European Banking and Public-Sector
19 August 2026
By Samantha Clarke and the Mimecast Threat Research Team
- Multilingual credential phishing observed in German, Dutch and Danish, with impersonated organizations across Germany, the Netherlands, Denmark and Belgium
- Messages originated from compromised accounts and used Amazon S3 URLs to host or redirect to actor-controlled phishing pages
- Lures impersonated banks, government agencies, a pharmacy, a pension provider and digital identity services
- Campaign objective: online-banking credential theft, MFA interception and potential account takeover
Campaign Overview
The Mimecast Threat Research team identified credential phishing campaigns using localized German, Dutch and Danish-language lures. The messages were observed originating from compromised accounts and directed recipients through Amazon S3 web application URLs to actor-controlled phishing pages.
The campaign impersonated trusted organizations in financial services, government, healthcare, pensions and digital identity. Banking brands were prominent, including Volksbank, Consorsbank, Commerzbank, ING, DKB and Sparkasse. Other observed brands included BENU, PFA, RVO, Belastingdienst, Isabel and itsme.
One documented workflow impersonated Volksbanken Raiffeisenbanken and attempted to collect the information needed to take over an online-banking account. The page requested the victim's location and identity details, VR-NetKey or alias, online-banking PIN, authentication method and live TANs. This combination could allow an attacker to authenticate as the victim and authorize fraudulent transactions.
Campaign Flow
Stage 1: Localized Phishing Email
Recipients receive a German-, Dutch- or Danish-language phishing message. The use of a compromised sender account can make the message appear more credible than mail from newly created or obviously unrelated infrastructure.
Stage 2: Amazon S3 Link
The message directs the recipient to an Amazon S3 web application hostname. The campaign uses specific bucket hostnames for hosting or redirection, taking advantage of a legitimate cloud service to make basic reputation-only analysis less effective.
Stage 3: Brand-Impersonation Page
The victim reaches an actor-controlled page reproducing the identity and authentication journey of a regional bank or trusted service. The lure is localized to the targeted organization and country.
Stage 4: Identity and Credential Collection
The page requests personal details and account credentials. In the observed Volksbank example, this included postcode or city, first and last name, date of birth, VR-NetKey or alias, and the online-banking PIN.
Stage 5: TAN Method and Live Code Interception
The victim is asked to identify the transaction-approval method in use and provide live TAN or approval codes. Capturing both credentials and one-time authorization data can enable account access and transaction approval.
Technical Analysis
Compromised Account Delivery
The investigated messages originated from compromised accounts. Abuse of an existing account may provide a plausible sender identity and can help the campaign inherit trust associated with legitimate mail infrastructure.
Legitimate Cloud Infrastructure Abuse
A number of unique Amazon S3 hostnames were documented in the investigation. Amazon S3 is a legitimate service; the risk is associated with the specific bucket hostnames and URLs, not the amazonaws[.]com domain as a whole.
Online-Banking Data Collection
The Volksbank impersonation requested a German postcode or city to identify the victim's local branch branding, followed by identity information and online-banking credentials. VR-NetKey is the customer identifier used for Volksbanken Raiffeisenbanken online banking; an alias may be configured as an alternative login name. The requested PIN is the online-banking password.
Transaction Authentication Interception
The workflow also collected the victim's approval procedure (Freigabeverfahren) and TANs. Observed or relevant methods included VR SecureGo plus, Sm@rt-TAN photo and Sm@rt-TAN plus. A TAN (Transaktionsnummer) is a one-time value used to approve a login or payment. Collecting a live TAN alongside account credentials creates a direct path to transaction fraud.
Targets
|
Region |
Sector |
Observed impersonation |
|
Germany |
Banking |
Volksbank, Consorsbank, Commerzbank, DKB, Sparkasse |
|
Netherlands / Germany |
Banking |
ING |
|
Netherlands |
Healthcare |
BENU pharmacy |
|
Denmark |
Pensions |
PFA |
|
Netherlands |
Government |
RVO and Belastingdienst |
|
Belgium |
Business banking |
Isabel / Isabel6 |
|
Belgium / Netherlands |
Digital identity |
itsme |
Indicators of Compromise (IOCs)
The following indicators are defanged for safe handling. Indicator status may change over time and should be validated against current telemetry.
|
Indicator |
Description |
|
234-ignis-clad.s3.us-west-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
77-gp-fennel-ratchet-ridgeway.s3.us-west-1.amazonaws[.]com |
Amazon S3 campaign hostname |
|
anvil-tp-275-jolt-knack.s3.eu-west-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
baste-uniform-jt.s3.us-west-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
bolt-jab-maple-prime.s3.ap-southeast-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
brace-5834-tansy-nw.s3.ap-southeast-1.amazonaws[.]com |
Amazon S3 campaign hostname |
|
cadence-holly-whittle-lr.s3.ap-southeast-1.amazonaws[.]com |
Amazon S3 campaign hostname |
|
cf-ream-sage-supple.s3.ap-southeast-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
coarse-whittle-fk-rattan.s3.ap-southeast-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
draw-airy.s3.us-west-1.amazonaws[.]com |
Amazon S3 campaign hostname |
|
draw-tx-anchor.s3.us-west-1.amazonaws[.]com |
Amazon S3 campaign hostname |
|
drum-dusky-8837.s3.ap-southeast-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
lithe-sigil-knead.s3.ap-southeast-1.amazonaws[.]com |
Amazon S3 campaign hostname |
|
main-site-652.s3.ap-northeast-1.amazonaws[.]com |
Amazon S3 campaign hostname |
|
melt-pine-mirror.s3.ap-southeast-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
mortar-pale-mill.s3.eu-west-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
onyx-blunt.s3.ap-southeast-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
sk-optic-hammer-6m-kindle-thin.s3.us-west-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
zinnia-mold-062-jx-coarse.s3.eu-west-2.amazonaws[.]com |
Amazon S3 campaign hostname |
|
vrbank[.]site |
Actor-controlled phishing domain |
|
vrsitego[.]info |
Actor-controlled phishing domain |
|
consorb[.]info |
Actor-controlled phishing domain |
|
benu-nl[.]site |
Actor-controlled phishing domain |
Recommendations
User Awareness Training
- Educate employees to access banking, tax, pension and identity services through known websites or official applications rather than unsolicited message links
- Emphasize that users should never disclose a TAN or approve an authentication request they did not initiate
- Train users to inspect the complete destination hostname, including links hosted on otherwise legitimate cloud platforms
- Instruct users to report unexpected account-verification or transaction-approval messages immediately
Proactive Threat Hunting
- Search email logs for the listed domains and exact Amazon S3 hostnames
Conclusion
This campaign combines compromised account delivery, localized brand impersonation, and legitimate cloud infrastructure abuse to harvest financial credentials and live authorization codes. The observed Volksbank workflow goes beyond basic password theft by collecting identity information, the victim's authentication method and TANs, potentially enabling account takeover and fraudulent transactions. Security teams should prioritize IOC hunting, contextual analysis of S3 links, user reporting, and rapid response when banking credentials or approval codes may have been exposed.
Keep your edge in threat intelligence
Join thousands of security professionals who rely on our curated alerts, expert analysis, and campaign IOCs to defend against the latest cyber threats.
Sign up successful
Thank you for signing up to receive updates for our threat intelligence notifications.
We will be in touch!