Fraudsters are currently sending emails regarding an alleged security update for Sparkasse banking. The message creates pressure and lures recipients to a fraudulent login page.
A new phishing email using the Sparkasse name claims that an important security update is required for online banking. According to fact-checking portal “Mimikama”, the aim of the message is to direct recipients to a fake site to steal banking details or login information.
Beware of This Sparkasse Trap: Fraudsters Create Pressure
Notably, the email threatens potential suspension of online banking if the supposed activation is not carried out. The message states, according to “Mimikama”, “Without activation, your online banking will soon be suspended.” Additionally, the greeting is impersonal, and the sender does not use a Sparkasse address but one from the domain ashoj.com.
Fake ChipTAN Page: Sparkasse Customers Urged to Provide Sensitive Data
The link itself also serves as a clear warning sign: it does not lead to an official Sparkasse domain, but to an external address. There, users are prompted to enter their bank routing number or BIC/SWIFT for a supposed ChipTAN update. If you receive such an email, you should not click any links or provide any information.
Phishing Wave: Why Fraudsters are Imitating Banks More Frequently
The new Sparkasse email precisely fits the pattern warned against by the Federal Office for Information Security (BSI). It states that approximately one in three unsolicited emails contains a phishing attempt. According to personal accounts, 62% of people have consciously received such messages. The deception often involves masquerading as a reputable provider: criminals frequently pose as banks, internet providers, or other trusted entities, creating pressure with fabricated security updates, expiring cards, or threats of account suspension to lure users to convincingly recreated websites.
The BSI further emphasizes that phishing is no longer limited to emails; it can also occur via SMS, QR codes, social networks, or phone calls. Whenever a message creates haste and prompts you to enter bank data, TANs, or login credentials via a link or QR code, exercise caution. In such cases, the supposed sender should only be contacted through official channels.

