Fraudulent Letter Reported on Reddit

A user on Reddit (r/Finanzen) shared a letter purporting to come from DKB (Deutsche Kreditbank). The letter arrived by post, complete with postage stamp, address, logo and signature. According to police, it is a fraud attempt.

Fake DKB letter with QR code – scam attempt

The fake DKB letter as shared on Reddit. Source: Reddit r/Finanzen

The letter is headed 'The New Payment System of DKB – Important Information for You.' It claims a new feature for checking or savings accounts related to real-time transfers has been activated. Recipients are asked to scan a QR code to 'verify' the change.

According to those affected, the letter appears legitimate at first glance. Inconsistencies emerge only on closer inspection.

How the Scheme Works

  1. Recipients receive a professionally designed letter in the name of their bank, complete with official logo and signature
  2. The letter asks them to scan a QR code, supposedly to verify a new account feature
  3. The QR code leads to a near-identical copy of the DKB login page
  4. The fake page captures login credentials, TANs and personal information
  5. With the stolen data, fraudsters can empty accounts or commit identity theft

Signs of the Forgery

Timeline Inconsistency

The letter states the new feature was activated in October 2025, yet the letter arrived months later.

Missing Legal Block

The customary fine print with imprint, board of directors, supervisory board and legally required disclosures is absent.

Focus on the QR Code

The entire letter is directed at a single action: scanning the QR code.

Suspicious URLs

The QR code leads to domains with unusual extensions (e.g., .ru) or shortened URLs that conceal the real destination.

Scheme Also Uses Names of Other Banks

According to police and Germany's Federal Office for Information Security (BSI), the same scheme is being carried out in the name of several banks:

  • DKB (Deutsche Kreditbank)
  • Deutsche Bank
  • Commerzbank
  • Targo-Bank
  • ING

Investigators say the fraudsters send the letters in bulk, counting on some recipients being actual customers of the bank named.

Advice for Recipients

  • Police advise against scanning QR codes from letters you were not expecting
  • Verify the letter by calling your bank on the official number printed on your card
  • Forward suspicious letters to phishingverdacht@dkb.de (for DKB letters)
  • File a police report and bring the original letter
  • If you have already entered data, contact your bank immediately and have your account blocked (emergency hotline: 116 116)

Technical Analysis: Checking the Phishing URL

The phishing URL from the letter was checked via the QRTrust API. The result:

Result: DANGEROUS – 94% Confidence

The databases Google Safe Browsing and PhishTank did not flag the URL, possibly because the site was too new or already offline. The AI-based checks classified the address as dangerous:

QRTrust LLM

QRTrust LLM: Phishing detected – 100% Confidence

ML Detection

ML Detection (Gradient Boosting): Phishing pattern detected – 99.99% Confidence

Google Safe Browsing

Google Safe Browsing: Not detected

PhishTank + OpenPhish

PhishTank + OpenPhish: Not detected

The ML analysis lists several indicators: the domain 'dkb.app-verwaltung.app' imitates the DKB name as a subdomain, has a domain reputation of 40/100, is not listed among the top 1 million trusted domains and has no SSL certificate history.

The case shows that URLs not yet listed in traditional databases can still be classified as phishing through AI-based pattern recognition.

Product Note: QR Code Checking With QRTrust

QRTrust checks the destination URL of a QR code before it is opened in the browser. The scanner compares the address against known phishing sites in real time and displays a warning if a match is found.

QRTrust checks against over 1 million known phishing URLs and uses AI-based pattern recognition to identify new threats.

Check a QR Code With QRTrust