New Phishing Scam Uses Fake Customs Fees to Steal Credit Card Details
A sophisticated phishing scam is targeting Israelis by impersonating the postal service and using fake customs fees as bait to steal credit card information. The fraudulent messages, sent from regular mobile numbers, claim a package is held at customs and requires a small payment. A shortened link leads to a fake website that mimics the Israel Post, complete with a tracking number and logo. The site requests credit card details, including the three-digit security code.
After the victim enters their card information, a second stage of the scam unfolds. The fake website claims the payment requires verification and, in parallel, the victim receives a legitimate one-time code from their credit card company. The victim is then prompted to enter this code into the fraudulent site. Scammers, monitoring the fake page, use this code to add the stolen card to a digital wallet or authorize a larger transaction. The initial customs fee was merely a lure; the one-time code is the actual theft mechanism.
Scammers prefer adding cards to digital wallets because it allows them to make purchases immediately while the victim still possesses their physical card. Charges appear as normal transactions on the victim's statement. Therefore, a message from the credit card company about a new card being added to a digital wallet is often the first sign of a successful scam after entering a code on a suspicious page.
These scams adapt their pretexts, using fake parking tickets or electricity bill warnings, especially around holidays. Some versions even include fabricated legal justifications for the requested information. In 2025, the National Cyber Directorate's hotline handled approximately 13,700 phishing reports, a 35% increase from 2024, indicating a growing threat.
Under Israeli law, victims of such remote payment fraud, where the physical card remains with the owner, are liable for a maximum of 450 shekels. Credit card companies must refund the rest within eight business days of notification. A legal opinion from 2021 clarified that providing a one-time code to an imposter does not negate this protection, a principle enforced by the Banking Supervision Department in 2025, leading to 33 million shekels in refunds. Victims should immediately block their card, check for unauthorized digital wallet additions, save all messages, report to the National Cyber Directorate hotline (119), and change any passwords entered on suspicious sites.