Messenger Fraud: German Victims Lose Average of €1,180
German victims of messenger fraud lose an average of €1,180 – nearly double the global average. Banks are often not liable for negligence.

Record Losses from Messenger Fraud – and Banks Are Not Always Liable
German victims of messenger fraud lose an average of €1,180 per incident. This is reported by boerse-express.com citing a recent study by security company Kaspersky. The figure is nearly double the global average of €630. Particularly striking: 44 per cent of total losses occur within the first 30 minutes of initial contact.
Multi-Channel Attacks with AI Support
According to the Kaspersky investigation, attack methods are becoming increasingly sophisticated. In 65 per cent of cases, perpetrators use multiple channels simultaneously – for example, an SMS that directs to a WhatsApp conversation. 74 per cent of those affected believe the fraudulent messages were created using artificial intelligence. Data from CrowdStrike support this assessment: AI-supported attacks have increased by 89 per cent.
Legal Status: Negligence Excludes Bank Liability
Those who click on a phishing link may be left bearing the loss – as shown by a ruling from the Delhi High Court on 29 May 2026. The court ruled that a credit institution is not liable if a customer clicks on a fraudulent link despite security warnings. Negligence includes ignoring such warning notices, not just the disclosure of passwords or transaction authorisation numbers.
In Germany, legal precedent refers to similar principles. The Federal Court of Justice ruled on 5 March 2024 that banks must demonstrate that a payment was properly authorised. Section 675u of the German Civil Code, however, limits this protection: in the case of gross negligence by the customer, bank liability is excluded. The Frankfurt Higher Regional Court confirmed this on 6 December 2023 in a phishing case.
In Austria, the Payment Services Act of 2018 regulates claims for reimbursement. Legal experts emphasise that what is decisive is whether strong customer authentication was correctly applied and whether the bank fulfilled its supervision obligations.
New Attack Vectors: Kali365, NFC and Banking Trojans
The FBI has warned of a platform called "Kali365" active since April 2026 that targets Microsoft 365 environments. Victims are induced to enter a device code on a legitimate Microsoft page. The attackers gain OAuth tokens and permanent access to Outlook, Teams and OneDrive – without needing to bypass passwords and two-factor authentication.
Other threats are gaining reach:
- NFC Attacks: The number of attacks on near-field communication technology rose by 188 per cent in 2026.
- Banking Trojans: The malware "OverlayPhantom" has targeted over 180 different financial apps since May 2025.
- Botnets: The dismantled "Asocks" botnet comprised 17 million devices; authorities warn of similar networks.
Klagenfurt Resident Loses Thousands of Euros After Fake Finanz-Online Email
A 74-year-old from Klagenfurt lost several thousand euros this week after receiving a fake "Finanz-Online" email. His case illustrates how urgently swift action is needed: security experts advise reporting unauthorised transactions within 13 months. If the loss is reported immediately and there is no gross negligence, customer liability is often capped at €50.
For prevention, experts recommend blocking device code flows in corporate policies and exercising extreme caution with unsolicited messages relating to accounts.
Source: Google News AT — Crime (de)