Executive Summary: The 40% Shift

Greek media summed up the country’s 2026 fraud picture in a phrase that reads as resignation more than alarm: fraud has become a daily reality. The statistics support the framing.

Between January 2024 and August 2025, Greek police recorded 5,117 fraud cases nationwide — and 2,418 of them involved electronic means or computers, a 40% increase on the previous year. That is the central fact of Greek fraud in 2026: the absolute volume is not extraordinary by European standards, but the migration of fraud onto digital rails is happening very fast, in a country whose population skews old and whose digital banking adoption arrived late and abruptly.

The payments data tells the same story from the other end. The Bank of Greece recorded 398,723 card fraud cases in 2024, totalling €22.6 million in losses. Within that, ATM-related fraud rose only slightly in case count but surged 22% in value, while fraud at POS terminals fell by 35% — the signature of chip-and-PIN and tokenisation working at the point of sale while criminals concentrate on higher-value, harder-to-reverse channels.

The Phone Networks: Greece’s Signature Fraud

The most prevalent scam in Greece is not online at all — it is a phone call. Organised networks run scripted impersonation at scale, and the cast of characters is well documented by Greek police: a relative in trouble, a doctor calling about an accident, a utility company employee, an accountant, a bank officer, a police officer.

The pretexts follow the same logic in each case. A car accident requiring an immediate payment. An unpaid bill about to trigger disconnection. A problem with the electricity meter. A bank account under attack that must be “secured” right now. The targets are overwhelmingly elderly Greeks, and the goal is either cash — often collected in person by a courier sent to the door — or the personal data needed to take over an account.

A growing variant deserves specific attention: fake electricity payment codes. The victim is told their power is about to be cut and directed to a fraudulent payment page to settle a supposed arrear. It works because it fuses two things Greeks have genuine anxiety about after a decade of economic turbulence — utility costs and bureaucratic penalties — and because the payment page looks exactly like the real one.

This is the same in-person, high-touch model that Japan calls ore ore fraud and Spain calls the estafa del hijo en apuros. Greece’s version is unusually organised, and it survives because it targets a generation that answers the landline.

Bank Impersonation: The National Bank of Greece Wave

Greek banks have been under sustained phishing pressure through 2026. A large volume of National Bank of Greece customers reported fraudulent emails carrying subject lines engineered for compliance-anxiety — one documented example reading “Transaction Security: Third Notice for Verification.”

The “third notice” framing is a deliberate piece of psychology. It implies the victim has already missed two warnings, manufacturing both urgency and a mild sense of having done something wrong. The payload is a credential harvest aimed at online banking logins and account PIN codes — a request no Greek bank would ever make, but one that fits a customer’s mental model of “verification.”

Greece’s Ministry of Digital Governance has confirmed a broader rise in phishing email volumes nationally. The pattern matches what ACI Worldwide and other payments analysts report across Europe for 2026: consumer fraud losses growing at roughly 20% year on year, with bank transfers, real-time payments and instant credit transfers the most exploited channels. Instant payments are the structural problem. Once SEPA Instant moves the money, there is no meaningful window to recall it.

Online Fraud: Listings, Rentals, Investments

Greek authorities identify three recurring online categories.

Fake sales listings on classified and marketplace platforms — goods that don’t exist, payment taken outside the platform’s protection, seller unreachable afterward.

Rental fraud, which in Greece has a seasonal and geographic edge. Short-term holiday rental demand on the islands and long-term rental scarcity in Athens both produce desperate, fast-moving renters who will wire a deposit for a property they haven’t seen to secure it before someone else does.

Investment schemes promising quick profits, increasingly crypto-denominated and increasingly advertised through social media, following the pattern documented across Southern Europe.

Greek police describe the common vulnerability precisely: these frauds exploit the gap between a consumer’s haste and their caution. Every one of them works by compressing decision time.

The Tourist Economy

Greece hosts tens of millions of visitors a year, and tourist fraud remains a durable industry — now with a digital layer on top of the analog classics.

The persistent physical scams: taxi overcharging from ports and airports, especially with visitors who don’t know the fixed-fare routes; restaurant billing tricks, including menus without prices, “recommended” fish charged by weight at extraordinary rates, and items appearing on bills that were never ordered; and ATM skimming at standalone machines in tourist areas.

The 2026 additions: fake booking sites for accommodation, ferry tickets and archaeological site entry, and card-machine manipulation — the handheld terminal presented with an amount in the wrong currency, with a dynamic currency conversion prompt buried in a screen the customer is being rushed through, or simply with extra digits added.

Protecting Yourself

Hang up and call back on a number you look up yourself. This single habit defeats the entire Greek phone-impersonation industry. No bank, utility, police force, or hospital will object to being called back on their published number. If a caller pressures you not to hang up, that pressure is the proof.

Tell older relatives, explicitly, that no one legitimate collects cash at the door. The courier collection is the step where the money becomes unrecoverable. Agree a family code word for genuine emergencies.

No Greek bank will ever ask for your PIN — not by email, not by phone, not through a link. Reach your bank only through its official app or by typing the address yourself. Treat “verification,” “third notice,” and “account suspension” subject lines as hostile by default.

Check your electricity and utility accounts through the provider’s own portal, never through a link in a message about a disconnection.

Never pay a rental deposit for a property you or someone you trust has not physically seen, and keep short-term rental payments inside the booking platform where dispute rights exist.

At ATMs, prefer machines inside bank branches. ATM fraud value in Greece rose 22% while POS fraud fell 35% — that gap is where the criminals are working. Cover the keypad, check for anything loose on the card slot, and avoid standalone machines in heavy tourist zones.

On card terminals, read the screen before you tap. Confirm the amount and the currency. Always choose to be charged in euros, not in your home currency — dynamic currency conversion is legal but expensive, and its prompt is where extra charges hide.

Greece’s fraud problem is not exotic. It is the ordinary European problem — instant payments, credential phishing, and organised phone impersonation — running into a demographic and a digital-trust culture that had less time than most to prepare. Awareness, as the Greek police keep saying, is genuinely the first line of defence. It is also, for now, most of the line.