Skip to content

Current scams in October 2026: what is going around

Clone shops on .shop domains, a fake vote in a messenger, callbacks to fake bank staff and shares that do not exist: the scams police and consumer advocates warned about in September, with warning signs and next steps.

  • approx. 14 min read
  • 18 sources
A desk with a smartphone showing notifications, a bank card, a letter with a QR code and an opened parcel, a laptop with a shop page behind.

In September 2026, police, consumer advice centres and authorities in Austria and Switzerland warned about a series of new and returning scams. They involve copied shops, a fake vote in a messenger, calls from supposed bank staff and shares that cannot be bought. For each scam: what happens, how to recognise it, the source with date and the next step.

How we compile this list

We read the warnings of the German police crime prevention service (ProPK), local police headquarters, the German consumer advice centres (Verbraucherzentralen), the financial regulator BaFin, the Austrian consumer platform Watchlist Internet and the Swiss Federal Office for Cybersecurity (BACS). This edition covers warnings from 1 September to 3 October 2026. We include scams that affect consumers in Germany, Austria or Switzerland and that we could verify in the original warning. Older warnings mentioned as background carry their date. The next edition appears in early November. Scams we describe on a permanent basis are listed under Scams.

Shopping online

Clone shops on the .shop ending

Clone shops copy product texts word for word from real online shops and sometimes load images straight from the brand’s own server. On 7 September 2026 the security company nebty described a network it calls DoppelCart, with around 119,000 domains and advertised discounts of 65 percent.According to nebty, the network’s .shop domains make up 2.72 percent of all .shop domains it examined. The finding comes from a company, and we found no warning from an authority about it. The shops often list the real brand’s support address as their contact.Anyone who complains ends up with the manufacturer, who knows nothing about the order. Check the address in the shop check before you buy and compare it with the shop the brand names on its own website. More in the article Clone fake shops on .shop domains.

The ending also shows up in our own data. On 3 October 2026 we analysed the 200 most recently checked entries on our fake shop list (check dates 25 September to 3 October). 164 come from a data feed. 36 were confirmed by an automatic rule of our check.These entries have not been reviewed by hand. 89 of the 200 domains end in .shop, 79 in .com and 20 in .de. Whether they belong to DoppelCart cannot be read from the ending. A .shop address on its own is not evidence of fraud, since anyone can register the ending.

Firewood, pellets and heating oil

With the first cold days, police stations warn about fuel shops that take prepayment and never deliver. On 25 September 2026 the Aurich/Wittmund police in Lower Saxony reported several complaints, each with losses of several hundred to several thousand euros.After the purchase, the perpetrators kept in touch via WhatsApp and cited delivery problems as the reason for the delay. On 24 September the Trier police headquarters reported that such shops use the details of real companies in their legal notice, sometimes with genuine trade register entries.The Aurich police name prices well below market level and, often, prepayment as the only payment option. According to the Trier police, checking the legal notice yourself often leads to other companies or persons. Both police forces recommend paying on invoice.More in the article Firewood, pellets, heating oil: fake shops in the heating season.

Fake ticket shops for theme parks

On 30 September 2026 the Swiss police platform Cybercrimepolice warned about fake ticket shops for Europa-Park and Rulantica, a theme park and water park in south-west Germany. The sites appear through search engines, advertising and social media, look very much like the official shop and advertise discounts of up to 25 percent.Anyone who pays receives no valid tickets. Depending on the site, several amounts or higher sums are debited. There are also competitions offering supposed free tickets that collect data and lead into paid subscriptions. Buy tickets from the park’s own website or known partners.A discount on a ticket that is rarely reduced is a reason to enter the address in the shop check first.

Subscription trap via a logged-in PayPal account

On 8 September 2026 Watchlist Internet described a subscription trap under the name NordicaLab. Anyone who stays logged in to PayPal after a payment and later confirms a pop-up on a website, such as a paid personality test, takes out a subscription. The follow-up debits run without further approval.The sign is a genuine PayPal email saying “You have authorised a payment” at a time when you did not buy anything. Watchlist Internet advises logging out after every payment. If you have an unwanted subscription, cancel it in writing with the company and in your PayPal account settings, and ask PayPal for a refund.What PayPal refunds is explained under PayPal buyer protection.

Travel and accommodation

Copied hotel websites and the tourist tax email

Copies of real hotel websites collect names, email addresses, phone numbers and travel dates through an enquiry form. On 17 September 2026 Watchlist Internet reported a cluster of such sites copying hotels, family hotels among them. The signs: the domain was registered only recently, while the real hotel’s address is much older.The sites look like they were built from a template, and many texts stop mid-sentence. On 28 September an email followed that announces a refund for a tourist tax and service fee charged twice and aims at access to online banking. It contains real booking details.According to Watchlist Internet, victims report that the booking details probably come from a leak at Booking. This is not confirmed. If in doubt, call the hotel on a number you have looked up yourself. The shop check also shows you the domain age of a hotel website.

Messages on your phone

WhatsApp: a request for your vote

According to Watchlist Internet, a known contact writes something like: “Hi! Could you quickly vote for Eliska?” The link leads to a voting page that asks for your mobile number. This lets the criminals trigger the device-linking feature.If you then enter the code from the app on that page, their device is linked to your account. On 17 September 2026 the German police crime prevention service ProPK wrote that from then on the criminals can read your chats and send messages in your name.Watchlist Internet reported the scam on 16 September as the return of a trap from the previous year, and the voting page’s domain had been registered two days earlier. Never enter verification codes on a website, and check with the sender on the number you already know.How to check linked devices and recover an account is explained in the article WhatsApp voting scam and account takeover.

Bank phishing with a short deadline

The Phishing Radar of the consumer advice centre in North Rhine-Westphalia documents new emails almost every day.In late September and early October 2026 they included a supposedly expiring photoTAN app from Comdirect bank (2 October), a fake PayPal email about a new login with a 24-hour deadline (1 October), a request in the name of the Austrian bank easybank to confirm personal data “by 4 October 2026” (29 September), and a supposed refund of 478.90 euros from the AOK health insurer (25 September).In the subject line of the PayPal email, some of the letters are Cyrillic instead of Latin; we checked this in the page’s source code. All of them share a short deadline, a threat of blocking or deletion and a link for entering data. Instead of the link, open your bank’s app or the address you know.What phishing by text message looks like is shown in the article Parcel and customs text scams.

Callback fraud and the fake bank call

On 15 September 2026 the Swiss cybersecurity office BACS reported a sharp rise in callback fraud.Emails or text messages in the name of the retailer Migros, the bank UBS, the payment app TWINT or MediaMarkt claim an invoice or a suspicious debit and give a phone number, often with the Swiss area codes 021, 022, 026 or 071. On the phone the criminals ask for card details and confirmation codes or get you to install remote access software.One BACS example is a fake Migros invoice including a white wine for around 250 francs, although Migros does not sell alcohol in its stores. In Austria, Watchlist Internet warned on 10 September about a text message claiming that the recipient’s FinanzOnline ID (the Austrian tax portal login) expires today.Those who entered their data later got a call from supposed bank staff urging them to transfer money to a safe account. Never call the number from an unexpected message, use the number on your card. More in the article Callback fraud and the fake bank call.

Being told to cut up your bank card

On 8 September 2026 BACS described a variant it calls analogue skimming. After a text message, a supposed bank employee calls. The card must be destroyed immediately for security reasons, but in a way that leaves the chip intact. The cut-up card is collected, put back together and used for cash withdrawals.In one case the criminals stole more than 10,000 francs this way, and in some cases they first had the victims raise the card limit. According to BACS, they probably obtain the PIN during the call. If you are asked to do this, hang up and have the card blocked via your bank’s number.

Investments and banking

Pre-IPO shares and investment groups

On 22 September 2026 Watchlist Internet warned about a supposed Zurich financial services firm called Prime Equity Partners that offers pre-IPO shares in OpenAI by phone and email for 622 euros each.The website gives 2015 as the founding year, but the domain was only registered in June 2026. The subscription form refers to German law and Frankfurt am Main as the place of jurisdiction, although, according to Watchlist Internet, neither the provider nor OpenAI is based in Germany.In its guide on investment fraud via WhatsApp groups (as of 17 September 2026), the German consumer advice centre describes a related pattern: withdrawals fail or depend on new deposits, for example for supposed taxes or fees.Before any investment, check whether the provider is listed in BaFin’s company database, and look at the age of the domain. More in the article Investment fraud with AI videos and recovery scams.

Supposed law firms that recover money

According to the consumer advice centre, after a loss supposed law firms sometimes get in touch unprompted and promise to recover the money for an upfront fee.The consumer advice centre in Hesse had warned about this scam, also called a recovery scam, on 6 May 2026. One of its advisers said that fraudsters act deliberately and often with data they already hold about their victims. The Hesse centre calls a recently registered website a strong indication of fraud.Do not pay an upfront fee for recovery. Contact the police and your bank. What is realistically possible after a transfer is explained under Money transferred.

Verification of Payee since 9 October 2025

Since that date, all banks must check whether name and IBAN match for bank transfers. BaFin distinguishes three outcomes: the details match, they almost match and the bank shows you the registered name, or they differ and you receive a risk warning. A further case is that the check is not possible.If a payment goes to the wrong recipient and the bank carried out the check, BaFin says the bank is not liable. With fake shops, the check helps when the shop name and the account holder do not match. If the account is in the name the shop gives, the bank reports nothing.Before a transfer you can match the IBAN against reported cases in the IBAN check. More in the article Verification of Payee and fake shops.

At the front door

On 28 September 2026 ProPK warned about parcels for strangers. Criminals order expensive goods in other people’s names or to other addresses and rely on neighbours accepting them. According to ProPK, whoever signs is liable for the parcel reaching the actual recipient. Retailers and parcel services then turn to you. Signs are a recipient name nobody in the building knows and people collecting the parcel who can only vaguely identify themselves. ProPK’s advice is to refuse the parcel at the door if you do not know the recipient’s name or address, or if you are unsure.

What you can do in every case

  1. Check before you buy.

    Enter the shop address in the shop check, look it up in the warning list and match an unfamiliar IBAN in the IBAN check.

  2. Call back yourself.

    With calls, emails and messages that put you under pressure, hang up or do not reply, and call the company, the bank or the contact on a number you know yourself.

  3. Tell your bank immediately.

    If you have transferred money or entered login details, call your bank and change your login details. Deadlines per payment method are listed under Getting money back.

  4. Keep evidence and report it.

    Save screenshots, emails, chat histories and the bank statement, then file a police report. The responsible offices in Germany, Austria and Switzerland are listed under Reporting offices, the order of steps in the article Reporting a fake shop.

Frequently asked questions

Which scams are current in October 2026?

In September and early October 2026, police and consumer advocates warned about clone shops on the .shop ending, fake fuel shops, fake theme park ticket shops, a fake dance vote in messengers, bank phishing with short deadlines, callback fraud, supposed pre-IPO shares in OpenAI and parcels for strangers.

How do I recognise a clone shop?

Typical signs are big discounts on branded goods, a recently registered domain, product texts copied word for word and a support address that belongs to the real brand. Compare the address with the shop the brand names on its own website.

What do I do if my WhatsApp account has been taken over?

Warn your contacts another way, for example by text message or phone call. Recover the account by following WhatsApp’s instructions and registering again with your number, then check the linked devices. File a police report.

Does my bank ask for my PIN or one-time code on the phone?

No, say the warning bodies. According to Watchlist Internet, banks do not ask for your PIN, one-time code (TAN), password or online banking login on the phone. The Swiss Federal Office for Cybersecurity (BACS) advises never to cut up a bank card on the instruction of an unknown person. Hang up and call the number on your card.

Can a law firm recover my lost money for a fee?

According to consumer advice centres, offers promising recovery for an upfront fee are often the next scam. Do not pay an upfront fee. Contact your bank and the police, and check the age of the website and the company’s trade register entry.

Unsure about a shop?

Enter the address. You get the verdict with a reason for every feature checked.

Check shop

Keep reading

Note

The articles serve to inform and are researched with AI support. Individual cases may differ. For a legal assessment, contact your consumer advice centre or a qualified lawyer.