Observed Signal · May 3, 2026 · Security Alert · Source: t3n · Impact: 2/5 · Sentiment: Negative

Phishing Claiming to Be Tax Office: How to Spot Fakes

Executive Signal Summary

German consumer advocates and tax authorities warn of renewed phishing campaigns impersonating the Elster tax portal. Fraudulent emails vary in sender and content—promising refunds or including fake invoices—but aim to steal login credentials, bank or card details via links to bogus security portals. Elster states it only sends notifications by email and never transmits tax data, invoices, or requests for sensitive information (tax numbers, account numbers, PINs) as attachments or via email. Consumer groups recommend marking such messages as spam, not clicking embedded links, and checking tax matters only via the official Elster website or the responsible tax office. A GMX/Web.de survey cited in the article found 64% of people experienced digital fraud attempts in the previous year, with 47% receiving phishing emails.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Phishing targeting tax-related email undermines trust in the email channel and may affect inbox security practices and ESP filtering; relevant to organizations relying on email communications though not industry-shifting.

SIGNAL RADAR

Track TargetVideo Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • German tax portal Elster reports criminals are sending phishing emails impersonating the tax administration.
  • Elster states it only sends notifications by email and will never send actual tax data, invoices, or request sensitive data (e.g., tax numbers, bank details, PINs) via email attachments or links.
  • Consumer protection group Verbraucherzentrale NRW and tax authorities warn recipients not to click embedded links and to move suspicious messages to the spam folder.
  • A GMX/Web.de survey referenced reports 64% of respondents were affected by digital fraud attempts in the past year; 47% received phishing emails, 26% reported phone scams, and 23% reported SMS fraud.
  • Similar fake Elster messages were warned about by the Lower Saxony State Criminal Police Office earlier (noting visual mimicry such as replacing an 'L' with a capital 'I').
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: May 3, 2026
Original Coverage Title: “Phishing im Namen des Finanzamts: Wie du die gefälschten E-Mails erkennst”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Email & PhishingJul 31, 2026

PayPal users targeted by 909€ phishing emails

Cybercriminals are circulating at least two PayPal-branded phishing email variants. One claims the recipient is owed a €95.66 refund and prompts users to click a link to claim it; the other alleges a €909 charge by merchant “Digistore24 GmbH” that will be debited within two days unless disputed. Both links direct to counterfeit, PayPal-styled webpages designed to harvest login credentials and personal and financial data. The messages use PayPal styling and urgency to appear legitimate, increasing the risk recipients will disclose sensitive information. Watchlist Internet reported the campaigns and t3n published a warning on 2026-07-31. Users are advised not to click links or buttons in such messages, to hover to inspect URLs, to mark suspicious emails as spam, and to verify account activity only by logging in through the official PayPal app or website.

Read assessment
IdentityApr 13, 2026

Fraudsters Exploit Deutsche Post's Postident for Loans

Reports from German consumer protection groups warn of a rising fraud scheme that abuses Deutsche Post's Postident identity-verification process. Attackers trick victims into completing Postident workflows — often by posing as banks, marketplace buyers, or via fake letters/QR-code coupons — which legally authenticate a third-party credit agreement in the victim’s name. Consumer organisations report cases with loan amounts of €20,000 or more. Because Postident verification is legally equivalent to a signature, victims find it difficult to annul resulting contracts. Authorities and consumer advice groups recommend verifying the requesting company via official channels, stopping the identification process if suspicious, informing one’s bank, and filing a police report.

Read assessment
Marketplace Fraud / Classifieds SecurityMay 31, 2026

How to Spot Fraud on Kleinanzeigen Classifieds

This t3n article explains common fraud schemes on the German classifieds portal Kleinanzeigen (part of the Adevinta group, formerly eBay Kleinanzeigen). It outlines recurring tactics used by scammers—fake payment confirmations, emotional 'pity' stories, phishing pages that mimic buyer-protection, too-good-to-be-true bargains, triangle fraud, and account takeovers—and gives practical warning signs for buyers and sellers. The piece also notes the platform's own buyer-protection service "Sicher Bezahlen" and stresses that transactions should only be trusted once funds actually appear in the recipient's account. Metadata shows the article was published on 2026-05-31 (originally published 2026-01-10).

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.