Fraudsters impersonating the DIHK/IHK via phishing emails in Germany; Fines threaten €985 for not updating data
Warning: Data Theft via Email, SMS and Phone
Warning: Data Theft via Email, SMS and Phone
Fraudsters continue to misuse the German Chamber of Commerce and Industry (IHK) as a cover for phishing attacks – most recently in connection with commercial permits through an email preceded by a phone call. Learn more about these and other criminal approaches here.
Important: The DIHK and IHKs never ask you via email, SMS, or phone for “data updates.” Under no circumstances should you click on links in such communications or disclose any data. Delete suspicious messages and, if necessary, contact us directly through our official channels to protect your company from data theft.
Since late 2022, emails have been circulating that fraudulently claim to be from the DIHK or IHK, aiming to obtain sensitive data. These emails always demand an update to company data, but under no circumstances should you click on any links or disclose data. These attempts are designed to steal information.
The DIHK promptly blocks relevant email addresses and domains whenever a new variant is reported, but this only provides short-term relief. Please remain vigilant! Scammers continue to adopt new strategies to extract data from businesses, including:
Phone call followed by an email “Legitimation”
One particularly insidious tactic involves referencing regulatory permits: potential victims first receive a phone call from a plausible-looking number. During this call, a supposed IHK employee claims that “revalidation” of an entry in a registry, such as the insurance intermediaries register managed by DIHK, requires personal data. This is followed by a convincingly crafted email with the subject “Legitimation,” requesting a “photo
copy of your ID card.” The email address used for sending and receiving appears as legitimation@XXX-ihk.info. Please do not comply with these requests as they are phishing attempts. If you are uncertain about the authenticity, contact your IHK or your responsible regulatory agency directly – do not use contact details provided within the email.
Deadline until 15 June: Update your company details in the IHK company register
Scammers behind a phishing email with a tight deadline (in June) threaten a fine of €985 for failing to “update your data in the IHK company register.” Although this phishing attempt originates from suspicious email addresses ending with the Dutch domain “.nl,” it lacks obvious errors or aggressive language. The seemingly legitimate “Chamber of Industry and Commerce (IHK), Corporate Register Department” requests a click on a “Update Data Now” button. Refrain from clicking, disclosing data, or interacting with the email in any way – simply delete it!
Final notice to update your company data
In May, a phishing email once again masqueraded as coming from an IHK sender. The email’s subject “Final notice to update your company data” claims non-compliance with obligations from § 14 GewO and HGB regulations. It impersonates a head of the “Company Data” department and demands updates to company information within a “binding 24-hour period” via a “secured portal”. The linked page is fraudulent and designed to capture data – do not click the link and delete the email immediately.
FINAL WARNING: Breach of statutory obligations – 24 hours deadline
Emails from April were signed by an alleged department head, Eva Posan, complete with a photo and a flawless intro. With the subject “FINAL WARNING: Breach of statutory obligations – 24 hours deadline,” scammers ramp up pressure. False threats, such as high administrative fines or “in-depth legal reviews,” are cited. As always, the provided link, “lhk.de
data-update” (a lowercase “l” imitating an “i”), is designed to steal your data. Do not click; delete the email immediately.
Important inquiry: Delivery method for annual financial statements
A mid-March email, more convincingly worded than usual and without errors, was sent bearing the subject “Important inquiry: Delivery method for annual financial statements.” The email requested a “prompt reply” regarding the submission method of the recipients’ financial statements. Purporting to be urgent for registration continuity, scammers threatened account suspension unless a response was provided within “three working days”. Again, any links should not be clicked, and no information should be disclosed.
Official notice regarding stored company information
The February phishing mail pressures recipients, accusing them of neglecting “data updates for 2026.” The fraudulent email leverages fake official credentials and a lowercase “l” in IHK names and URLs. Threats include “formal actions within the oversight procedure.” Delete this email and never click the malicious link.
Request to update your data
An email seemingly from “Deutsche.Handelskammer@gmx.de” falsely claimed to originate from the “Deutsche Industrie- und Handelskammer,” urging recipients to update their details using a highlighted “reference number.” Do not click the “To DIHK Service Portal” button or provide any information – this email is fake.
Status update on company data
New year, same scams: January emails with the subject “Status update on company data” claimed unfinished updates at DIHK. The domain lhk.de misleadingly linked to the scam’s data-stealing page. Delete the message and avoid all links.
Director Competition Law, Unfair Commercial Practices Law, Public Procurement Law, Corporate Crime Law | In-House Lawyer
You may also be interested in
How to Spot Phishing Emails
New phishing emails are constantly circulating. However, by knowing how to identify them and recognising their common traits, you can protect your data. Here, you’ll find out what to look out for when dealing with suspicious emails.