Fake Bank Letters with QR Codes in Circulation
Fraudsters are sending counterfeit letters that appear to come from Deutsche Bank, according to the bank. The letters often carry subject lines such as 'Banking App Update Required' or 'TAN Procedure Update Necessary' and contain a QR code.
The letters claim the QR code is needed to update the recipient's TAN device or BestSign procedure. According to police, it is in fact a so-called quishing attack, a combination of QR code and phishing.
How the Scheme Works
According to police, the perpetrators proceed in several steps:
- Fake letters are sent in Deutsche Bank's corporate design with copied logos and layouts
- The letters claim that identity verification or a TAN update is required under EU regulations (AML/KYC)
- A QR code is presented as a quick way to complete the supposed process
- Scanning the code leads to a counterfeit banking page
- Login credentials, TANs, credit card details or personal information are requested and harvested there
Signs of a Fake Letter
Unexpected Letters
The letters arrive unsolicited and refer to an update that was never requested
QR Codes in Bank Letters
Banks say they do not send QR codes for security updates by letter
Urgency and Threats
The letters create time pressure or threaten account suspension
Spelling Errors
Unusual wording or grammatical errors can indicate a forgery
No Personal Salutation
The correct salutation with the recipient's full name is often missing
Deutsche Bank's Response
Deutsche Bank advises recipients to disregard and dispose of such letters. Customers who have already scanned the QR code or entered data should contact the bank immediately, it said.
The bank said it never asks customers to enter sensitive data such as PINs, TANs or passwords by email, text message, phone or letter.
Deutsche Bank said it would never ask customers to enter their login credentials or update their TAN procedure via a QR code in a letter.
Recommended Precautions
- Do not scan QR codes from unsolicited letters: Banks, authorities and insurers say they use other channels for security updates
- Check destination addresses before opening: Verification services compare the address behind a QR code against databases of known phishing sites
- Contact the bank directly: In case of doubt, use the phone number on the bank card, not the number given in the letter
- Do not enter TANs on external sites: Banks say they do not ask customers to enter a TAN on a website reached via a link or QR code
- Report suspicious letters: Deutsche Bank accepts reports at phishing@deutsche-bank.de; a police report can also be filed
Advice for Affected Customers
Police advise those who have already entered data to take the following steps:
- 1.Have online banking blocked via the emergency hotline 116 116
- 2.Contact the bank using its official service number
- 3.Change all passwords and PINs
- 4.File a report with the police
- 5.Document the incident with screenshots and keep the letter
According to police, acting quickly improves the chances of limiting financial damage.
Background: Postal Mail as a Delivery Channel
The case shows that criminals are increasingly using traditional mail for phishing. Police point to similar cases in which letters were sent in the names of various banks.
Authorities advise against scanning unsolicited QR codes and recommend reporting suspicious letters to the bank or the police.
Check QR Codes Before Opening
QRTrust checks the destination URL of a QR code against databases of known phishing sites before the website opens.
Use QRTrust for FreeSources and Further Information
This article is based on the following warnings and reports:
