Home / World Scam / EU cyber agency flags Chinese-linked smishing gang targeting Ireland as scams surge
EU cyber agency flags Chinese-linked smishing gang targeting Ireland as scams surge
A new EU cybersecurity assessment identifies Ireland as a primary target for an organised smishing operation, underscoring growing mobile text fraud and rising ransomware exposure that authorities and banks say is costing Irish households and businesses millions.
By Sophie Redford · Published September 27, 2026 at 9:05 PM · Updated September 27, 2026 at 9:17 PM
Authorities warn that organised smishing campaigns are increasingly targeting Irish mobile users.
Ireland has been singled out by European cybersecurity authorities as one of five member states notably targeted in 2025 by a large scale, Chinese linked smishing operation, a development that Irish police and financial regulators say is helping drive a fresh wave of mobile text message scams across the country. The finding appears in the European Union Agency for Cybersecurity annual Threat Landscape analysis for 2026, which examined thousands of incidents across the bloc and identified an organised criminal cluster known as Smishing Triad as a major purveyor of so called smishing campaigns. Smishing involves fraudulent SMS or messaging app texts that impersonate trusted organisations, lure recipients to click on a link, and harvest bank credentials, one time passwords, or payment card details. Security analysts who track the group say the operation uses professionally produced phishing kits and constantly rotated domains to scale attacks. Technical reporting from specialist cybersecurity firms shows the gang stages high volume campaigns that can switch victims in real time between credential collection, card capture and one time password interception, making the scams unusually effective at converting a single click into an immediate theft. Why Ireland is in the crosshairs The EU assessment lists Ireland alongside France, Poland, Germany and Lithuania as countries that experienced notably concentrated activity from Smishing Triad during 2025. Analysts point to a combination of factors that makes Ireland attractive to the operators: a high level of digital banking adoption, widespread use of one time passwords for authentication, and an economy where international corporate and financial services connectivity yields plentiful spoofing opportunities. The ENISA report also places Ireland in the upper half of member states for ransomware incidents reported in 2025, raising concerns that financially motivated cybercrime is shifting between extortion and direct theft channels. Security researchers say the same criminal ecosystems behind smishing often supply access data and proceeds to ransomware actors, creating a pipeline from consumer fraud to larger scale enterprise attacks. What investigators and banks are saying While the European report provides the regional picture, Irish authorities and financial institutions have been issuing warnings and taking action locally. National policing units focused on economic and cyber crime are increasingly emphasising public education on smishing techniques and pressing banks and mobile operators to improve detection and block malicious links. Separately, the national financial regulator has published warning notices in recent weeks about unauthorised investment platforms and cloned firms operating to extract money from consumers, part of a broader pattern in which fraudsters combine mobile messaging with fake investment websites and social media impersonation. Bank fraud teams have reported sizeable individual losses to investment and payment scams in recent months, and industry statements note that criminals are encouraging rapid transfers to cryptocurrency wallets or nonrecoverable payment rails to frustrate recovery. That tactic is a common next step after initial credential capture via smishing links. How the scams work, and why they succeed Analysts who have examined Smishing Triad activity say the messaging normally impersonates banks, delivery companies, or government services, and often refers to urgent matters such as blocked payments, missed parcels, or verification requests. Victims are directed to compact mobile webpages that mirror legitimate login flows and request card numbers or one time passcodes. More sophisticated kits observed in technical research allow operators to alter the capture screens on the fly, so if a victim provides a card number the attacker can immediately request a one time password, catching the account owner while they are still authenticating. Because the initial contact arrives over SMS, victims often assume the message is legitimate and respond without the delay or verification steps they might apply to email. What citizens and businesses should do now Authorities and cybersecurity experts recommend simple but effective steps: never click on links in unexpected texts; verify messages by calling official numbers obtained independently from a bank or delivery firm website; do not share one time passwords, PINs or full card details with anyone who contacts you; and report suspected smishing messages to your bank and to the national fraud-reporting services. Businesses should tighten multifactor authentication methods where possible, favour app based authenticators over SMS based one time passwords, and ensure staff are trained to recognise social engineering attempts that can become the entry point to larger intrusions. Why this matters Smishing campaigns are not merely nuisance crimes, they are a high volume revenue stream for organised cybercriminal networks that feed money into broader criminal supply chains, including money laundering and ransomware. The scale and automation used by Smishing Triad, combined with technical advances in phishing kits, means individual victims can be depleted quickly and at scale, and recovery of stolen funds becomes far more difficult once payments have been moved to opaque channels. The EU agency assessment, and the follow up technical reports from private security firms, underline that Ireland is not an isolated target but part of a cross border problem. The message from regulators, banks and police is that improvements to public awareness, stronger authentication and faster information sharing between industry and law enforcement are essential to reduce the success rate of these campaigns. For now, the safest course for people who receive urgent looking texts is to stop, check, and use an independently verified phone number or official website to confirm whether the message is genuine.
Sophie Redford is a journalist and contributor at QuantumNova covering a diverse range of stories and topics. Her work focuses on accurate, accessible reporting supported by credible information and relevant context.
U.S. law enforcement actions and Treasury designations targeting an international fundraising network accused of routing millions to Hamas have renewed scrutiny on how illicit finance sustains violence affecting Israel. Authorities say the scheme collected and laundered donations, including after the October 7, 2023 attacks on Israel, prompting coordinated arrests and sanctions across jurisdictions.
The Central Bank of Ireland and the Competition and Consumer Protection Commission flagged a wave of unauthorised firms and sophisticated investment frauds targeting Irish savers, urging immediate caution and new reporting steps as payment and crypto-related losses rise.
After a surge of complaints alleging fake utility messages, malicious apps and video-call 'digital arrest' extortion, Lucknow police this week launched a monthlong public awareness and intervention campaign to stop losses, recover funds and disrupt mule networks.
A small Canadian medical clinic was listed on the Booba Project extortion crew’s leak site today, part of a wider burst of claims that security trackers say target several health organisations across North America. Cybersecurity researchers warn the pattern raises real risks for victims and could foreshadow follow up data dumps or ransom demands.