EU Scam Patterns
The scams hitting Europe don't look like the American ones. Here are the local lures to recognise.
Most online safety advice is written for a US audience — IRS calls, Social Security numbers, US banks. Living in Luxembourg and the Greater Region, you face a different set. These are the patterns actually circulating here.
- Fake SEPA / instant-transfer tricks — "refund," "wrong payment," "verify the transfer."
- Fake bank & fake-regulator (CSSF) messages — urgency + a link + a LuxTrust prompt.
- Quishing — QR-code phishing on parking meters, fines, invoices (dedicated page).
- Fake delivery & customs fees — "pay €2 to release your parcel."
- Cross-border investment & crypto "advisors" — often the subject of CSSF warnings.
The patterns in detail
Fake SEPA / instant-transfer manipulation
SEPA instant transfers settle in seconds and don't reverse like a card chargeback — attackers love that. Variants:
- "We refunded you by mistake, please send it back." You never received anything; they're after a real transfer from you.
- "Confirm/verify this transfer" pages that are just credential or LuxTrust-approval harvesters.
- Invoice redirection: a real supplier invoice intercepted and the IBAN swapped — common against small businesses.
Defence: a real transfer is irreversible — verify any "refund/return" request by calling the institution on a known number. Confirm new or changed IBANs out-of-band.
Fake bank / fake CSSF communications
Branded emails or SMS claiming "unusual activity," asking you to log in via a link and approve a LuxTrust prompt. The regulator doesn't manage your personal account; your bank doesn't ask you to confirm identity through a link. Read the LuxTrust prompt itself — it tells you what you're really approving. Full teardown in Scam of the Month.
Quishing (QR-code phishing)
Stickers over real QR codes on parking meters and fake fines; QR codes in invoices and delivery texts. → dedicated page: Quishing.
Fake delivery & customs fees
"Your parcel is held, pay a small customs fee" with a card-harvesting page. The tiny amount lowers your guard; the point is capturing the card, not the €2. Defence: track parcels only in the carrier's own app/site you navigated to yourself.
Cross-border investment & crypto schemes
Slick "advisors," fake trading platforms, romance-investment hybrids. The CSSF regularly publishes warnings naming fake entities impersonating real Luxembourg firms. Defence: check the CSSF warnings list before sending a cent.
Red flags that cut across all of them
- Urgency and a deadline ("within 24h," "account frozen").
- A link or QR code instead of "log in the way you normally do."
- A request to approve a LuxTrust prompt to "confirm identity."
- A new or changed IBAN on an invoice you were expecting.
- A small fee that mainly serves to capture your card.
🇱🇺 In Luxembourg
- Verify suspicious financial messages against CSSF warnings.
- Report messages to SPAMBEE, URLs to CIRCL.
- Money moved → bank, then plainte (Police Grand-Ducale).
- The official orientation point is cyberfraud.lu.
If one of these got you
→ I've Been Hit, then the bank/card or impersonation section for your case.