An SMS about a parcel waiting to be collected. An e-mail asking you to verify your bank account. A Facebook advertisement promising unclaimed ZUS benefits. Each of us has seen at least one of these messages – and it is becoming increasingly difficult to distinguish a fake from a genuine one.
According to the CERT Polska report for 2025, more than 28,000 phishing incidents using the OLX brand and more than 22,000 using Allegro were registered in the past year alone. These are not figures concerning large corporations – they are attacks aimed at ordinary internet users: buyers, sellers and people waiting for deliveries.
Below, we describe the most common schemes used by cybercriminals in Poland, as well as specific tips on how to protect yourself.
1. An SMS from "InPost" – an extra charge for a parcel you did not order
This is one of the most commonly used schemes in Poland. The victim receives an SMS stating that a parcel cannot be delivered because an additional payment is missing – usually a few zlotys. The link in the message leads to a website deceptively similar to the official InPost website or that of another courier company, where the victim is asked to provide payment card details.
The real aim is not to unlock the parcel – there is no parcel – but to intercept the card number, expiry date and CVV code. The data are then used for unauthorised transactions or sold on the black market.
Rule: InPost, DPD, DHL and Poczta Polska do not send SMS messages with payment links for additional delivery charges. Check parcel status only in the courier’s official app or by manually entering the website address in your browser – never by clicking a link in an SMS.
2. Fake investments featuring celebrities and ZUS
According to CERT Orange Polska data, fake investments accounted for as much as 68 percent of all phishing campaigns blocked by the operator in 2025. The scheme is always similar: an advertisement on social media featuring a public figure or institution (ZUS, the Ministry of Finance, a well-known businessperson) promises high returns from investments in cryptocurrencies or government programmes.
After clicking, the victim is taken to a page with a registration form. Soon, a "consultant" calls and helps to "invest" – in practice, persuading the victim to transfer money directly to the scammers. Losses range from a few to several dozen thousand zlotys.
Typical warning signs include: a promise of profit without risk, time pressure ("offer valid today only") and a phone call from an unknown person shortly after completing the form.
3. A tax refund from the "Ministry of Finance"
This campaign is particularly active around tax-return deadlines. Criminals send e-mails styled as official correspondence from the Ministry of Finance or the National Revenue Administration, informing recipients about an awaiting tax refund. The link leads to a page designed to steal electronic banking login details or full card information.
This campaign is characterised by its multi-stage process: the victim passes through several screens resembling official government websites, creating a false sense of credibility.
How to check: Information about a tax refund is available only after logging in to Your Tax Account via the podatki.gov.pl website or the e-Urząd Skarbowy app. The Ministry of Finance does not send tax-refund links by e-mail.
4. Fake bank websites – PKO BP, Peko, Santander
Cybercriminals create copies of Polish banks’ login pages that are almost visually identical to the originals. Victims usually reach them after clicking a link in an e-mail, SMS or advertisement. After entering a login and password, the page may display a message about a "temporary block" and ask for an SMS code – this is how criminals take full control of the account.
|
How to recognise a fake bank website |
What to look out for |
|
URL |
The genuine PKO BP address is pkobp.pl – a fake one may look like pko-bp.pl, pkobp-logowanie.pl or something similar |
|
SSL certificate |
A padlock in the address bar is not enough – scammers have one too. Click it and check who the certificate was issued to |
|
Request for an SMS code on the website |
A bank never asks you to enter an authorisation code directly on the login page |
|
A call from a "bank employee" |
If a "consultant" calls after you enter the website – hang up and call the bank’s official number |
5. OLX and Allegro – the "buyer scam"
The scheme known as the "OLX method" remains one of the most common forms of fraud in Poland. A seller lists an item, and an alleged buyer contacts them, wanting to pay through OLX’s secure payment system. The seller receives a link to a page where they are supposed to "collect" the transfer by entering card details. Instead of receiving money, they lose funds from their own account.
The mechanism works the opposite way to what it seems: the seller is the victim, not the buyer. The fake payment page does not charge a delivery fee – it steals card details.
Rule: OLX never sends links for collecting payments via WhatsApp, Messenger or SMS. Payments for sold items go directly to the bank account or are handled exclusively through the official OLX app.
6. What to do to avoid becoming a victim – specific steps
Check whether your data has already leaked
The Have I Been Pwned service lets you check for free whether your e-mail address has appeared in known database leaks. If so, change the password in the affected service and everywhere else you use the same password.
Do not use the same passwords in multiple places
Taking over one account should not provide access to the others. Different passwords for different services are essential – in practice, this requires a password manager, because no one can remember dozens of unique combinations.
Enable two-step verification for your bank and email
An SMS code or code from an authenticator app as the second login factor means that a password alone is no longer enough to take over the account. Most Polish banks offer this feature – check your account’s security settings.
Protect yourself on public Wi-Fi
In cafés, hotels and shopping centres, we use Wi-Fi networks available to everyone. On such a network, traffic may be monitored by other people. Using a VPN encrypts the connection, making intercepted data useless to anyone listening in – which is particularly important when logging in to a bank or shop away from home.
Report suspicious messages
You can forward a suspicious SMS directly to CERT Orange at 508 700 900 or report the incident via the form on the incydent.cert.pl website. Every report helps block fake websites and protect other users.
Summary
The schemes described above share one feature: they all create a false sense of urgency or trust. An SMS about a parcel, an e-mail from a bank, a ZUS advertisement – each of these messages is designed to trigger an immediate reaction before critical thinking kicks in.
The most effective protection is to make a habit of pausing for a moment before clicking a link and asking yourself a simple question: was I expecting this message? If not, it is better to go directly to the institution’s website or call its official number.
If you have encountered an attempted scam or would like to share your experience, visit the forum istotne.pl. More local and national news can be found in the news section.