The Case
A company in the Main-Tauber district received counterfeit bank letters last week that were barely distinguishable from genuine correspondence, according to Heilbronn police. The company holds no account at the bank named in the letters.
The forgeries carried the bank's actual sender address and contact details, police said. Only the email address differed slightly from the original.
The Heilbronn police headquarters confirmed the case and warned against the fraud method known as quishing.
How the Scheme Works
- The perpetrators send professionally designed letters in the name of well-known banks, complete with logo, address and contact details, police said
- The letters claim that stricter European rules on fraud prevention took effect on January 1, 2026
- Recipients are told to register their devices by scanning a QR code, supposedly to protect their account
- The QR code leads to a counterfeit phishing website that intercepts login credentials and TANs
- With the stolen data, the perpetrators can access the victim's bank account
Signs of a Forged Letter
No Account at the Bank
Mail from a bank where the recipient holds no account is a clear indication of fraud.
Different Email Address
The email address in the letter differs slightly from the original, for example by an extra letter or a different domain ending.
Pressure Through Legal Changes
The letter creates time pressure by citing alleged new legal requirements and threatens account suspension.
QR Code as Only Action
The letter's sole aim is to prompt a QR code scan. Banks do not make such requests by mail, according to police.
Affected Banks
Police and the State Criminal Police Office (LKA) have documented forged letters in the names of several banks:
- • Volksbanken Raiffeisenbanken (VR Bank)
- • ING-DiBa
- • ApoBank
- • Deutsche Bank
- • DKB (Deutsche Kreditbank)
Investigators believe the perpetrators use customer data stolen in earlier phishing attacks or data leaks to target recipients.
Police Recommendations
- • Police advise against scanning QR codes from letters without verifying the document's authenticity
- • Contact your bank using the official phone number on your bank card, not the number given in the letter
- • Do not enter sensitive data such as passwords, TANs or PINs on websites reached via QR codes
- • File a police report and submit the original letter as evidence
- • Anyone who has already entered data should contact their bank immediately and have the account blocked (emergency hotline: 116 116)
QRTrust: QR Code Checks Before Opening
QRTrust checks QR codes before the embedded link is opened. The application analyses the target URL in several steps and flags known phishing pages before the website is visited.
The check runs against a database of more than 1 million known phishing URLs and uses pattern-based analysis to identify new threats. The service is GDPR compliant and hosted in Germany.
Check a QR code with QRTrust →Sources
About QRTrust
QRTrust is Germany's first QR code security platform, developed in Dortmund. AI-powered real-time detection, a local threat database and multi-layered security checks protect citizens, authorities and businesses from quishing attacks. GDPR compliant, hosted in Germany.
