🛡️ netzmeldung.com
Risk: Elevated

Raiffeisen phishing email demands pushTAN activation

Category: Phishing · Published: 13/07/2026 · Last updated: 22/07/2026

Summary

What is this about? Current fraud case, reported by Watchlist Internet. See linked source for details.
Who is affected? Consumers in Germany.
How high is the risk? Elevated

Why is this warning issued?

This warning was included because it is based on a report from Watchlist Internet. It is intended to protect other users from this scam. The assessed risk is elevated.

How the scam works

  • You receive an email that appears to come from Raiffeisen Bank.
  • The email states that a new payment control system has been introduced to stop fraudulent activities.
  • You are asked to activate your pushTAN service via a link.
  • The link leads to a fake website that looks deceptively similar to the real Raiffeisen page.
  • On this page, you are asked to enter personal data and account information.
  • The criminals use this data to access your money.

How to recognise it

  • Subject line such as 'Please act now: activate pushTAN service' with time pressure
  • Request to enter personal data or account details via a link in the email
  • Claim that a new payment control system is needed due to fraudulent activities
  • The sender address may look like Raiffeisen but differs from the real domain (e.g., @raiffeisen.at)
  • Use of the bank's logos and design to appear legitimate
  • A note that the service is 'completely free' is intended to build trust
  • Impersonal greeting and time pressure
  • Link to an external login page

How to protect yourself

  • Check the sender address carefully: if the official domain is missing (e.g., @raiffeisen.at), it is fraud.
  • Do not click on links in such emails and open the banking app directly.
  • Check in your official banking app whether a similar request appears there – if not, it is phishing.
  • Never enter personal data, passwords, or access credentials via a link from an email.
  • When in doubt, call your bank or your advisor directly.
  • If you have already entered data: inform your bank immediately, have your card blocked if necessary, and file a report with the police.

What you should never do

  • Do not click on the link in the email.
  • Do not enter any personal data, passwords, or TANs on the linked page.
  • Do not respond to the time pressure – a real bank does not make threats via email.
  • Do not ignore the incident if you have already clicked or entered data.
  • Do not pay anything and do not confirm any transactions you did not initiate yourself.

Frequently asked questions

Do I have to pay something if I do not activate pushTAN?

No. pushTAN is a voluntary service. Real banks do not send threatening emails with payment demands.

What happens if I do not respond to the email?

Usually nothing happens. If your account really had a problem, your bank would contact you through other channels.

Where did the criminals get my data?

This often cannot be determined precisely. Data may come from previous data breaches, public sources, or address trading. The perpetrators often send the emails in bulk.

I have already clicked the link and entered data – what should I do?

Contact your bank immediately, describe the incident, and have cards and access blocked if necessary. File a report with the police. Stay alert, as further fraud attempts may follow.

How do I recognize a real email from my bank?

Real banks will never ask you by email to enter personal data, passwords, or TANs. When in doubt, call your bank directly or check your banking app.

Affected data

Scam type

Comments

No comments yet. Registered users can share their experiences.

Related warnings

Original source

Find more information in the original source.

Watchlist Internet ↗

Update history

  • 22/07/2026Description updated
  • 13/07/2026Warning added from an official source