← Security Awareness Hub Luxembourg / EU · Spot the scam

EU Scam Patterns

The scams hitting Europe don't look like the American ones. Here are the local lures to recognise.

Most online safety advice is written for a US audience — IRS calls, Social Security numbers, US banks. Living in Luxembourg and the Greater Region, you face a different set. These are the patterns actually circulating here.

TL;DR
  • Fake SEPA / instant-transfer tricks — "refund," "wrong payment," "verify the transfer."
  • Fake bank & fake-regulator (CSSF) messages — urgency + a link + a LuxTrust prompt.
  • Quishing — QR-code phishing on parking meters, fines, invoices (dedicated page).
  • Fake delivery & customs fees — "pay €2 to release your parcel."
  • Cross-border investment & crypto "advisors" — often the subject of CSSF warnings.

The patterns in detail

Fake SEPA / instant-transfer manipulation

SEPA instant transfers settle in seconds and don't reverse like a card chargeback — attackers love that. Variants:

  • "We refunded you by mistake, please send it back." You never received anything; they're after a real transfer from you.
  • "Confirm/verify this transfer" pages that are just credential or LuxTrust-approval harvesters.
  • Invoice redirection: a real supplier invoice intercepted and the IBAN swapped — common against small businesses.

Defence: a real transfer is irreversible — verify any "refund/return" request by calling the institution on a known number. Confirm new or changed IBANs out-of-band.

Fake bank / fake CSSF communications

Branded emails or SMS claiming "unusual activity," asking you to log in via a link and approve a LuxTrust prompt. The regulator doesn't manage your personal account; your bank doesn't ask you to confirm identity through a link. Read the LuxTrust prompt itself — it tells you what you're really approving. Full teardown in Scam of the Month.

Quishing (QR-code phishing)

Stickers over real QR codes on parking meters and fake fines; QR codes in invoices and delivery texts. → dedicated page: Quishing.

Fake delivery & customs fees

"Your parcel is held, pay a small customs fee" with a card-harvesting page. The tiny amount lowers your guard; the point is capturing the card, not the €2. Defence: track parcels only in the carrier's own app/site you navigated to yourself.

Cross-border investment & crypto schemes

Slick "advisors," fake trading platforms, romance-investment hybrids. The CSSF regularly publishes warnings naming fake entities impersonating real Luxembourg firms. Defence: check the CSSF warnings list before sending a cent.

Red flags that cut across all of them

  • Urgency and a deadline ("within 24h," "account frozen").
  • A link or QR code instead of "log in the way you normally do."
  • A request to approve a LuxTrust prompt to "confirm identity."
  • A new or changed IBAN on an invoice you were expecting.
  • A small fee that mainly serves to capture your card.

🇱🇺 In Luxembourg

  • Verify suspicious financial messages against CSSF warnings.
  • Report messages to SPAMBEE, URLs to CIRCL.
  • Money moved → bank, then plainte (Police Grand-Ducale).
  • The official orientation point is cyberfraud.lu.

If one of these got you

I've Been Hit, then the bank/card or impersonation section for your case.

Invoice-redirection and CEO-fraud variants target businesses hard in this region. Payment-verification controls are cheap compared to one redirected transfer — johlem.net.