One click, thousands of lekë: how Albanians are falling for computer fraud

It all started with a message on her phone.
Gentjana Driza was waiting for an order from TEMU on May 23 when she received a message seemingly from Albanian Post, telling her she had to pay a minimal customs fee.
The message had a link attached, which she clicked, and several forms appeared on her screen. According to her report to the police, Driza thought it was a legitimate request from Albanian Post, so she followed the instructions without thinking twice and entered her personal and banking details.
But she soon realized she had just fallen victim to a fraud.
Through the banking app on her phone, she began receiving one notification after another about transfers of considerable sums from her account. The notifications did not stop even after she contacted the bank and blocked the card.
Within three days, Driza lost around 100,000 lekë from her bank account, while the full amount remained unclear due to the dynamics of the transactions.
“I ask the competent bodies to carry out the relevant verifications and investigations to identify the person or persons responsible for this computer fraud, and to take legal measures for their criminal prosecution,” she declared to the police.
Driza is just one of hundreds of victims of digital fraud in Albania — a country recording huge growth in cyberattacks in recent years.
According to the National Authority for Cyber Security, AKSK, attacks of this nature have seen a significant increase during 2020–2026, both in volume and in their complexity.
“In recent years there has been a particular increase in attacks targeting users through psychological manipulation and online fraud, with the objective of stealing credentials, financial information or securing access to systems,” AKSK told BIRN.
The most frequent threats identified by AKSK include what are known as phishing or smishing attacks — social engineering attacks that target ordinary citizens through fake messages aimed at tricking them into sharing personal or financial data.
Not only ordinary citizens are in the crosshairs, but also public institutions and critical information infrastructures.
Since the massive cyberattacks against state infrastructure in 2022, Albania has significantly strengthened, according to AKSK, its national capacities for detecting, preventing and managing incidents in the digital sphere.
However, cybersecurity experts doubt whether the funds spent and the new structures set up have managed to minimize the risks in this regard.
“The problem is that investment is not measured by the value of tenders or the number of conferences, but by the results it produces,” said Besmir Semanaj, a cybersecurity expert.
“It is not enough to buy equipment or software. You need expertise, transparency, independent audits and above all the right people in the right positions,” he stressed.
Digital “phishing”
Institutions dealing with cyberattacks in Albania classify them into attempts and incidents, while official statistics show a huge gap between them.
According to the National Authority for Cyber Security, during 2026 over 17 million attempted cyberattacks were registered, but only a small number of them were classified as confirmed security incidents.
The data also shows a rise in phishing and smishing campaigns, reflecting global trends in cybercrime targeting individuals and organizations.
“Phishing” means one of the methods of computer crime, where fraudsters trick people into sharing personal information or downloading harmful files by pretending to be trusted sources. In a similar form, smishing represents the use of SMS messages to defraud people.
“Phishing attacks are one of the most common forms of cyber fraud and their impact can be financial, operational and reputational,” AKSK said.
The State Police also confirms that “phishing” and “smishing” attacks are now the most widespread forms of online fraud in Albania, although data on them is part of broader statistics.
The State Police told BIRN that during 2020–2026 it had referred to the Prosecution 2,316 cases of the criminal offenses of cyber fraud or cyber forgery, with 233 people arrested and 1,339 people tried while free.
“Based on cases investigated in recent years, one of the most widespread forms of computer fraud in Albania remains fraud through phishing and smishing messages or communications, where perpetrators try to deceive citizens by posing as banking institutions, service companies or personal information,” the Police declared.
According to expert Semanaj, phishing remains the main method of computer fraud in Albania, because “it is cheap and profitable”.
“You don’t need to attack a server or find some technical vulnerability; it’s enough to deceive the human,” says Semanaj, stressing that the goal is always economic.
“Either they take the money directly from the account, or they take your credentials and use them later. Today an email address, a Facebook account or bank access have value and are sold,” he added.
Semanaj considers the human factor the main problem and appeals for more education and awareness among Albanian citizens.
“Most attacks don’t start by breaking a firewall. They start because someone clicks a link, opens a document or gives a verification code. We still see people using the same password everywhere, who haven’t activated two-factor authentication and believe every message that looks ‘official’,” he said.
“Of course there are also technical problems, but even the most modern system in the world won’t save you if the user hands the keys to the attacker himself,” Semanaj added.
Beyond borders
Like many other crimes, cybercrime knows no borders. Among the thousands of cases processed in recent years, the State Police told BIRN it had also identified 89 foreign nationals accused of computer fraud or forgery in Albania.
The exchange of information for handling cases is also important for the General Prosecution, which in the same period registered 42 letters rogatory incoming from foreign authorities for the criminal offense of computer fraud. On the other hand, the General Prosecution told BIRN it had sent 300 letters rogatory to foreign authorities, highlighting the cross-border nature of part of the investigations.
The smishing fraud in the name of Albanian Post also involves a 22-year-old of French nationality named Zyad, who entered Albania like many other foreign tourists in mid-May. The court imposed the prison arrest measure on him, while another German national was declared wanted for the same fraud scheme.
Police first identified the number through which the messages were distributed in the name of Albanian Post, and then the sales point in Ksamil, where the number had been registered in the name of a German national.
However, the shop’s security cameras identified the 22-year-old Frenchman as the person who had bought the card — he was dressed sportily, with a cap on his head and headphones for listening to music.
In a second case that occurred in October 2025, two Chinese nationals are also accused of creating a fraud scheme using Albanian Post credentials again.
Cunfeng Fan, 51, and Haike Yan, 45, came to Albania last October and stayed at a hotel in the Siri Kodra area of Tirana. Through several passports they had brought with them, they are accused of buying Albanian phone numbers. Police tracked them down after an email sent by a citizen, who denounced an attempt to defraud his parents.
The whistleblower made available to investigators the phone number from which the smishing message with an Albanian Post link had been sent, and put it under surveillance. On October 31, 2025, police raided their hotel room and found, among other evidence, a list of Albanian phone numbers.
The two Chinese nationals tried to pass the blame to a third person from Cambodia, who according to them had provided the phone numbers.
The involvement of dozens of foreign nationals in digital fraud schemes in Albania makes it harder to uncover the crimes and bring perpetrators to justice. Hence for cybercrime expert Besmir Semanaj, the most efficient way to prevent them would be educating the population through awareness campaigns.
“I always say one very simple thing: don’t click links that come via SMS or email when it concerns the bank. Open the app yourself or type the bank’s address in the browser,” says Semanaj, adding: “it’s 10 seconds that can save you thousands of euros.”



Komentet
Bëhu i pari që komenton!
Lini një Koment të Ri
Për t'u përgjigjur një komenti specifik, kliko butonin 💬 Përgjigju poshtë atij komenti.