For many consumers, online fraud has long been a part of everyday digital life. The
The "Federal Cybercrime Situation Report 2025" also illustrates just how prevalent this scam is: In 2025 alone, 382,470 phishing emails were recorded. This figure makes it clear that phishing remains one of the most commonly used methods by cybercriminals.
At the same time, attack methods are changing rapidly. In addition to traditional emails, scammers now rely on QR codes, text messages, phone calls, and artificial intelligence to deceive their victims.
During the 2026 SCHUFA Protection Weeks, we’ll show you which phishing scams are particularly prevalent right now, how to spot them, and how you can effectively protect yourself against data misuse and financial loss.
- Phishing is one of the biggest threats to consumers in Germany. Nearly half of all security inquiries reported to the BSI are related to phishing, account misuse, or identity theft.
- One in four consumers in Germany has already been a victim of online fraud. Phishing is one of the most common methods used to obtain personal data and login credentials.
- Phishing doesn't just affect individuals. The 2025 Bitkom study shows that, within a year, 22 percent of German companies suffered losses due to phishing attacks.
- The consequences are often noticeable. In the 2026 Cybersecurity Monitor, 12 percent of respondents said they had already fallen victim to a phishing attack. Of those, 88 percent reported specific damages.
-
than ever. Security agencies have observed that cybercriminals are increasingly using artificial intelligence to create messages and social engineering attacks that are deceptively realistic.
Click here to view SCHUFA's identity protection solutions
Fake emails, fraudulent text messages, manipulated QR codes, or calls that sound deceptively real: Phishing is one of the most common forms of Internet fraud. The scammers’ goal is always the same: they want to get their hands on personal data, passwords, credit card information, or online banking login credentials. Their methods are constantly evolving and becoming increasingly sophisticated. In addition to traditional phishing emails, criminals today also use artificial intelligence, search engines, or phone calls to gain trust and deceive their victims. Here are the most common types of phishing scams:
1. Quishing: Phishing Using QR Codes
According to the Federal Office for Information Security (BSI), the following warning signs are typical:
- Unerwartete QR-Codes von Banken, Behörden oder Unternehmen
- Aufforderungen zur Eingabe von Passwörtern oder Zahlungsdaten
- Dringende Sicherheits- oder Kontohinweise
- Unbekannte oder ungewöhnliche Internetadressen nach dem Scan
2. Smishing: Phishing via text message
In
This is typical of smishing:
- Angebliche Probleme bei Paketlieferungen
- Warnungen vor einer Kontosperrung
- Druck durch kurze Fristen
- Links zu externen Webseiten
- Aufforderungen zur Preisgabe persönlicher Daten
3. Phishing Using AI
Criminals exploit current events, well-known brands, or personal information from social media to build trust. Their goal is to get victims to disclose sensitive data or click on malicious links. The BSI points out that modern technologies make it much easier to create convincing phishing messages.
Possible warnings:
- Unerwartete Aufforderungen zur Datenbestätigung
- Hohe Dringlichkeit oder Zeitdruck
- Auffallend persönliche Ansprache
- Aufforderung zum Öffnen von Links oder Anhängen
4. Vishing: Phishing by Phone
In
The following signs may indicate vishing:
- Unerwartete Anrufe zu Konten oder Zahlungen
- Abfrage von Passwörtern oder TANs
- Erzeugung von Druck oder Angst
- Aufforderung zu sofortigem Handeln
5. Whaling: Phishing Targeting Executives
The BSI describes targeted phishing attacks—also known as spear phishing—as requiring particularly elaborate preparation. The goal may be to steal confidential corporate information or to induce large money transfers.
Typical signs:
- Persönlich formulierte Nachrichten
- Vermeintliche Anfragen von Geschäftsführung oder Geschäftspartnern
- Aufforderungen zur Weitergabe vertraulicher Daten
- Dringende Zahlungsanweisungen
6. SEO Poisoning: Phishing via Search Engines
In
According to the BSI, victims may download malware from these sites or enter their login credentials on fake login pages. Fraudsters frequently capitalize on current trends, popular software programs, or topics in high demand.
Here are some things to keep in mind:
- Suchergebnisse nicht allein aufgrund einer hohen Platzierung vertrauen
- Internetadressen sorgfältig prüfen
- Downloads nur von offiziellen Webseiten durchführen
- Auf Schreibfehler oder leicht veränderte Domainnamen achten
7. Classic Phishing Emails and Text Messages
The most common
The Consumer Protection Agency regularly warns about such scams and publishes current examples in its "Phishing Radar."
Typical warning signs:
- Dringende Handlungsaufforderungen
- Forderung nach Passwörtern, TANs oder Zahlungsdaten
- Verdächtige Links oder Dateianhänge
- Ungewöhnliche Absenderadressen
- Androhung negativer Konsequenzen bei Nichtreaktion
Stay up to date with our free identity protection newsletter and learn how to spot the nasty traps set by online scammers.
Phishing attacks are becoming increasingly sophisticated. Criminals use fake emails, text messages, QR codes, phone calls, or websites to obtain passwords, bank information, and personal details. The Federal Office for Information Security (BSI) therefore recommends that you always approach digital messages with a critical eye and follow some basic security rules. The following five tips will help you better protect yourself against phishing attacks.
Tip 1: Do not share sensitive information via email, text message, or phone
The BSI points out that reputable banks, government agencies, or companies never ask for passwords, TANs, credit card information, or other confidential login credentials via email, text message, or phone. If such information is requested, it is usually an attempt at fraud.
Tip 2: Carefully check links and web addresses
Don't click on links in emails, text messages, or instant messages without thinking. Instead, check the web address carefully or go to the website directly in your browser. The BSI recommends saving important login pages as bookmarks and accessing only those pages.
Tip 3: Be especially wary when something is urgent
Phishing messages often create a sense of urgency. Phrases such as “Act now,” “Account will be locked,” or “Final reminder” are intended to prompt recipients to respond quickly. Consumer protection agencies recommend always scrutinizing such messages and verifying any alleged claims directly with the purported sender.
Tip 4: Don't open unknown attachments or downloads
Do not open file attachments or start downloads from suspicious messages. The BSI recommends downloading software and documents exclusively from the official websites of companies or providers. Malware is often spread through fake attachments or download links.
Tip 5: Keep Your Devices and Security Software Up to Date
Up-to-date software protects against many known security vulnerabilities. The BSI recommends regularly updating operating systems, apps, and antivirus programs, and keeping existing security features—such as firewalls—enabled. This often allows phishing attacks and malware to be detected or blocked early on.
Click here for SCHUFA's identity protection solutions