Overview
- The fraudulent email uses fake Sparkasse branding and promises a follow-up call within 48 hours to request a data update.
- One victim who entered credentials and approved transactions via pushTAN lost €49,421.44 before realizing the scam.
- A May 5 Dresden court ruling (case 8 U 1482/24) found Sparkasse partly liable for weak login authentication and ordered a €9,884.29 reimbursement plus €1,119.79 in legal costs.
- Verbraucherzentrale cautions customers to ignore unsolicited emails and confirm any account requests exclusively through Sparkasse’s official channels.
- Repeated court findings on pushTAN vulnerabilities and new branch alerts highlight ongoing gaps in Sparkasse’s online-banking security.