Back to Cases
Phishing Europe 2022

The Pan-European SMS Phishing Network

A criminal network sent millions of fake delivery and banking texts across Europe, stealing millions from victims in at least 10 countries.

Several million eurosTotal Losses
Victims across 10+ European countriesVictims Affected
Europol Press Release, June 2022Source

Timeline: How It Unfolded

Throughout 2021-2022

Millions of SMS messages are sent across Europe, impersonating DHL, PostNL, La Poste, Deutsche Post, and national banks. Messages claim a package needs a customs fee or a bank account needs verification.

When links are clicked

Victims are taken to highly convincing fake websites mimicking their postal service or bank. They enter payment details or banking credentials.

Real-time theft

The criminal network uses stolen credentials in real-time. As a victim enters their banking login on the fake site, an operator immediately uses those credentials on the real bank site and drains the account.

June 2022

Europol coordinates raids across Belgium and the Netherlands. 9 suspects are arrested and 24 house searches are conducted. Servers containing stolen credentials are seized.

Investigation reveals

The network contacted victims by email, text message, and messaging apps with phishing links to bogus banking websites. Some suspects also pretended to be police or bank staff and approached older victims at their doors.

How the Scam Worked

  • The network operated like a business — with developers building fake websites, operators sending millions of texts, and "cashers" withdrawing stolen money.
  • They used SIM farms (thousands of SIM cards in automated machines) to send millions of texts cheaply.
  • Fake websites were customised per country — Dutch victims saw PostNL branding, German victims saw Deutsche Post, etc.
  • A real-time phishing panel let operators use stolen credentials immediately, before victims could realise and change passwords.
  • They also sold their tools and data to other criminals, multiplying the impact.

Red Flags That Were Missed

The texts came from unknown numbers, not official short codes used by real postal services
Customs fees and small payments were requested via credit card on external links, not through official postal service channels
The URLs didn't match official domains (e.g., postnl-betaling.com instead of postnl.nl)
The messages were generic — no tracking number, order reference, or specific package details

What You Should Learn From This

Delivery notifications with payment links are the most common SMS scam in Europe. Always track packages through the official app or website.
Real postal services handle customs fees through their own official channels, not random text links.
Check the URL carefully — the real domain is the part just before .com/.nl/.de, not the beginning of the URL.
If you receive a suspicious text, forward it to your country's scam reporting number before deleting it.
Use virtual card numbers or PayPal when making small online payments — this limits exposure if details are stolen.

Outcome

9 arrests in the June 2022 operation, with a further 8 arrests in a follow-up operation in December 2024. Europol reported that victims were based in at least 10 European countries and that economic damages amounted to several million euros. The operation highlighted how smishing networks operate as cross-border criminal enterprises.