The Case

A company in the Main-Tauber district received counterfeit bank letters last week that were barely distinguishable from genuine correspondence, according to Heilbronn police. The company holds no account at the bank named in the letters.

The forgeries carried the bank's actual sender address and contact details, police said. Only the email address differed slightly from the original.

The Heilbronn police headquarters confirmed the case and warned against the fraud method known as quishing.

How the Scheme Works

  1. The perpetrators send professionally designed letters in the name of well-known banks, complete with logo, address and contact details, police said
  2. The letters claim that stricter European rules on fraud prevention took effect on January 1, 2026
  3. Recipients are told to register their devices by scanning a QR code, supposedly to protect their account
  4. The QR code leads to a counterfeit phishing website that intercepts login credentials and TANs
  5. With the stolen data, the perpetrators can access the victim's bank account

Signs of a Forged Letter

No Account at the Bank

Mail from a bank where the recipient holds no account is a clear indication of fraud.

Different Email Address

The email address in the letter differs slightly from the original, for example by an extra letter or a different domain ending.

Pressure Through Legal Changes

The letter creates time pressure by citing alleged new legal requirements and threatens account suspension.

QR Code as Only Action

The letter's sole aim is to prompt a QR code scan. Banks do not make such requests by mail, according to police.

Affected Banks

Police and the State Criminal Police Office (LKA) have documented forged letters in the names of several banks:

  • Volksbanken Raiffeisenbanken (VR Bank)
  • ING-DiBa
  • ApoBank
  • Deutsche Bank
  • DKB (Deutsche Kreditbank)

Investigators believe the perpetrators use customer data stolen in earlier phishing attacks or data leaks to target recipients.

Police Recommendations

  • Police advise against scanning QR codes from letters without verifying the document's authenticity
  • Contact your bank using the official phone number on your bank card, not the number given in the letter
  • Do not enter sensitive data such as passwords, TANs or PINs on websites reached via QR codes
  • File a police report and submit the original letter as evidence
  • Anyone who has already entered data should contact their bank immediately and have the account blocked (emergency hotline: 116 116)

QRTrust: QR Code Checks Before Opening

QRTrust checks QR codes before the embedded link is opened. The application analyses the target URL in several steps and flags known phishing pages before the website is visited.

The check runs against a database of more than 1 million known phishing URLs and uses pattern-based analysis to identify new threats. The service is GDPR compliant and hosted in Germany.

Check a QR code with QRTrust

About QRTrust

QRTrust is Germany's first QR code security platform, developed in Dortmund. AI-powered real-time detection, a local threat database and multi-layered security checks protect citizens, authorities and businesses from quishing attacks. GDPR compliant, hosted in Germany.