TFBank phishing page detected

A phishing campaign targeting TF Bank customers in Germany, Austria, and Scandinavia uses “security update” phishing emails and SMS to harvest login credentials and real-time OTPs. The attack, often involving fake “Meine Karte” portals, aims to steal personal data and access credit lines by mimicking legitimate brand identity Target: TF Bank Customers (Germany, Austria, Sweden, …

Fake Refund of your personal income tax (Erstattung Ihrer persönlichen Einkommensteuer) with bank phishing revealed

A phishing campaign impersonating German tax authorities (Finanzamt/ELSTER) is targeting taxpayers with fraudulent “Erstattung Ihrer persönlichen Einkommensteuer” (Income Tax Refund) emails and SMS, directing them to a fake portal designed to steal banking credentials (PINs/TANs). The attack uses a “Multi-Bank” approach, presenting a list of major German banks to intercept credentials in real-time, often using …

RWE (Rheinisch-Westfälisches Elektrizitätswerk) fake page with bank phishing detected

A phishing campaign targeting RWE AG customers in Germany uses fake energy refund emails to steal sensitive personal and financial data, including online banking credentials, via a fraudulent portal. The scam pressures users with urgent deadlines to claim a “refund for overpaid electricity costs” and directs them to malicious domains, such as kunden-rwe.net, to enter …

One Nevada Credit Union phishing page detected

A phishing campaign impersonating One Nevada Credit Union targets members via SMS and email, aiming to harvest login credentials, security answers, and sensitive personal information like SSNs through a cloned, fraudulent portal. Attackers exploit regional brand trust to create urgency around “security verification,” targeting the legitimate onenevada.org domain with sophisticated lookalike URLs. To protect against …

Banco BBVA phishing page detected

A widespread phishing campaign targeting BBVA bank customers in Spain and Latin America uses high-pressure smishing tactics to steal login credentials and SMS OTP codes. Fraudulent websites mimic the legitimate BBVA portal to intercept security codes for unauthorized transactions. Users are advised to avoid clicking links in suspicious messages and to use the official BBVA …

PayPal phishing page revealed

This phishing campaign against PayPal users utilizes fraudulent “Account Suspension” notifications to direct victims to a high-fidelity cloned site. The multi-step funnel steals user credentials, personal information, and credit card data, often employing deceptive domains and urgent demands to bypass security measures. Target: PayPal Users WorldwideThreat Level: Critical (Financial & Identity Theft)Phishing Method DescriptionThis attack …

Bank Central Asia phishing page detected

A phishing campaign targeting Bank Central Asia (BCA) customers in Indonesia uses WhatsApp-based smishing to direct victims to fraudulent sites mimicking the KlikBCA login portal. Attackers aim to harvest User IDs, PINs, and KeyBCA token codes, enabling real-time, fraudulent transaction authorization. The attack is a “Token Interception” method, utilizing spoofed domains like klikbca-update.online to bypass …

Banco CUSCATLAN phishing page detected

A phishing campaign targeting Banco Cuscatlán users in El Salvador and Guatemala uses fraudulent “digital profile update” notifications to steal netbanking credentials and OTP codes. The attack, which directs victims to a pixel-perfect replica of the legitimate site, aims to perform real-time account takeovers via deceptive domains and urgent, alarming messaging. Customers are advised to …

Bank of America phishing page revealed

A June 2025 phishing campaign targeting Bank of America users employs a “Compliance & Maintenance” pretext, claiming an “incomplete profile update” to steal credentials and bypass two-factor authentication [1]. The fraudulent site, often hosted on deceptive domains, attempts to capture online banking IDs, passcodes, email credentials, and real-time one-time passcodes (OTP). Users should be wary …