"You have a new message": phishing trap in the name of easybank
Summary
Why is this warning issued?
This warning was included because it is based on a report from Watchlist Internet. It is intended to protect other users from this fraud scheme. The assessed risk is elevated.
How the scam works
- The fraudsters send an email that appears to come from easybank.
- The subject line "You have a new message" is intended to entice recipients to open it.
- The email claims that account details need to be completed due to alleged legal requirements.
- It is claimed that a document with important information is available in the personal mailbox.
- Recipients are asked to log in to their online banking via a "secure link" and carry out the required steps there.
- The link leads to a QR code. In all likelihood, online banking credentials were to be captured this way; the code has since been blocked.
How to recognise it
- The subject line "You have a new message" is impersonal and is intended to arouse curiosity.
- The email claims that account details need to be "completed" and refers to legal requirements or "KYC verification".
- The displayed sender name "EasyBank No-reply" appears legitimate, but the email was sent via a private address at the provider "hiway.at".
- This private email address is said to have been taken over by the criminals and misused for further phishing traps.
- The embedded button leads to a QR code and not directly to the official easybank website.
- The greeting "Dear customer" is impersonal and untypical for bank information emails.
- Impersonal greeting and time pressure
- Link to an external login page
How to protect yourself
- Do not open the link or button in the phishing email.
- Log in to your online banking directly via the bank's official website, not via a link from the email.
- If you have entered login details, contact your bank immediately and describe what happened.
- If possible, change your online banking password immediately.
- Monitor your account closely. Report any unusual transactions to your bank immediately.
What you should never do
- Do not click the button or link embedded in the email.
- Do not enter any online banking credentials on the page that opens.
- Do not rely on the sender name "EasyBank No-reply" alone.
- Do not wait if you have already entered your login details; contact your bank immediately.
Frequently asked questions
Do I have to make a payment?
No. The described email does not request any payment. It concerns an alleged completion of account details and, in all likelihood, online banking credentials.
How do the fraudsters know my email address?
This cannot be determined from the source text. What is known is that easybank phishing is currently being reported more frequently and that a private address at "hiway.at" has been misused for several such traps.
How can I tell whether the message is genuine?
In this specific case, the impersonal subject line, the generic greeting, the sending via a private address, and the QR code instead of the official bank website indicate a phishing attempt.
What should I do if I have entered my login details?
Contact your bank immediately, describe what happened, and, if possible, change your online banking password right away. The bank will check whether further measures, such as an account block, are necessary.
Can the QR code still be opened?
According to the source text, the QR code has since been blocked. There is still no need to click the link in the email to check your actual online banking.
Affected data
Comments
No comments yet. Registered users can share their experiences.
Related warnings
- Phishing-Mails der ÖGK jetzt auch im Dialekt
- Phishing-Welle im Namen des Finanzministeriums nutzt Familienbeihilfe als Köder
- A1-Phishing: Gefälschte E-Mails im Umlauf
- Phishing-Radar: Aktuelle Warnungen
- Phishing-Mails: Woran Sie sie erkennen und worauf Sie achten müssen
- Neue Gesundheitskarte: Betrugsversuche mit Phishing-Mails
Original source
Find more information in the original source.
Watchlist Internet ↗Update history
- 20/08/2026Description updated
- 19/08/2026Warning added from an official source