Technology

GMX and web.de Warn AI-Powered Phishing Grows as German Spam Volume Drops 45%

GMX and web.de report 45% less spam in H1 2026 but warn phishing is more targeted and AI-driven. Fake invoices, QR scams, and account takeover in Germany.

Phishing GMX web.de Cybersecurity AI Germany Email Security
GMX and web.de Warn AI-Powered Phishing Grows as German Spam Volume Drops 45% — PanoPoints

On Monday, August 10, 2026, German email providers GMX and web.de said spam volume fell roughly 45% in the first half of the year — yet warned that remaining phishing attacks are increasingly personalized and AI-assisted, drawing broad coverage across German media. Weekly suspicious mail dropped from about 1.8 billion in the prior-year period to roughly 990 million, the providers said, while the quality of fraud attempts has risen sharply.

Editor’s note: This article draws on statements reported by GMX and web.de on August 10, 2026, as covered by AFP via t-online.de, ad-hoc-news.de, and Zeit Heute, plus prior GMX newsroom security briefings on AI-generated phishing tactics in 2026.

What GMX and web.de reported

GMX and web.de — two of Germany’s largest consumer email brands, operated under United Internet — published first-half 2026 security figures showing a sharp decline in bulk spam while highlighting a shift in criminal tactics.

MetricDetail
Spam decline (H1 2026 vs. prior year)About 45%
Weekly suspicious email volumeDown from ~1.8 billion to ~990 million per week
Long-term rise (2021–end 2024)Detected spam at the two providers rose roughly 146% before the recent reversal
Trend reversalProviders say volume has fallen since summer 2025

The companies credited multi-stage filtering and industry-wide authentication standards adopted by major providers globally for making it harder to deliver mass spam at scale.

Why phishing is getting harder to spot

Despite lower overall spam volume, GMX and web.de said attackers are sending fewer identical bulk messages and more targeted, individually tailored fraud attempts. Generative AI tools help criminals produce fluent, context-aware text with fewer grammatical errors, polished layouts, and convincing urgency — making malicious mail harder to distinguish from legitimate correspondence.

The providers listed several active scam patterns:

  • Fake invoices addressed to the recipient by name
  • QR-code fraud embedded in otherwise credible-looking messages
  • Account takeover attempts against existing mailboxes
  • Business email compromise (BEC) targeting employees at specific companies

Security officials at the two brands have previously noted that AI can generate booking confirmations, payment notices, and branded graphics in seconds — often without the broken language or misaligned logos that once signaled spam.

Channels beyond the inbox

GMX and web.de said part of the threat is moving off email. Criminals increasingly use social networks, SMS, and messaging apps to reach victims with the same personalized pressure tactics. Users who feel safer ignoring obvious mass mail may still encounter convincing scams in other channels tied to the same identity data.

What users can do

The providers urged customers to treat inboxes as a key to digital identity and to layer technical defenses with everyday skepticism:

RecommendationWhy it matters
Enable two-factor authentication (2FA)Stolen passwords alone are often insufficient to hijack an account
Use a strong, unique mailbox passwordReused credentials remain a common takeover path
Question unexpected invoices and payment demandsPersonalized billing fraud is a leading AI-assisted pattern
Scrutinize QR codes from unfamiliar sendersQR scams can route victims to credential-harvesting sites
Avoid clicking links in suspicious mailVerify requests through official apps or typed URLs instead

GMX email-security leadership has also emphasized watching for artificial urgency — countdown timers, “final notice” language, or threats of cancellation — as one of the most reliable remaining warning signs when visual quality no longer gives scams away.

Broader context in Germany

The August 10 warning landed amid sustained public attention to phishing in Germany, where GMX and web.de together serve tens of millions of accounts. The headline numbers — nearly one billion suspicious messages still filtered every week — underline that “less spam” does not mean “low risk.”

Industry authentication efforts (such as stricter sender verification) appear to be squeezing high-volume campaigns, pushing criminals toward lower-volume, higher-yield social engineering. That trade-off matches wider 2025–2026 reporting from European providers and security researchers on AI lowering the cost of credible fraud at small scale.


Discussion

1. When an email looks professionally written and personally addressed, what still makes you pause before clicking a link or scanning a QR code?

2. If your email provider blocks far more spam than a year ago, does that make you more or less careful about the messages that still reach your inbox?

Share how you verify payment requests and account alerts — especially when they arrive outside email.


This article is news and general security information, not professional cybersecurity or legal advice. If you believe an account has been compromised, contact your provider and financial institutions immediately.

Discuss this topic with 8 billion people:

Opinions

Your Opinion Always Matters

Discuss, debate, and vote on hot topics.

Foresight

Foresight Builds Future Confidence

Share your method to predict the future.

CameraReal

Show Your Authentic World

Capture traceable, tamper-proof photos to restore verifiable trust in social media.