HomeSecurityGermany arrests hacker for stealing €4 million through phishing attacks

Germany arrests hacker for stealing €4 million through phishing attacks

The German Federal Criminal Police Office (BKA) yesterday raided the homes of three people suspected of orchestrating large-scale phishing campaigns that defrauded Internet users. In total, they appear to have stolen 4,000,000 euros from users.

See also: New phishing campaign targets military contractors

phishing

See also: IRS warns of increased phishing attacks via SMS

One of the three individuals, a 24-year-old German national, was arrested and charged, while the second, a 40-year-old, was also charged with 124 counts of computer fraud. Investigations into the third suspect are ongoing.

Based on data collected by the German Computer Crime Office, the phishing operations attributed to the defendants were committed between October 3, 2020, and May 29, 2021.

The three men obtained money from their victims by sending them phishing emails that were clones of messages from real German banks.

The BKA comments that the forgery was of very high quality and almost impossible to distinguish from genuine bank emails.

The emails informed recipients of upcoming changes to the bank's security system, which inevitably affected accounts .

To ensure they could continue using the bank's services, victims were asked to log in to a phishing website, thereby handing over their credentials.

Additionally, victims were asked to enter their TAN (transaction authentication number), which is a one-time code for electronic transactions, allowing hackers to access e-banking and withdraw money.

As stated in the BKA announcement, the threat actors even carried out DDoS (distributed denial of service) against banks, hoping that this would help cover up their fraudulent transactions.

Germany arrests hacker for stealing €4 million through phishing attacks

See also: Microsoft Exchange servers compromised via OAuth apps for phishing

If you receive an email claiming to be from your bank and asking you to take action to resolve a problem, do not click any of the embedded buttons or URLs.

Instead, open a new tab, use a search engine to visit the bank's official website, and log in to the customer portal to check for any alerts.

Finally, never enter account credentials before confirming that the domain you are on is the real one.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS