Pekao warns against a new wave of cyber attacks. Check how to protect yourself

Pekao warns customers about dangerous email. Learn how to avoid data theft and secure your account.
Bank Pekao issued alarming message addressed to all its clients. Although the warning appeared at the beginning of the year, the institution reminds of a threat that still remains valid. It is about the actions of cyber criminals who are trying to extort data using false messages.
Watch out for fraudsters
Already on January 17, 2025, Pekao informed about the phishing campaign in which customers received emails regarding the alleged update of the conditions of using the bank’s services. The content of the message contains a link leading to a false side reminiscent of the official PEKAO24 website. Users, convinced of the need to act quickly, gave their login data there, which then went to the hands of fraudsters.
Cybercriminals, gaining access to accounts, could carry out operations, order transfers, and change the security settings – all without the knowledge of the account owner. The bank reminds that such attacks are based on emotions manipulation: stress, time pressure and a sense of threat.
Attempts at extortion
Other banks, including PKO BP and BNP Paribas, also recorded similar attempts. The script was similar – customers received false messages encouraging urgent action in connection with alleged changes in banking services.
Pekao advises how to protect against this type of threats. If the message raises any doubts, you should not react hastily. Instead, it is worth contacting the bank’s helpline directly. In addition, if you click on a suspicious link, make sure that the page address starts with https://www.pekao24.pl/logowania.
The bank also reminds that the authorization system never demands a full password – the user is asked to enter only selected characters. It is also important to thoroughly check the content of authorization messages before their approval.
To further increase safety, Pekao recommends activation of two -component authentication. Thanks to this, even when the login and password takes over the account, access to the account will be more difficult to get.