In the 2026 Cybersecurity Monitor, 12 percent of respondents said they had already fallen victim to a phishing attack. Of those, 88 percent reported specific damages.
  • than ever. Security agencies have observed that cybercriminals are increasingly using artificial intelligence to create messages and social engineering attacks that are deceptively realistic.

Click here to view SCHUFA's identity protection solutions

Fake emails, fraudulent text messages, manipulated QR codes, or calls that sound deceptively real: Phishing is one of the most common forms of Internet fraud. The scammers’ goal is always the same: they want to get their hands on personal data, passwords, credit card information, or online banking login credentials. Their methods are constantly evolving and becoming increasingly sophisticated. In addition to traditional phishing emails, criminals today also use artificial intelligence, search engines, or phone calls to gain trust and deceive their victims. Here are the most common types of phishing scams:

1. Quishing: Phishing Using QR Codes

QR codes with traditional phishing attacks. Criminals send QR codes via email, messaging apps, and snail mail, or place them on stickers and posters. After scanning the code, victims are redirected to fake websites where they are asked to enter their login credentials, credit card information, or other sensitive data. Since the actual web address is hidden behind the QR code, many users don’t realize they’ve been scammed until it’s too late.

According to the Federal Office for Information Security (BSI), the following warning signs are typical:

  • Unerwartete QR-Codes von Banken, Behörden oder Unternehmen
  • Aufforderungen zur Eingabe von Passwörtern oder Zahlungsdaten
  • Dringende Sicherheits- oder Kontohinweise
  • Unbekannte oder ungewöhnliche Internetadressen nach dem Scan

2. Smishing: Phishing via text message

In , criminals send fraudulent text messages or instant messages. They often pose as a package delivery service, bank, or online service and claim, for example, that a delivery failed or that an account verification is required. Links in these messages direct victims to fake websites or trick them into downloading malware.

This is typical of smishing:

  • Angebliche Probleme bei Paketlieferungen
  • Warnungen vor einer Kontosperrung
  • Druck durch kurze Fristen
  • Links zu externen Webseiten
  • Aufforderungen zur Preisgabe persönlicher Daten

3. Phishing Using AI

is making phishing messages more believable than ever. With the help of AI, scammers can create messages that are grammatically correct, professionally written, and tailored to each recipient. As a result, classic red flags such as spelling or grammar errors are becoming increasingly rare.

Criminals exploit current events, well-known brands, or personal information from social media to build trust. Their goal is to get victims to disclose sensitive data or click on malicious links. The BSI points out that modern technologies make it much easier to create convincing phishing messages.

Possible warnings:

  • Unerwartete Aufforderungen zur Datenbestätigung
  • Hohe Dringlichkeit oder Zeitdruck
  • Auffallend persönliche Ansprache
  • Aufforderung zum Öffnen von Links oder Anhängen

4. Vishing: Phishing by Phone

In (voice phishing), scammers contact their victims by phone. They may pose as employees of banks, government agencies, IT service providers, or well-known companies. Their goal is to obtain confidential information such as passwords, TANs, or account details. Fraudsters often pressure their victims or claim that an account is at risk.

The following signs may indicate vishing:

  • Unerwartete Anrufe zu Konten oder Zahlungen
  • Abfrage von Passwörtern oder TANs
  • Erzeugung von Druck oder Angst
  • Aufforderung zu sofortigem Handeln

5. Whaling: Phishing Targeting Executives

is a highly targeted form of phishing. These attacks are primarily directed at executives, CEOs, or other decision-makers within a company. The scammers often research information about their targets in advance and create personalized messages.

The BSI describes targeted phishing attacks—also known as spear phishing—as requiring particularly elaborate preparation. The goal may be to steal confidential corporate information or to induce large money transfers.

Typical signs:

  • Persönlich formulierte Nachrichten
  • Vermeintliche Anfragen von Geschäftsführung oder Geschäftspartnern
  • Aufforderungen zur Weitergabe vertraulicher Daten
  • Dringende Zahlungsanweisungen

6. SEO Poisoning: Phishing via Search Engines

In , cybercriminals manipulate search engines so that fake websites appear as high as possible in search results. This leads users to fraudulent websites that imitate well-known brands, software providers, or online services.

According to the BSI, victims may download malware from these sites or enter their login credentials on fake login pages. Fraudsters frequently capitalize on current trends, popular software programs, or topics in high demand.

Here are some things to keep in mind:

  • Suchergebnisse nicht allein aufgrund einer hohen Platzierung vertrauen
  • Internetadressen sorgfältig prüfen
  • Downloads nur von offiziellen Webseiten durchführen
  • Auf Schreibfehler oder leicht veränderte Domainnamen achten

7. Classic Phishing Emails and Text Messages

The most common remains the fake email or text message. In these scams, fraudsters pose as banks, online stores, streaming services, or government agencies and ask victims to enter personal information. They often cite alleged security issues, account suspensions, or necessary verifications as reasons for doing so.

The Consumer Protection Agency regularly warns about such scams and publishes current examples in its "Phishing Radar."

Typical warning signs:

  • Dringende Handlungsaufforderungen
  • Forderung nach Passwörtern, TANs oder Zahlungsdaten
  • Verdächtige Links oder Dateianhänge
  • Ungewöhnliche Absenderadressen
  • Androhung negativer Konsequenzen bei Nichtreaktion

Stay up to date with our free identity protection newsletter and learn how to spot the nasty traps set by online scammers.

Phishing attacks are becoming increasingly sophisticated. Criminals use fake emails, text messages, QR codes, phone calls, or websites to obtain passwords, bank information, and personal details. The Federal Office for Information Security (BSI) therefore recommends that you always approach digital messages with a critical eye and follow some basic security rules. The following five tips will help you better protect yourself against phishing attacks.

Tip 1: Do not share sensitive information via email, text message, or phone

The BSI points out that reputable banks, government agencies, or companies never ask for passwords, TANs, credit card information, or other confidential login credentials via email, text message, or phone. If such information is requested, it is usually an attempt at fraud.

Tip 2: Carefully check links and web addresses

Don't click on links in emails, text messages, or instant messages without thinking. Instead, check the web address carefully or go to the website directly in your browser. The BSI recommends saving important login pages as bookmarks and accessing only those pages.

Tip 3: Be especially wary when something is urgent

Phishing messages often create a sense of urgency. Phrases such as “Act now,” “Account will be locked,” or “Final reminder” are intended to prompt recipients to respond quickly. Consumer protection agencies recommend always scrutinizing such messages and verifying any alleged claims directly with the purported sender.

Tip 4: Don't open unknown attachments or downloads

Do not open file attachments or start downloads from suspicious messages. The BSI recommends downloading software and documents exclusively from the official websites of companies or providers. Malware is often spread through fake attachments or download links.

Tip 5: Keep Your Devices and Security Software Up to Date

Up-to-date software protects against many known security vulnerabilities. The BSI recommends regularly updating operating systems, apps, and antivirus programs, and keeping existing security features—such as firewalls—enabled. This often allows phishing attacks and malware to be detected or blocked early on.

Click here for SCHUFA's identity protection solutions