German pension-phishing impersonating the Deutsche Rentenversicherung (DRV-Bund + 14 regional bodies). Targets ~57M German pensioners + contributors. German-language panic hook: "Rentenbescheid," "Rentenanpassung," "drohende Rentenkürzung," "Rentenauszahlung ist gefährdet," "Rentenkonto überprüfen," "Sozialversicherungsnummer bestätigen" + credential-harvesting link on a non-DRV host (legit DRV only uses deutsche-rentenversicherung.de / rentenversicherung.de / drv-bund.de). Age-demographic weapon: retirees receiving monthly pension payments click panic narratives faster than younger cohorts. Evidence: DRV-Bund official Phishing-Warnungen page; BSI CS-Warnungen 2026; Heise + Spiegel + Süddeutsche Zeitung Feb 2026 coverage; Verbraucherzentrale + Stiftung Warentest senior-fraud advisories. Closes the non-English regional-coverage set (Spanish LATAM + Japanese + Brazilian + German)
drv-rentenversicherung-german-pension-phishing
What this tier means
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
How Gorganizer detects this
German-language phishing that impersonates the Deutsche Rentenversicherung (DRV) — Germany's federal pension insurance body, which covers approximately 57 million active contributors and retirees. The attack surface covers the umbrella DRV-Bund plus the 14 regional bodies (Nord, Mitteldeutschland, Rheinland, Baden-Württemberg, Bayern Süd, Bayern Nord, Braunschweig-Hannover, Berlin-Brandenburg, Westfalen, Schwaben, Saarland, Hessen, Oldenburg-Bremen, Rheinland-Pfalz). The signal fires on a DRV brand mention + a German-language pension-specific panic hook ("Rentenbescheid," "Rentenanpassung," "drohende Rentenkürzung," "Rentenauszahlung ist gefährdet," "Überprüfung Ihres Rentenkontos," "Sozialversicherungsnummer bestätigen," "drohender Zahlungsstopp," "Rentenkonto ist gesperrt," "Beitragszeiten") + a credential-harvesting link on a host that is NOT deutsche-rentenversicherung.de / rentenversicherung.de / drv-bund.de. Primary victim demographic: retirees receiving monthly pension payments, who historically click panic narratives about pension reduction or suspension at much higher rates than younger cohorts — the age profile makes this attack uniquely lucrative for the fraudsters. Evidence: the DRV-Bund publishes an ongoing "Phishing-Warnungen" page documenting current campaigns; the BSI (Bundesamt für Sicherheit in der Informationstechnik) issued CS-Warnungen throughout 2026 about DRV impersonation waves; Heise, Spiegel, and Süddeutsche Zeitung covered a February 2026 wave targeting pensioners; Verbraucherzentrale and Stiftung Warentest publish senior-fraud advisories specifically calling out the DRV-impersonation pattern. Distinct from generic SSN / tax phishing because the Deutsche-Rentenversicherung + Rentenbescheid combination is uniquely German — Switzerland uses AHV (Alters- und Hinterlassenenversicherung), Austria uses PVA (Pensionsversicherungsanstalt), and no English-language pension phishing uses the specific German compound-noun pension phrasing (Rentenbescheid, Rentenanpassung, Rentenkürzung). This iter closes the engine's non-English regional-coverage set: Spanish/Portuguese LATAM (iter 1059 Casbaneiro), Japanese (iter 1063 Yamato/Sagawa), Brazilian (iter 1067 PIX/boleto), and now German. Warning signs: any German-language email claiming a pension matter where the sign-in link is hosted anywhere other than the three official DRV domains. Go directly to deutsche-rentenversicherung.de via a bookmarked URL, or phone the DRV service hotline on 0800 1000 4800 if in doubt.
False-positive guard
Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.
About the scoring engine
Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.
Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.
Ready to clean your inbox?
Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.
Get started