Criminals are sending sophisticated phishing emails to customers of Germany’s Sparkasse and DKB banks, posing as security updates to steal login credentials. Here is how to recognise the scam and protect your account.
Two of Germany’s most widely used banking institutions are under attack simultaneously. Customers of the Sparkasse savings bank network and the DKB, Deutsche Kreditbank, are being targeted by a coordinated wave of phishing emails crafted with a level of sophistication that consumer protection groups are describing as increasingly difficult to distinguish from genuine bank communications. The campaigns arrived within 24 hours of each other in mid-July 2026, with anti-fraud monitoring organisation Mimikama and Germany’s Verbraucherzentrale both issuing urgent public warnings within days of each other.
The timing is deliberate. Summer holidays generate higher volumes of casual, distracted digital behaviour, making banking customers measurably more vulnerable to fast-moving fraud attempts that rely on urgency and inattention.
The Sparkasse Attack: Fake ChipTAN Update and a Frozen Account Threat
Criminals are currently sending emails in the name of the Sparkasse. The mail warns of a suspension of online banking, but behind it is phishing.
The Sparkasse phishing campaign, first documented on July 24, 2026, takes a format designed specifically to look like an urgent security communication from the bank. The fraudulent message carries the appearance of an official Sparkasse communication. It states that the authentication method for online banking has been updated “for security reasons”. Users are told they must now activate a new release in the banking app. Otherwise, online banking could “soon be suspended”.
The technical hook is a fake ChipTAN update request. A button with the instruction “Activate authentication now” leads to a suspicious website. According to Mimikama, this site is already classified as risky, malicious, and as a phishing site. This is followed by fake verification pages, including a supposed authenticity check with Captcha. A supposed ChipTAN update is then displayed, during which users are asked to enter their bank sort code or BIC/SWIFT.
ChipTAN is one of the most trusted transaction authentication systems used by German banks, making the choice to imitate it particularly cynical. By mimicking a process that Sparkasse customers associate with genuine, high-security banking operations, the criminals are exploiting existing trust to extract the very credentials that would allow them to drain accounts.
On July 10, 2026, a similar warning had circulated for Sparkasse customers. The scheme was almost identical: allegedly, a “critical update” for the S-pushTAN app was required. The emails came from dubious sender addresses, contained no personal salutation, and threatened account suspension.
The DKB Attack: App Registration Expiry and Re-Authentication Trap
The DKB campaign, which preceded the Sparkasse wave by two weeks, used a slightly different technical pretext but the same underlying psychological architecture.
Criminals are sending emails to customers of the bank with the subject line “Your DKB app registration expires on July 15, 2026.” Customers are urged to act quickly or they will lose access to their account.
The fraudulent emails play on time pressure. Recipients are asked to complete an alleged “re-authentication process” to avoid losing access to their accounts. But anyone who clicks the link does not land on the real DKB site but on a deceptively similar phishing website. Anyone who enters their access data there sends it directly to the fraudsters.
A current phishing email claims that the DKB customer’s online banking profile has been deactivated “for security reasons”. To continue using the bank’s services and avoid account closure, customers are asked to confirm their data “immediately” via a link. Typical of such fraud attempts are keywords such as “unauthorised account use” or “money laundering”, which are deliberately designed to cause alarm. Additionally, restricted access is threatened.
Earlier in the year, a separate DKB campaign used the subject line “Security check: phone verification pending,” in which customers were asked to confirm their telephone number, supposedly to protect their account. The email looks deceptively genuine at first glance but reveals itself on closer inspection through typical characteristics: impersonal salutation, dubious sender address, embedded link, and the threat of account restriction.
Attacks on DKB customers have risen massively in 2024, 2025 and 2026. The fraud schemes are becoming increasingly professional and are barely distinguishable from genuine messages.
Why These Campaigns Are So Effective
The sophistication of the current phishing wave reflects a broader and deeply concerning trend in financial cybercrime across Europe. Industry figures show that around 94 percent of financial institutions have recorded an increase in phishing attempts. Particularly alarming: only 28 percent of current two-factor authentication methods are considered genuinely phishing-resistant.
The campaigns targeting Sparkasse and DKB customers exploit several well-documented psychological vulnerabilities simultaneously. The threat of account suspension creates immediate fear. The artificial deadline generates urgency that overrides careful thinking. The use of familiar branding, including the Sparkasse’s red logo, the DKB’s corporate colours, and technical terminology like ChipTAN and S-pushTAN, creates an appearance of legitimacy that convinces recipients to proceed before they have paused to examine the email carefully.
Since April 2026, alongside classic email attacks, there has also been a marked increase in additional phishing channels. QR code phishing, known as quishing, has emerged as a particularly insidious variant in which a fraudulent QR code embedded in an email bypasses many traditional spam filters, since the link itself is embedded in an image rather than appearing as a clickable URL. Voice phishing, or vishing, involves actual phone calls from individuals claiming to be bank security staff. SMS phishing, or smishing, mirrors the email campaigns but arrives via text message, which many recipients treat as inherently more trustworthy than email.
How to Identify the Fake Emails
Both the Sparkasse and DKB campaigns share a consistent set of identifiable red flags that, once known, make the fraud relatively straightforward to detect.
The sender address is the first and most reliable indicator. The sender does not use an official Sparkasse address but a foreign domain. Genuine communications from Sparkasse institutions arrive from addresses ending in the official domain of the customer’s local savings bank. Genuine DKB communications arrive from addresses ending in dkb.de. Any variation from these exact domain patterns, including addresses that look similar but contain additional characters, hyphens, or entirely different domain endings, indicates fraud.
The absence of a personal salutation is the second major warning sign. The mail contains no personal salutation and mentions no customer data. Genuine bank communications address customers by name and typically reference at least partial account information. An email that opens with “Dear customer” or “Dear account holder” without a name is not from your bank.
The nature of the request itself should trigger immediate scepticism. Reputable banks do not ask their customers to enter access data, TANs, or app approvals via a link in an email. No German bank will ever send an email asking you to click through to a website and enter your full login credentials, TAN codes, ChipTAN numbers, or app release codes. This category of request does not exist in legitimate banking communication.
The destination link is the fourth indicator. The URL visible when hovering over the button or link in the email will not end in the genuine bank’s domain. The link does not lead to an official Sparkasse domain. The target page is classified as dangerous and as phishing.
What to Do If You Receive One of These Emails
The response to receiving a phishing email is straightforward and requires no technical expertise.
Do not click any links or buttons in the message. Do not enter any data on any website reached through a link in an unsolicited email. Do not call any phone numbers listed in the email, as these will connect you to the fraudsters rather than your bank.
Check your account exclusively via the official Sparkasse app or via the internet address of your Sparkasse that you already know. The same principle applies to DKB customers: access your account only through the official DKB app or by typing dkb.de directly into your browser. Never navigate to your bank through a link provided in any email, regardless of how legitimate that email appears.
Forward the suspicious email to your bank’s official fraud reporting address and then delete it. The Sparkasse network has a dedicated phishing reporting channel, and the DKB maintains a security contact address for exactly this purpose.
What to Do If You Have Already Clicked or Entered Data
Speed is critical. Anyone who has already entered data or granted approval should immediately contact their Sparkasse and have the online banking access blocked. In such cases, every minute counts.
Call your bank’s emergency number immediately. Every German bank maintains a 24-hour hotline for blocking compromised accounts. The national emergency number for blocking German bank accounts is 116 116, available around the clock.
After blocking the account, file a criminal complaint, notify the DKB or your savings bank in writing, and document everything: the email, the website address you were directed to, and any transactions that occurred after the data was entered.
German banking law provides important protections for phishing victims. As a phishing victim, you have a claim for reimbursement against the DKB under Section 675u of the German Civil Code. Current court rulings, including from the Kammergericht Berlin, confirm that the bank is obliged to compensate in cases where the customer was not grossly negligent. Banks frequently attempt to refuse reimbursement by alleging gross negligence on the customer’s part, but courts have repeatedly found against this position where customers have fallen victim to sophisticated phishing campaigns. Document your case carefully and consider seeking legal advice if your bank refuses to reimburse unauthorised transactions.
Protecting Yourself Going Forward
Several straightforward measures significantly reduce phishing risk.
Enable two-factor authentication on all banking accounts if you have not already done so, and use an authenticator app rather than SMS-based verification wherever possible, since SMS codes can be intercepted in more sophisticated attacks.
Never access banking services through links in emails, regardless of the apparent source. Always open your bank’s website by typing the address directly into your browser, or use the official app installed directly from the App Store or Google Play.
Consider enabling transaction notifications so that any unauthorised activity triggers an immediate alert to your phone. Many German banks allow customers to set spending limits and geographic restrictions on their accounts through their app settings, which can contain the damage if credentials are ever compromised.
Anti-phishing tools built into modern browsers and email clients catch a significant proportion of known phishing campaigns, but they are not infallible. The most reliable protection remains human scepticism: if an email creates urgency, threatens account suspension, or asks you to click a link to enter login credentials, it is almost certainly fraudulent.
Related Articles:


