mariuscomper.uk Română

Fake texts in Romania, 2026

You tapped the link. The money may leave days later.

The parcel or fine text reaches you in seconds. What happens after you tap, minute by minute and then day by day, is not what you would guess.

Which one reached you this week?
See what happens next

The story follows the digital-wallet scheme described in Google’s 2025 court complaint and by analysts. The pause and the burst come from different sources; I put them in one story so the route is visible. Other texts take another route; see below. Every screen is a simulation with invented data.

Second 0 · you

You tap the link. The page looks like theirs.

The message in the simulation is an example: short deadline, small sum. The page copies how a trusted site looks. The address can be a clue, but on a small phone screen lookalike addresses are hard to judge.

As you type · they read

They see what you type, before you press “Pay”.

Google says in its November 2025 complaint that the Lighthouse kit tracks your keystrokes as you type them. You do not have to submit the form.

Google v. Does 1–25, US federal court in New York, 12 Nov 2025, ¶82. Krebs on Security, 18 Feb 2025.

A few minutes

Your bank sends you a real code. You type it into their page.

While you wait, the complaint says, your card is added to the digital wallet (Apple or Google) of another phone. The bank sends the real code, the fake page asks you for it, and it reaches them while it is still valid.

Google v. Does 1–25, ¶¶41–46 (the complaint’s example is Google Wallet; Apple appears in Krebs on Security, 18 Feb 2025). Codes are good for only a few minutes (Krebs on Security).

Your card · on another phone

From now on the card can be used without another code.

According to the complaint, the card is ready to use on their phone without further codes.

Google v. Does 1–25, ¶46. These are Google’s allegations, not findings of a court.

Afterwards

The page says all is well. You put the phone away.

The fee on the page is the lure; the sources do not say whether it is ever charged. Nothing on your screen may look like theft, so check your bank app’s notifications too. What you do not see: another phone now holds your card.

The wait

Then, for days, nothing happens.

The analysis firm SecAlliance describes the pause between the card entering the wallet and the first fraudulent payment. In the first operations, 60–90 days. In recent ones, 2–10. A researcher at the same firm, quoted by Krebs, says “like 10 days”. Keep scrolling: it is your ordinary life.

SecAlliance, Aug 2025; Krebs on Security, 18 Feb 2025. These are analysts’ observations of smishing (SMS phishing) networks, not a controlled measurement.

Day X

Then, ten minutes.

When they start paying, they pay fast. In a case described by Norwegian broadcaster NRK (the Darcula scheme), one card was used twelve times on AliExpress within ten minutes. Only the rhythm comes from there: no amounts appear here.

NRK, “The hunt for Darcula”, 4 May 2025. The ten minutes are the length of the burst, not the time since the tap.

Why you never connect the two moments

When the money goes, the “parcel” text may already be days old.

Your statement shows payments at an online shop you never opened. It says nothing about a parcel. Two moments days apart look like two unrelated events.

What we do not know: how long it takes for you. The 2–10 days come from analysts watching Chinese smishing networks, not from a study of Romania. No source measures the time from tap to emptied account. And not every text follows this route.

If you tapped today

The calendar lays the 2–10 day range from the analyses onto your own days. It is not a forecast for your card: it is what was observed in other cases. If you entered card details or a code, official sources say to call the bank at once to block the card. Do not wait to see a payment. If you only opened the page and typed nothing, there is nothing to block.

4,975
phishing incidents reported to DNSC in 2025, 70.6% more than in 2024
71%
of the incidents DNSC assigned to an economic sector in 2025 concerned banks; post and courier, 10.8%
83%
of frauds complained about to the central bank in 2024 began with social engineering

DNSC, Annual Report 2025 (pp. 7–8, 11; read from a copy hosted by startupcafe.ro, because dnsc.ro blocks automated requests). BNR, Annual Report 2024, p. 200. These are incidents and complaints, not numbers of victims. No source I opened gives the money lost to phishing in Romania.

One device

Texts can leave from a SIM farm.

Google alleges the network sent its texts using “banks of smartphones, SIM cards, modems” (¶56). In the farm Europol describes, the average is at most about 33 cards per device: 40,000 cards across at least 1,200 devices. Europol says a SIM box can hold hundreds.

The whole factory

One farm, 40,000 cards.

Europol describes a SIM farm set up by seven Latvian nationals and stopped by arrests in October 2025: at least 1,200 devices and 40,000 SIM cards, through which more than 49 million online accounts were created. Europol writes that SIM farms underpin most online fraud operations.

Europol, IOCTA 2026, pp. 18–19. This installation is not linked to any text received in Romania.

The sites

And about 200,000 fake domains.

The firm Silent Push counted about 200,000 domains used by the Smishing Triad group, whose kit is Lighthouse, and Google’s complaint repeats the figure. Every dot on screen is one reported domain, not necessarily a live site. They appear and vanish.

Silent Push, 10 Apr 2025; Google v. Does 1–25, ¶¶6 and 108. The complaint says they were created in 20 days; Silent Push gives no period for the domains. The 20 days belong to the visits (over a million, about 50,000 a day, on part of the servers).

It is not one person with a phone. It is a subscription.

In November 2025 Google sued up to 25 unnamed defendants over a smishing kit sold by subscription. What the complaint says:

200,000
domains used by the network (Silent Push). Over a million visits in 20 days, about 50,000 a day, on part of the servers
600+
templates, imitating more than 400 institutions and firms
15 min
how often an optional kit feature asks Google whether a domain has been flagged
884,000
cards stolen in 7 months through another network, Darcula (NRK)

Google v. Does 1–25, ¶¶6, 33, 38, 108 (the site and visit figures cite Silent Push, 10 Apr 2025). NRK, 4 May 2025. “Visits” means visits to the fake pages, not victims.

And in Romania?

Among the network’s domains, Silent Push listed one that copies the Poșta Română address, posta-romanam[.]cc, next to the real one. That shows Poșta Română is a target. It does not prove a particular Lighthouse template. FAN Courier appears in 2026 warnings (DNSC via Europa Liberă, 26 Jan; Bitdefender, 12 Mar), and for fake Ghișeul.ro fines DNSC says, via Agerpres (30 Jul 2026), that the pages ask for full card details. The DNSC originals cannot be opened from outside. The kit did not disappear after the 2025 action: Silent Push told CyberScoop (14 Nov 2025) it was still tracking many sites running its code.

Not every text goes after your card

The delivery that wants your WhatsApp code

Bitdefender says more than a million people in Romania received a fake FAN Courier text asking them to pick a locker. The fake page asks for the WhatsApp verification code. With it, the attackers take over the account and ask your friends for money. No card, no bank. DNSC recorded more than four times as many account-compromise incidents in 2025 as in 2024 (1,125 against 248) and links a significant share of them to WhatsApp “vote for my daughter” messages. FAN Courier says it never asks by SMS for passwords, verification codes or WhatsApp codes.

Bitdefender, 12 Mar 2026 (the figure is the firm’s own telemetry, method not published). DNSC, Annual Report 2025, pp. 7–8. FAN Courier, warning of 11 Feb 2026.

“Mum, I’ve changed my number”

Here there is no link and no fake page. The message arrives directly on WhatsApp from a new number and quickly asks for money. Romanian police warned about it in 2025. Before you send anything, call the person on the number you know.

Romanian police warnings, 2025, as reported in the press (news.ro, România TV). I could not open the original statement.

What to do now, depending on how far you got

Where did you stop? Pick one and see what the official sources say.

You entered nothing. Stop here.

  1. Close the page. Take a screenshot of the message and the link, then delete or report the message. Do not reply or tap other links in it. If anything downloaded or you approved a request from the page, get help.
  2. If the page asked for a code (for example from WhatsApp), do not give it. FAN Courier says it never asks for one by SMS.
  3. You can report it to DNSC on 1911, open around the clock.

DNSC, Annual Report 2025, p. 29 (the 1911 line). FAN Courier, warning of 11 Feb 2026.

Call the bank now, not when you see a payment.

  1. Block the card in your bank’s app or on the number on the back of the card. Do not wait for a payment to appear: in the scheme described, days can pass between the details and the first payment, and the sooner you call the better.
  2. Tell the bank exactly what you typed into the fake page. Ask it to check and, if possible, block fraudulent transactions, and to see whether the card was added to a digital wallet on another phone.
  3. Numbers verified on official pages on 28 Sep 2026: BCR 021 311 10 01, *2227 or its fraud line 0373 514 228; ING Card Stop 021 402 85 99; CEC 021 202 69 99. For other banks, use the number in the app.

sigurantaonline.ro (DNSC, Romanian police, banking association), “What to do in case of fraud”. The BCR, ING and CEC contact pages. I could not verify the Banca Transilvania, BRD or Raiffeisen numbers.

The same call to the bank, even faster.

  1. Call the bank at once and say exactly what happened: you entered both the card details and the code sent by SMS or in the app on a fake page.
  2. Keep the evidence: screenshots of the message, the link and any conversation.
  3. Go to the nearest police station. 112 is for emergencies. The complaint needs your name, personal ID number and address. The police’s online form is only for petitions, not criminal complaints.
  4. Tell the bank about any payment you did not make, without delay. The law gives you at most 13 months.

sigurantaonline.ro; Romanian police, “Where do we go?”; BRD, “What does the bank do when you are defrauded?”; Law 209/2019, art. 169.

What matters is whether the payment was authorised.

  1. For a payment you did not authorise, the bank must refund immediately, at the latest by the end of the next business day, unless it has reasonable grounds to suspect fraud and gives its reasons in writing to the authority. The bank must prove the fraud or gross negligence. If the payment instrument was lost or someone else used it, you bear at most 30 euro, unless there was fraud or gross negligence.
  2. If you entered the code on the fake page yourself, the bank may argue that you authorised the payment or were negligent, but entering the code does not by itself settle that. Tell it exactly what happened and dispute any payment you did not knowingly approve. I found no Romanian case law on this; the outcome is decided case by case.
  3. BRD says that when the customer expressly authorised the payments, the chances of recovery are “minimal”. Still ask in writing for the payment to be examined, and keep the evidence.

Law 209/2019, arts. 171–173, 179; BRD, “What does the bank do when you are defrauded?”. That is one bank’s view, not a court’s.

Who pays, in 2026?

Today Romanian law puts on the bank the refund of unauthorised payments and the proof that the payer acted fraudulently or with gross negligence. Whether payments from a wallet count as “authorised” when the victim unknowingly helped set it up is exactly what banks and customers dispute. BRD says that where payments were expressly authorised, the chances of recovery are minimal.

On 27 November 2025 the European Union agreed a new payments regulation (PSR). The European Parliament’s press release says that when a scammer poses as an employee of your bank and tricks you into approving a payment, the bank would have to refund in full if you inform the police and the bank. A fake courier or Ghișeul.ro text is not that case. The ECON committee approved the text on 5 May 2026, and a plenary vote is indicated for 14 December 2026. It is not in force. From the agreed text I could not verify which situations it covers, how fast refunds must come or when it applies.

Law 209/2019; European Parliament press release, 27 Nov 2025; procedure file 2023/0210(COD) in the Parliament’s Legislative Observatory (checked 28 Sep 2026).

Send it to someone who does not read websites

A similar text could reach someone in your family. If they know the money does not always leave at once, they can call the bank before any payment appears. And if it does leave at once, a fast call still matters.

What we know, what we do not, and where it comes from

Documented

  • Google’s complaint of 12 November 2025 describes the sequence: keystrokes read as typed, card added to a digital wallet, confirmation code passed to the attacker, payments without a further code. These are one party’s allegations in a lawsuit, not court findings.
  • SecAlliance (Aug 2025) describes the pause before the first payment: 60–90 days at first, 2–10 days in recent operations. Another researcher says “like 10 days”.
  • Europol (IOCTA 2026) describes an installation of 1,200 SIM devices and 40,000 cards dismantled in October 2025.
  • DNSC reported 4,975 phishing incidents and 1,125 account-compromise incidents for 2025.
  • Law 209/2019 puts the refund of unauthorised payments on the bank, by the end of the next business day.

Unmeasured or unopened

  • No source measures the time from tap to emptied account. That is why the clock in the simulation shows stages, not seconds.
  • I found no official figure for money lost to phishing in Romania. The central bank publishes shares, and Eurostat last measured receiving phishing messages in 2019 (30.4% of people aged 16–74 in Romania, against 24.7% in the EU).
  • BCR describes the digital-wallet step on its fraud page: card details and the 3-D Secure code, typed into a fake page, are loaded into an Apple device. Its example starts from a fake OLX buyer, not a text. I found no Romanian bank describing it for parcel or fine texts.
  • We do not know how many of the texts in Romania take this route. What is documented is that Romanian firms and domains are imitated.
  • I found no proven Romanian case from text to emptied account to a mule account (the person whose account receives the money). I read only nearby cases, involving fake business emails.
  • I did not read the official steps for recovering a hijacked WhatsApp account, so I do not list them; if you gave the code, try to recover the account from the app and warn your contacts by another channel.
  • I could not open the original DNSC statements, because dnsc.ro blocks automated requests. Where I read copies, the text says so.

Sources

  1. Google v. Does 1–25, US District Court SDNY, 1:25-cv-09421 (complaint, 12 Nov 2025)
  2. Krebs on Security, “How Phished Data Turns into Apple, Google Wallets” (18 Feb 2025)
  3. SecAlliance, “Chinese Smishing Syndicates and Digital Wallet Fraud” (Aug 2025)
  4. Silent Push, “Smishing Triad” (10 Apr 2025)
  5. Europol, IOCTA 2026
  6. NRK, “The hunt for Darcula” (4 May 2025)
  7. Bitdefender, the FAN Courier campaign (12 Mar 2026)
  8. FAN Courier, SMiShing alert (11 Feb 2026)
  9. DNSC, Annual Activity Report 2025 (copy: startupcafe.ro)
  10. BNR, Annual Report 2024
  11. Eurostat, isoc_cisci_pb (phishing messages received, 2019)
  12. Sigurantaonline.ro, “What to do in case of fraud” (DNSC, Romanian police, banking association)
  13. Romanian police, “Where do we go?”
  14. BRD, “What does the bank do when you are defrauded?”
  15. Law 209/2019 on payment services (arts. 169–179)
  16. European Parliament, payment services deal (27 Nov 2025)
  17. European Parliament Legislative Observatory, procedure 2023/0210(COD)
  18. BCR, “The most common frauds”
  19. CyberScoop, “Lighthouse text scammers disrupted” (14 Nov 2025)
  20. Agerpres, DNSC on fake Ghișeul.ro fines (30 Jul 2026)
  21. Europa Liberă, DNSC warning about couriers (26 Jan 2026)

We use no logos or screenshots of the institutions being imitated. Every screen is a simulation with invented data; the addresses in them are invented.