- Phishing emails posing as ING or Abanca exploit urgency to steal IDs, passwords and SMS codes.
- Fraudulent sites clone official banking portals to capture data and take real control of accounts.
- ING deploys tools like fraud detection, RCS, “Who is calling me?” and SOS Fraud to limit scams.
- Calmly checking senders, links and using only official channels is key to stopping these attacks.
A single email that looks like it comes from your bank can be enough for criminals to drain everything you have in your ING account in just a few minutes, especially if you click without thinking and type in whatever they ask for. These scams are designed to look familiar, urgent and absolutely credible, so that you react fast instead of stopping to double-check the details.
Right now, there are very aggressive phishing campaigns in Spain targeting customers of ING and also Abanca, using messages in Spanish that talk about restricted accounts, urgent verifications or serious problems with your contract. The goal is always the same: to scare you into a rush, make you follow a link and then collect your personal data, your login credentials and, above all, the SMS codes that protect real transactions in online banking.
How they steal everything from your ING account with just one email

The latest wave of phishing detected by cybersecurity company ESET focuses specifically on ING customers. Attackers impersonate the bank by sending emails that look like official notices about your account, your contract or some service linked to your profile. The hook is always the same: there is supposedly a problem that prevents you from operating normally and you must act immediately.
Subject lines are crafted to trigger instant panic with phrases like “your account is restricted”, “urgent verification required” or “problem detected in your contract”. The entire text of the email reinforces this sense of urgency, suggesting that your money might not be safe or that you could lose access if you do not confirm your data right away.
At first glance, the email can easily pass as genuine. The criminals copy the ING logo, imitate the colors and typography, and use a tone that sounds like typical banking communication. That is exactly why so many people click without thinking. The trick is that, if you look more closely at the header, the sender’s address and the domain of the links, you will see they have nothing to do with the official ING website.
Once you click the link, you are taken to a fake ING login page that looks almost identical to the real client area. The design, the forms and even the texts are cloned so that you believe you are on the official site. It is not just a simple imitation; the replica is good enough to fool anyone who is not paying full attention to the address bar. Avoid following unknown links and consider using a spam blocker app to reduce exposure.
On that fraudulent page, the criminals ask for several key pieces of information, step by step: first an ID such as your DNI or passport and your date of birth, then your security key, and finally the verification code that ING sends by SMS to your phone. Each screen looks like part of a legit security process, but in reality it is a funnel to collect everything they need to break into your account. Protect your phone from unwanted messages with a spam call/blocker app that also filters unsafe SMS.
Step-by-step: the phishing script used against ING and Abanca

With ING, the phishing chain usually starts with that alarming email about a blocked account or a problem with your contract. The message includes a button or link that supposedly lets you resolve the incident. When you click, you land on the fake access page, where the process unfolds in several stages that mirror real banking steps.
First, the page requests personal identification data such as DNI or passport number along with your date of birth. This alone already gives the attackers enough to start building a profile in your name, but they do not stop there. The interface reassures you by presenting these fields as a routine identity check.
Next, the system asks for your security key, the code you normally use to access the ING client area. Once you type and submit it, the phishing site quietly forwards that information to the criminals, who can then attempt to log in to the real ING platform in the background.
The final move is the most dangerous one: the fake site asks you to enter the SMS verification code sent to your phone. This code is the second factor that banks use to protect sensitive operations and logins. By capturing it in real time, the attackers can complete the login process or authorize transfers in your name on the actual ING site. Consider tools such as a call blocker app to reduce risks from malicious number-based attacks.
In the Abanca variant, the pattern is almost identical, although the fields change slightly. The fake page initially demands your NIF and PIN, which is enough to simulate an access attempt. Immediately afterwards, it prompts you to type in the SMS code that Abanca sends you. As with ING, once the attackers have that combination of credentials plus the temporary code, they effectively have direct access to your real account.
What happens when criminals get your data and SMS codes
Once the scammers collect your IDs, login data and at least one valid SMS code, they can operate in your online banking with very few obstacles. Inside your real ING or Abanca account, they can review your balances, check which products you have contracted and decide how to move the money out as fast as possible.
Typical actions include immediate transfers to mule accounts, cardless cash withdrawals or modifying security settings. All of this can be done in a matter of minutes while you are still on the fake page, thinking that you are simply verifying your profile or fixing some supposed incident with the bank.
Experts warn that these operations are increasingly automated. Cybercriminals rely on kits and platforms that allow them to set up phishing campaigns in a few clicks, even without advanced technical skills. These tools handle the cloning of websites, the collection of data and, in some cases, the real-time use of SMS codes.
For victims, the only real defence in that moment is caution. If you stop before entering any information, if you do not share the SMS code or if you manually access your bank’s app or website instead of following the link, you break the entire chain of the scam. That is why keeping a cool head when you see dramatic warnings about your accounts makes such a difference.
If you have already filled in the forms and realize afterwards that it was a fraud, you must react immediately: contact your bank through its official channels, use the emergency options in the app (such as blocking cards or accounts) and notify customer support so they can freeze operations and help you recover control.
Tips to spot fake ING emails before you click
Staying safe starts with learning to dissect every email that claims to be from your bank. Instead of reacting on autopilot, take a few seconds to look at the details that scammers usually botch or try to hide.
Always check the sender’s email address, not just the display name. Even if the name looks like “ING” or “ING España”, the real address behind it often belongs to a random domain that has nothing to do with the bank. Some criminals try to mimic the official look with subtle changes, such as extra letters, strange subdomains or misspellings. If you use different providers, check also how addresses look in services like Yahoo Mail.
Hover your mouse over any button or link to see the actual URL before you click. If the address does not clearly belong to the official ING domain that you already know and trust, do not follow it. Instead, open your browser and type the bank’s address manually or use the mobile mail app to verify if there is any real alert or pending task.
Pay attention to the tone and the level of pressure in the message. When someone insists that you must act “right now”, threatens you with immediate consequences or repeats that your money is at risk unless you click, that is a red flag. Real banks do not need to corner you or stress you out to complete a standard security check.
Read the content calmly, line by line, without rushing to click or download anything. Spelling mistakes, strange phrasing or formatting glitches can give away that you are dealing with a copy, not an official communication. Even if the text looks polished, remember that any request for passwords, full card numbers or SMS codes by email is inherently suspicious.
Phishing by email: what it is and why it still works
Email phishing is one of the oldest online scams, and yet it remains incredibly effective. The basic idea is simple: attackers send fake emails pretending to come from a trusted source so that you voluntarily hand over sensitive information such as passwords, account numbers or personal data.
To make the deception believable, criminals carefully imitate real brands, logos and design styles. Banks, schools, charities and large online retailers are frequent targets, because their names inspire trust and people are used to receiving messages from them. If the email looks familiar, your guard naturally drops.
Most phishing emails revolve around your login credentials. The message usually claims that the organization needs to verify your account details, review recent charges or confirm suspicious activity. The included link takes you to a website controlled by the criminals, which replicates the official login page in order to capture whatever you type.
Legitimate companies simply do not ask you to confirm passwords or other highly sensitive data via email or standard SMS, precisely because those channels are easy to spoof and intercept. If you receive a message that goes against this basic rule, you can safely assume it is fraudulent or, at the very least, untrustworthy.
Attackers also play the long game by using variants of phishing such as spear phishing and pharming. In spear phishing, the email is highly personalized and appears to come from within your own company or from a colleague, which makes employees more likely to share payment details or internal information. Pharming, on the other hand, silently redirects you to malicious sites even when you type the correct address into your browser, allowing hackers to capture anything you submit.
Common phishing formats you are likely to encounter
Classic email phishing remains the most visible and widespread version of the scam. The message tells you that you are a valued customer or member, then claims that a problem has been detected and encourages you to click to “restore access”, “confirm your details” or “secure your account”. Any request to type your password directly from that link should set off alarms.
Another recurring theme is the false alert about identity theft. The email may pretend to come from a fraud department or a security team, insisting that your identity has been compromised and that you must confirm personal details urgently to protect yourself. Ironically, it is by responding to this fake warning that you end up giving your real data to the criminals.
Spear phishing pushes this one step further by targeting specific employees within companies. Messages look like internal requests from HR or finance, asking for bank account numbers, tax IDs or payment confirmations. If anything about the email feels unexpected or unusual, the safest move is to confirm through another channel, such as a direct call or face-to-face conversation.
Pharming attacks are more technical and often invisible to the average user. Instead of tricking you with an email, attackers manipulate domain name resolution or your device’s configuration to send you to a fake site even when you type the correct URL. Once there, the page harvests your login details and other information as if it were the real service.
In every case, the common denominator is that the criminals rely on habit and trust. They need you to stay on autopilot, clicking and typing as you always do, so that you do not notice the small inconsistencies that betray the fraud.
How ING tries to protect you from scams and “cibergüenzas”
Beyond your own vigilance, ING has been rolling out several security tools and services designed to protect clients from fraud attempts, especially those involving transfers, SMS messages and suspicious calls. The bank refers to online scammers with a touch of humor as “cibergüenzas”, but the measures behind that branding are very serious.
One of the key protections is the internal fraud detection system for transfers. If the bank’s monitoring tools detect that a transfer you are about to make looks unusual or matches common scam patterns, you will see a warning message. That alert is there to make you pause, reconsider and, if necessary, cancel the operation before your money reaches the wrong hands.
Another pillar is the use of RCS (Rich Communication Services) instead of traditional SMS for certain communications. When available on your device, RCS allows ING to send messages from a verified profile, with a recognizable logo and clear confirmation from your mobile operator that the sender is legitimate. This makes it easier to spot fake SMS that try to mimic the bank.
The “Who is calling me?” service is specifically designed to tackle phone scams. If you receive a suspicious call from someone who claims to be ING, you can open this feature in the app, enter the phone number you are talking to and get instant confirmation of whether it really belongs to the bank or not. This tool is especially useful given the rise in fraudsters calling and pretending to be from your bank’s security team. Complement these protections with a robocall blocker app to filter suspicious numbers.
On top of that, ING offers an SOS Fraud button inside the app and web. In the “Help” section, under “Emergencies”, you can access this option if you believe your accounts or cards are at risk. By tapping it and describing what has happened, you trigger a process that allows the bank to block critical elements at once and prevent further attacks, even if it later turns out to be a false alarm.
Extra ING protections: cards, online purchases and account control
Keeping an eye on where your ING cards are stored and how they are used online is another crucial aspect of security. For that, the bank provides an e-control feature that shows you, at a glance, which merchants and subscriptions (for example, streaming services or delivery platforms) have your cards on file.
From that same interface, you can allow or block future charges from each shop or subscription. This prevents unwanted renewals, surprise payments and recurring charges you might have forgotten about. When your cards expire and are renewed, e-control can also update them automatically with merchants, avoiding manual changes in every single service.
For online purchases, ING includes an online shopping insurance that offers additional protection when you pay with the bank’s cards and the amount exceeds a certain value. If your order arrives damaged, never shows up or you receive a completely different item, you can claim reimbursement of what you paid, including packaging, shipping and taxes, provided that the policy’s conditions are met.
To use that protection, you only need to go to the movement corresponding to the purchase within your app or web, tap on the “protected purchase” banner and follow the instructions to file the claim. This adds a safety net to your online shopping and can mitigate part of the damage in case of fraud or seller issues.
For everyday operations, ING also encourages customers to enable biometric validation such as fingerprint or facial recognition to confirm sensitive actions. This not only makes the process faster, but also raises the bar for anyone trying to access your accounts without your permission, as they would need both your device and your biometric factor.
Small habits that greatly boost your banking security
Apart from all the technical tools, simple daily habits can drastically improve the safety of your ING accounts. Many of these measures take seconds to set up and then quietly protect you in the background every time you log in or make a payment.
Turning on notifications for account activity is one of the most effective steps. With alerts enabled, you will get immediate messages whenever there is a transfer, card charge or other significant movement. If something looks off, you will spot it right away and can react before the damage escalates.
Regularly changing your security key or PIN adds another layer of defence. Updating these codes from time to time makes it harder for anyone who might have seen or guessed them to use that information. Just make sure you avoid obvious combinations and do not reuse passwords from other services.
Using the discrete mode inside the ING app helps protect your privacy in public spaces. With this option, you can hide your balances and sensitive data on screen when you are surrounded by other people, preventing curious glances from learning more than they should about your finances.
If at any point you notice that your notifications have stopped arriving—for example, you are not getting validation prompts or transaction alerts—check the settings both in the ING app and on your phone’s operating system. It is possible that notifications have been disabled, or that you changed devices and the validation is still active on your old phone.
Whenever you cannot fix such issues yourself, or you suspect that something is wrong with your access, the safest move is to call ING through its official customer service numbers. Bank staff can verify that everything is in order, help you restore notifications and deactivate validation on devices you no longer use.
Training yourself to recognize scams before they hit
ING also tries to educate users through short tests and tutorials that focus on the most common fraud scenarios. These interactive resources show real-world examples of phone calls, emails, social media posts and investment offers to help you train your eye.
One of the main messages is that scammers do not only pretend to be your bank. They also impersonate delivery companies, energy suppliers, tech support or any other brand you might trust. The objective is always to get you to share card data, passwords or to grant remote access to your devices.
The bank insists that it will never ask you to install apps that are not official ING applications, never request remote access to your phone or computer, and never contact you by WhatsApp to ask for transfers or codes. If a message or call breaks any of these rules, you should treat it as a probable fraud attempt.
In the field of investments, ING highlights several classic red flags: promises of 100% guaranteed returns with zero risk, pressure to take out loans in order to invest more and websites or apps that do not clearly belong to regulated institutions. Any combination of these signs should make you back away immediately.
Finally, the bank provides content on digital wellbeing, such as podcasts and guides that explain how to develop healthier digital habits. Understanding how scams work, how quickly they can escalate and how to keep control of your data is part of that broader approach to taking care of your online life and your finances at the same time.
Staying ahead of these email scams is less about memorizing every possible trick and more about adopting a cautious mindset whenever someone claims there is a problem with your ING account, pushes you to act fast or asks you for passwords and SMS codes; by calmly checking senders and links, using only the official app or website, and relying on the security tools your bank already offers—fraud alerts, RCS messages, “Who is calling me?”, SOS Fraud and card and account controls—you put enough friction in front of the criminals to stop them from turning a single fake email into a total cleanout of your money.
Engineer. Tech, software and hardware lover and tech blogger since 2012



